
About CFGI
Your trusted partner for financial consulting solutions
Key Highlights
- Headquartered in Boston, Massachusetts
- Over 300 professionals dedicated to financial consulting
- Specializes in interim CFO services for MA companies
- Serves clients across healthcare, technology, and manufacturing
CFGI is a leading financial consulting firm headquartered in Boston, Massachusetts, specializing in interim CFO services and accounting consulting for middle-market companies. With a team of over 300 professionals, CFGI has successfully served clients across various industries, including healthcare,...
🎁 Benefits
Employees at CFGI enjoy competitive salaries, comprehensive health benefits, a generous PTO policy, and opportunities for remote work. The company als...
🌟 Culture
CFGI fosters a client-centric culture that emphasizes collaboration and expertise. The firm values integrity and accountability, ensuring that employe...
Overview
CFGI is seeking a Senior Compliance Manager to lead GRC and data privacy engagements. You'll work with executives to enhance security governance and compliance programs. This role requires deep expertise in GRC frameworks and regulatory compliance.
Job Description
Who you are
You are a seasoned Cybersecurity GRC & Data Privacy Subject Matter Expert with a strong background in governance, risk management, and compliance. With at least 5 years of experience, you have successfully led strategic advisory engagements that enhance clients' security posture and privacy programs. You possess excellent communication skills, allowing you to effectively engage with CISOs, CIOs, and other executives, ensuring that your advisory services align with their organizational goals.
Your expertise in GRC frameworks such as NIST CSF and ISO 27001 is complemented by a solid understanding of regulatory compliance requirements, including GDPR and CCPA. You have a proven track record of designing and operationalizing cybersecurity governance models, which includes developing policies, standards, and risk management strategies. Your consulting instincts enable you to navigate complex client environments and deliver tailored solutions that drive measurable outcomes.
What you'll do
In this role, you will lead end-to-end GRC and privacy engagements, overseeing the scoping, planning, execution, and reporting phases. You will design and operationalize cybersecurity governance models, ensuring that they are aligned with industry best practices and regulatory requirements. Your responsibilities will include building and maturing enterprise risk programs, conducting risk assessments, and developing control libraries that enhance organizational resilience.
You will also support clients in their regulatory readiness and compliance initiatives, providing guidance on SEC cyber disclosures, NYDFS 500, and HIPAA compliance. Additionally, you will enhance privacy programs by implementing data mapping, conducting Data Protection Impact Assessments (DPIAs), and managing consent processes. Your role will require you to collaborate closely with various stakeholders, including risk leaders and private equity deal teams, to ensure that the solutions you provide are practical and effective.
What we offer
At CFGI, you will have the opportunity to work on high-impact projects with sophisticated clients and private equity portfolio companies. We foster a collaborative culture that values autonomy and flexibility, allowing you to shape and scale our fast-growing Cybersecurity practice. You will receive competitive compensation and benefits, along with a clear career growth trajectory that supports your professional development.
Interested in this role?
Apply now or save it for later. Get alerts for similar jobs at CFGI.
Similar Jobs You Might Like
Based on your interests and this role

Compliance Manager
CFGI is seeking a Senior Compliance Manager to lead GRC and data privacy engagements. You'll work with executive leaders to enhance security governance and compliance programs. This role requires deep expertise in GRC frameworks and regulatory compliance.

Privacy Manager
BitGo is hiring a Privacy Manager to build and operationalize a global privacy program. You'll partner with the Legal Department and lead privacy request operations while ensuring compliance with regulatory requirements. This role requires strong organizational skills and experience in privacy management.

Program Manager
Upstart is hiring an Information Security Program Manager - GRC to lead governance, risk, and compliance initiatives. You'll work to enhance security frameworks and ensure regulatory compliance. This position requires experience in information security management.

Compliance Manager
Meta is seeking a Senior Cloud Security GRC Specialist to enhance security governance, risk management, and compliance across its cloud platforms. You'll collaborate with various teams to ensure compliance with regulations like GDPR and NIS2. This role requires a strong background in information security and compliance management.

Security Engineer
Fireblocks is seeking a Security Risk Engineer to oversee the technical execution of GRC initiatives. You'll collaborate with cross-functional teams to enhance resilience and audit readiness. This role requires strong technical expertise in cybersecurity and risk management.