The candidate needs to have advanced GRC delivery experience and the versatility to operate as a Lead GRC Athlete—running workstreams end-to-end across Governance, Risk, Compliance, and Technical Recovery, and rotating between them without re-hiring. This is a workstream ownership role that requires in-depth knowledge, conceptual thinking, and the credibility to work with Principals globally. The candidate provides direction and mentorship to Seniors and Analysts, advises the team on complex matters, and foresees most future implications of the solutions they implement. Solid working knowledge of SOX ITGC, NIST CSF and ISO 27001, risk lifecycle management, third-party cyber risk, DR/BCP practices, and ServiceNow GRC is essential. The candidate closes loops with artifacts and evidence and knows when to execute, when to govern, and when to escalate.