Jobs Companies UMA Education Manager, Governance, Risk & Compliance

Über diese Manager, Governance, Risk & Compliance Stelle bei UMA Education

UMA Education · Remote · Remote (RMT)

Ultimate Medical Academy is a non-profit healthcare educational institution with a national presence. Headquartered in Tampa, Florida and founded in 1994, UMA offers content-rich, interactive online programs as well as hands-on training at our Clearwater, Florida campus. 

As a full-time team member, you will have access to the following benefits:

  • Medical (including prescription), Dental, Vision (UMA subsidized)
  • FSA/HSA (Depending on Medical Plan chosen)
  • Basic Life Insurance (UMA paid)
  • Additional Voluntary Life Insurance (Team Member paid)
  • Employee Assistance Program – EAP (UMA paid)
  • Long Term Disability (UMA paid)
  • Short Term Disability (Team Member paid)
  • Supplemental Insurance such as Critical Illness, Accident, and Hospital (Team Member Paid)
  • Paid Time Off – 15 days accrued in year 1, 9 holidays, and 1 day of Volunteering Time Off
  • 401k (eligible upon completion of 90 days of employment and must be at least 18 years of age)
  • Pet Insurance
  • Identity Theft Protection

Purpose of the Position:

The Manager, Governance, Risk & Compliance (GRC) is responsible for leading and advancing the institution’s governance, risk management, compliance, and information security programs to support the achievement of organizational objectives and regulatory requirements. This role develops, implements, and monitors frameworks, policies, controls, and risk mitigation strategies that promote operational effectiveness, safeguard institutional assets, and ensure compliance with applicable laws, regulations, accreditation standards, and internal policies. The Manager partners with leaders across the institution to foster a culture of accountability, risk awareness, and continuous improvement in support of the institution’s mission and long-term success.

The Manager also provides hands-on leadership for key information security programs, including vulnerability management, third-party risk management, security performance reporting, policy governance, and the continuous improvement of security controls and operational practices.

What You’ll Do:

  1. Lead Governance, Risk, and Compliance Programs: Develop, implement, and continuously enhance the institution’s governance, risk management, and compliance framework to ensure alignment with organizational objectives, regulatory requirements, accreditation standards, and recognized industry practices.
  2. Conduct Cybersecurity and Technology Risk Management Activities: Lead the identification, assessment, monitoring, and mitigation of cybersecurity and technology risks. Support the institution’s enterprise risk-management process by communicating material technology risks, control deficiencies, and actionable mitigation strategies to leadership.
  3. Oversee Regulatory and Compliance Requirements: Serve as a trusted business partner to departments across the institution and collaborate with Legal and Compliance to address applicable federal, state, higher education, privacy, and information security requirements, including FERPA, GLBA, the FTC Safeguards Rule, HIPAA where applicable, and state privacy and breach-notification requirements.
  4. Manage Security Governance and Architecture Oversight: Partner with Information Technology, Engineering, Enterprise Architecture, and security teams to establish and maintain security governance processes, evaluate technical and administrative controls, and ensure technology solutions align with institutional security, privacy, risk, and compliance requirements.
  5. Manage the Vulnerability Management Program: Lead and continuously improve the institution’s vulnerability management program, including vulnerability scanning, risk-based prioritization, patching and security-update coordination, remediation tracking, exception management, validation, and executive reporting. Partner with infrastructure, cloud, engineering, application, and business system owners to establish remediation priorities, service-level expectations, and accountability for addressing identified vulnerabilities based on severity, exploitability, asset criticality, known exploitation, and business impact.
  6. Lead Third-Party Information Security Risk Management: Conduct and coordinate information security and privacy risk assessments for vendors and third parties in partnership with Procurement, Legal, Compliance, Information Technology, and business stakeholders. Review relevant vendor security documentation, including questionnaires, SOC reports, penetration-testing summaries, certifications, data-processing practices, incident-notification commitments, and remediation plans. Track identified third-party risks, corrective actions, exceptions, and ongoing monitoring activities throughout the vendor lifecycle.
  7. Lead AI Governance Initiatives: Develop and maintain an institutional AI governance program, including policies, standards, risk assessments, intake and review processes, and oversight practices that promote the ethical, responsible, secure, and compliant use of artificial intelligence technologies.
  8. Coordinate Compliance and Control-Assurance Activities: Manage periodic and annual compliance assessments, audits, policy reviews, control testing, evidence collection, remediation activities, and reporting requirements to support ongoing adherence to regulatory obligations, accreditation expectations, contractual requirements, and organizational policies.
  9. Monitor and Report on Risk and Compliance Performance: Establish and maintain key performance indicators, key risk indicators, dashboards, and reporting mechanisms that provide leadership with visibility into security operations, vulnerabilities, remediation performance, third-party risk, compliance obligations, audit findings, policy exceptions, and overall Information Security program effectiveness. Translate technical security and compliance information into business-relevant insights that support informed decision-making, risk prioritization, operational improvement, and resource planning.
  10. Manage Policy Development and Governance Processes: Lead the creation, review, approval, communication, and maintenance of institutional policies, standards, and procedures related to governance, risk management, information security, privacy, artificial intelligence, data protection, and regulatory compliance. Maintain a structured policy lifecycle that includes assigned ownership, scheduled reviews, documented approvals, version control, exception management, and communication of material changes.
  11. Monitor the Regulatory and Threat Landscape: Maintain awareness of emerging cybersecurity threats, vulnerabilities, technologies, regulatory developments, and industry practices that may affect the institution. Maintain a documented register of applicable privacy, data-protection, breach-notification, and information security requirements in coordination with Legal and Compliance. Provide practical recommendations regarding required controls, operational changes, policies, processes, and technology investments.
  12. Drive Continuous Improvement: Identify opportunities to improve the effectiveness, scalability, automation, and maturity of information security and GRC processes. Evaluate recurring issues, audit findings, vulnerabilities, incidents, control deficiencies, and operational trends to identify root causes and recommend sustainable corrective actions. Promote the use of automation, workflow management, dashboards, and integrated platforms to improve visibility, accountability, consistency, and operational efficiency.
  13. Develop and Deliver Security Awareness Training: Design, implement, and evaluate institution-wide security awareness and compliance training programs that educate team members on cybersecurity risks, data-protection responsibilities, privacy requirements, social-engineering threats, and emerging risks.
  14. Lead with Care: Lead, coach, and develop team members, fostering a culture of wellness, recognition, engagement, accountability, and continuous improvement. Meet regularly with direct reports in one-on-one and group settings to provide feedback and cultivate and maintain a positive work culture. Provide hands-on leadership by working directly with team members and cross-functional partners to deliver projects, resolve issues, complete assessments, implement controls, and advance critical information security and GRC initiatives.
  15. Perform other duties as assigned.

