GRC Lead (IT/OT)
Glocomms is partnered with an American energy company dedicated to reliable, clean power and sustainable development to identify a GRC Lead (IT/OT) who will drive governance, risk, and compliance strategies across both IT and operational technology environments. This is a highâvisibility, hybrid role (2-3 days/week onsite in Danbury, CT) supporting secureâbyâdesign engineering, regulatory readiness, and enterprise risk management for a highly regulated criticalâinfrastructure organization.
Key Responsibilities
As the GRC Lead (IT/OT), you will design, implement, and mature governance programs that strengthen cyber resilience across industrial control systems (ICS), OT networks, and corporate IT environments. You will be responsible for aligning the organization with leading security frameworks (e.g., NIST CSF, IEC 62443) and ensuring ongoing compliance with regulatory, security, and audit requirements.
You will partner closely with engineering, security operations, risk, compliance, and technology leadership to embed governance processes, monitor control effectiveness, and steward audit readiness across the enterprise.
Governance, Frameworks & Policy
- Lead the development, maintenance, and communication of IT/OT security policies, standards, and operational procedures.
- Build and mature enterprise control frameworks, including control mapping, compensating controls, and change governance.
- Implement and maintain RACI/RASIC structures for governance clarity and crossâfunctional execution.
- Drive continuous improvement, KPI tracking, and governance program design across both IT and OT.
Risk Management & Compliance
- Oversee enterprise risk management, including the risk register, risk acceptance processes, and businessârisk reporting.
- Conduct control selfâassessments, internal assurance testing, and independent verification of control effectiveness.
- Identify and manage nonâcompliance gaps, develop remediation plans and CAPA actions, and ensure timely closure.
- Manage and enhance thirdâparty risk management (TPRM), evaluating vendor security posture and compliance controls.
Audit Readiness & Evidence Management
- Lead mock audits, audit evidence preparation, and SOX / ITGC / ITAC readiness activities.
- Maintain and govern evidence repositories, automate evidence collection through GRC platforms, and manage audit evidence packages.
- Coordinate crossâfunctional groups to achieve successful regulatory inspections, external audits, and internal audits.
Technical Integration Across IT & OT
- Collaborate with engineering teams to embed secureâbyâdesign principles, threat modeling, and segmentation governance.
- Oversee OT asset inventory, network zoning, conduits, and control architecture alignment with IEC 62443.
- Integrate GRC processes into incident response, root cause analysis, and operational risk reviews.
- Ensure alignment of technical security standards, control requirements, and engineering processes.
Programs, Tools & Stakeholder Engagement
- Manage and optimize GRC software platforms, evidence automation workflows, and compliance metrics reporting.
- Lead security awareness training, roleâbased training programs, and crossâfunctional education initiatives.
- Facilitate discussions between technical and nonâtechnical stakeholders; drive conflict resolution and alignment across teams.
- Maintain updated regulatory policy interpretations and guide business units through applicability and compliance requirements.
- 7+ years of experience in GRC, cybersecurity, IT/OT risk, or compliance roles within critical infrastructure or highly regulated industries.
- Strong understanding of NIST CSF, IEC 62443, IT/OT controls, and regulatory standards.
- Experience with audit lifecycle management, evidence governance, ITGC/ITAC/SOX, and assurance testing.
- Technical fluency across IT and OT domains: network segmentation, ICS/SCADA, asset inventories, security controls, threat intelligence, and architectural principles.
- Demonstrated ability to influence senior stakeholders and lead crossâfunctional teams.
- Experience with GRC platforms, dashboarding, metrics, and workflow automation.
FAQs
Congratulations, we understand that taking the time to apply is a big step. When you apply, your details go directly to the consultant who is sourcing talent. Due to demand, we may not get back to all applicants that have applied. However, we always keep your CV and details on file so when we see similar roles or see skillsets that drive growth in organisations, we will always reach out to discuss opportunities.
Yes. Even if this role isnât a perfect match, applying allows us to understand your expertise and ambitions, ensuring you're on our radar for the right opportunity when it arises.
We also work in several ways, firstly we advertise our roles available on our site, however, often due to confidentiality we may not post all. We also work with clients who are more focused on skills and understanding what is required to future-proof their business.
That's why we recommend registering your CV so you can be considered for roles that have yet to be created.
Yes, we help with CV and interview preparation. From customised support on how to optimise your CV to interview preparation and compensation negotiations, we advocate for you throughout your next career move.
