About this opportunity
Pinnacle Group, Inc. lists this GRC Manager (Third-Party IT Risk) opportunity in dallas, Texas. Review the employer’s description below for duties, qualifications and application requirements.
Job description
Pinnacle Group is seeking a GRC Manager – Technology Risk & Governance to own, manage, and mature key governance, risk, and compliance programs across the organization. This role will oversee third-party risk management, technology risk, compliance readiness, AI risk governance, business continuity, and audit support. The ideal candidate brings hands‑on experience in technology risk, vendor assessments, security frameworks, and compliance programs, with the ability to lead initiatives, influence stakeholders, and support future growth within the risk function.
Job Description
Own and manage the third-party risk management program, including risk-based vendor assessments, onboarding reviews, and periodic evaluations throughout the vendor lifecycle.
Partner with Information Security, Legal, Compliance, IT, and business stakeholders to identify, assess, document, and mitigate technology, cybersecurity, privacy, AI, and vendor-related risks.
Review SOC 1 and SOC 2 reports, ISO 27001 certifications, penetration testing reports, business continuity plans, disaster recovery documentation, privacy materials, and related compliance evidence.
Interface with third-party auditors, vendors, and internal stakeholders to gather documentation, respond to assessment requests, and support audit readiness.
Support responses to technology-related third-party questionnaires, ensuring information is accurate, complete, consistent, and professionally documented.
Maintain organized assessment records, risk documentation, compliance evidence, and supporting materials in accordance with internal policies and procedures.
Prepare risk summaries, dashboards, reports, and governance materials for leadership and committee review.
Maintain and support Pinnacle Group’s ISO 27001 certification and SOC 2 compliance in partnership with IT and other key stakeholders.
Collaborate with cross-functional teams to create, maintain, and implement AI-related standards, procedures, and risk governance practices.
Enhance and maintain Pinnacle Group’s business continuity plan in collaboration with appropriate business and technology stakeholders.
Requirements
Bachelor’s degree in Business Information Systems, Cybersecurity, Risk Management, Compliance, or a related field.
Experience in technology risk, governance, compliance, information security, audit, third-party risk management, or a related discipline.
Strong experience performing vendor risk assessments for SaaS platforms, cloud providers, managed service providers, software vendors, and AI-enabled products.
Working knowledge of security and compliance frameworks such as ISO 27001, SOC standards, NIST, CIS Controls, and related governance practices.
Experience interfacing with third-party auditors and responding to security, risk, compliance, or vendor assessment questionnaires.
Ability to assess technology vendors, identify risk concerns, document findings, and communicate recommendations clearly to technical and non-technical stakeholders.
Strong written and verbal communication skills with the ability to collaborate effectively across auditors, vendors, IT, Legal, Compliance, and business teams.
Experience using Drata or similar governance, risk, and compliance platforms preferred.
Working knowledge of AI-related risks, controls, governance standards, and emerging compliance considerations preferred.
Why Join Pinnacle Group?
At Pinnacle Group, you will have the opportunity to make a meaningful impact by strengthening risk governance, compliance readiness, and operational resilience across the organization. This role offers visibility across key business functions and the ability to influence how technology, vendor, AI, and compliance risks are managed at scale. You will join a collaborative, values-driven environment that supports professional growth, ownership, and continuous improvement.
During the hiring process, we may use artificial intelligence (AI) tools to assist in evaluating information related to your application. These tools may help analyze job‑related qualifications or assist recruiters in reviewing applications and interview responses. AI-generated information is one factor considered in our hiring process. Final employment decisions are made by qualified hiring personnel and are not based solely on AI-generated recommendations.
Compensation and Benefits Disclosure
The specific compensation for this position will be determined by a number of factors, including the scope, complexity and location of the role as well as the cost of labor in the market; the skills, education, training, credentials and experience of the candidate; and other conditions of employment. Our full-time consultants have access to benefits including medical, dental, vision and 401K contributions as well as any other PTO, sick leave, and other benefits mandated by appliable state or localities where you reside or work.
#J-18808-Ljbffr
Worksite address
dallas, TX, 75215, US
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.