Career Level Expectations:

  • Combines people leadership, technical judgment, and hands-on execution to advance information security and GRC priorities in partnership with technology and business stakeholders.
  • Typically manages a team or small unit.
  • Owns short to mid-term (1-3 years) execution of functional strategy and the operational direction of a team.
  • Handles often difficult and complex problems and that require extensive investigation and analysis.
  • Requires ability to influence others to accept practices and approaches, and ability to communicate with executive leadership.
  • Desire for growth and professional development.

Required Skills/Experience:

  • Bachelor’s degree in cybersecurity, information security, information systems, computer science, risk management, business administration, or a related field, or an equivalent combination of education and relevant professional experience.
  • Progressive experience in information security governance, cybersecurity risk management, regulatory compliance, security assurance, or a related discipline.
  • Experience leading and developing team members or directing complex, cross-functional information security and GRC programs and initiatives.
  • Experience managing or supporting a vulnerability management program, including vulnerability assessments, patch and remediation coordination, risk-based prioritization, exception management, validation, and performance reporting.
  • Experience conducting third-party information security and privacy risk assessments and evaluating vendor controls, audit reports, certifications, contractual requirements, and remediation plans.
  • Working knowledge of recognized cybersecurity frameworks and standards, including the NIST Cybersecurity Framework, applicable NIST Special Publications, CIS Critical Security Controls, and other relevant risk and control frameworks.
  • Technical understanding of cloud environments, identity and access management, endpoint security, network security, vulnerability management, data protection, logging and monitoring, application security, and software-as-a-service platforms.
  • Experience developing meaningful information security and GRC metrics, key performance indicators, key risk indicators, dashboards, and executive-level reporting.
  • Experience creating, reviewing, maintaining, and implementing information security, privacy, risk-management, and technology policies, standards, and procedures.
  • Experience monitoring cybersecurity, privacy, breach-notification, and data-protection requirements and partnering with Legal and Compliance to translate applicable requirements into operational and technical controls.
  • Experience using one or more GRC, integrated risk-management, third-party risk, privacy, vulnerability-management, audit, or security platforms, such as ServiceNow IRM/GRC, OneTrust, LogicGate, Tenable, Qualys, Rapid7, or comparable technologies.
  • Experience integrating cybersecurity and technology risks into broader enterprise risk-management processes, including risk assessments, control evaluations, risk registers, remediation plans, and executive reporting.
  • Knowledge of higher education regulatory requirements, including FERPA, GLBA, the FTC Safeguards Rule, and related privacy, security, and compliance requirements applicable to distance education institutions.
  • Ability to analyze complex technical and regulatory issues, identify practical solutions, and clearly communicate risks and recommendations to technical teams, business leaders, and executive stakeholders.
  • Experience serving as a strategic business partner and influencing stakeholders to implement appropriate security, risk-management, and compliance practices.
  • Demonstrated continuous-improvement mindset, with experience enhancing processes, controls, workflows, reporting, automation, and program maturity.
  • Ability and willingness to work hands-on with team members and cross-functional stakeholders to deliver assessments, projects, remediation activities, and information security initiatives.
  • Ability to professionally communicate fluently in verbal and written English.
  • Ability to support a diverse and inclusive work environment.
  • Computer literacy/basic computer skills to effectively navigate and utilize the technology required for the role.

Preferred Requirements:

  • Advanced degree or equivalent professional experience and advanced proficiency in one or more of the required skills or disciplines.
  • One or more current professional certifications, such as Certified Information Systems Security Professional, Certified Information Security Manager, Certified in Risk and Information Systems Control, Certified in Governance, Risk and Compliance, Certified Information Systems Auditor, or a comparable information security or risk-management certification.
  • Experience supporting information security and GRC programs within higher education, distance education, financial services, healthcare, nonprofit, multi-entity, shared-services, or another highly regulated environment.
  • Experience with the Gramm-Leach-Bliley Act Safeguards Rule, FERPA, HIPAA, state privacy requirements, breach-notification laws, and related information security obligations.
  • Experience supporting security governance, risk, compliance, or technology integration activities associated with acquisitions, organizational restructuring, new business entities, or external partnerships.
  • Proficient in MS Office (Word, Excel, PowerPoint) and other business tools such as Microsoft Teams.

Compliance: 

  • Demonstrate knowledge of, and carefully follows all applicable state laws and rules, federal and state compliance requirements and regulations including those prescribed by the U.S. Department of Education, accrediting agencies, state regulations and internal policies and procedures.  
  • Effectively communicate compliance requirements to other staff as appropriate and quickly escalate any compliance concerns to the Compliance department. 

Work Environment/Physical Demands:

  • This is a full-time remote position, with occasional onsite travel required.
  • Home office set up, quiet place to work, ability to be on camera, and ability to hard wire into high-speed internet connection.
  • May require setup of computer equipment; accommodation consideration available upon request.
  • Flexibility to work evenings and weekends, as needed.

Anticipated starting salary is based on experience and qualifications.

Compensation Range
$150,000$159,390 USD

OUR VALUES

Our institutional values are shaped and validated by our team members. They describe how we strive to operate and are the standards of behavior we look to embody. 

ACT WITH INTEGRITY

We operate honestly and ethically in an industry-compliant fashion. We are fair and trustworthy in our interactions with all we serve. Our team members, at all levels, lead by example and strive to do the right thing for our students and for each other. We are disciplined professionals who strive to be straightforward and dependable.

CHAMPION STUDENT OUTCOMES

We live by a strong commitment to our students and are passionate about preparing them for meaningful careers. We are deeply dedicated to ensuring students’ educational and career success. We excel at building our students’ confidence and empowering them to reach their full potential.

COMMIT TO TEAM MEMBER SUCCESS

We are committed to our team members’ success and to each other’s success. We strive to create an environment that attracts and retains the best talent while offering continuous learning, professional development and career growth opportunities. We recognize and reward our team members for their contributions to the organization and to our students.

PURSUE RESULTS WITH PURPOSE

We pursue results with a sense of urgency and purpose. We take responsibility for achieving ambitious, measurable results and hold each other accountable. We think strategically and critically, greet new ideas and challenges openly, and look for innovative solutions to challenges.

HAVE FUN. BUILD ENERGY

Enjoying what we do is central to achieving our goals. Building energy, having fun, being optimistic and creating a positive working environment are all critical to our success and that of our students. We strive to be inspired and to inspire others. We consistently show appreciation and celebrate our successes, both large and small.

WORK AS ONE

We believe that diverse, inclusive teams produce breakthrough results. We strive to build and maintain positive relationships with colleagues from all types of backgrounds by showing respect and humility when interacting with each other and resolving conflicts in a constructive manner. By working together, we win together - as one - ensuring that the goals of the company are the focal point of our efforts.

UMA will NEVER ask you to send money or ask you to provide bank account information in order for you to get reimbursed for tools to work. If you have been contacted by someone claiming to be from UMA about a job posting, you can always verify the position at https://workatuma.com/

Bereit, sich bei UMA Education zu bewerben?
Bei UMA Education bewerben

Über UMA Education

Here are our current job openings. Please click on the job title for more information, and apply with your updated resume from that page if you are interested.  

 

UMA will NEVER ask you to send money or ask you to provide bank account information in order for you to get reimbursed for tools to work. If you have been contacted by someone claiming to be from UMA about a job posting, you can always verify the position here.

Alle Jobs bei UMA Education ansehen →

Ähnliche Jobs

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei UMA Education

Alle Jobs bei UMA Education ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos