Penlink is a technology company bringing clarity to complex data for people who need it now. We partner with law enforcement agencies across the United States, offering a software solution to manage data and aid investigators solving crimes. It sounds like a lot of data and analytics, but really, it’s about improving the world and keeping safe the places we call home.
We focus on creating products that positively impact our communities and being "in the mission" and less about the laidback culture and amazing benefits – even though we offer those too. With our get it done attitude and focused mission we are growing at an unprecedented rate and are therefore seeking a Senior GRC Officer to join our global Security and Compliance team. This role will independently manage substantial portions of Penlink's U.S. governance, risk, and compliance program, initially as our sole dedicated U.S.-based GRC professional while remaining fully integrated into the global Security and Compliance team. You'll personally drive the work rather than operate solely in an oversight capacity, taking hands-on, day-to-day ownership of assigned FedRAMP, CMMC, and other compliance workstreams — coordinating with technical teams, auditors, and business stakeholders from planning through evidence collection, assessment, remediation, and ongoing monitoring.
YOUR RESPONSIBILITIES
Independently manage assigned governance and compliance workstreams across FedRAMP, CMMC Level 2, SOC 2 Type 2, ISO 27001, TX-RAMP Level 2, and CJIS, including full FedRAMP workstreams from readiness through Agency ATO.
Lead development and quality review of core compliance documentation (SSP, POA&M, control narratives, policies, procedures, and readiness artifacts) and serve as the primary day-to-day contact for 3PAO/C3PAO assessors, consultants, and control owners.
Coordinate implementation and validation of NIST SP 800-53 and CMMC security requirements across engineering, cloud, IT, and product teams; build and maintain organized evidence repositories and continuous monitoring processes.
Own risk management, vendor risk assessment, policy governance, access review, and exception management, including leading the Cloud Vulnerability Task Force.
Plan and support external audits, assessments, and certification programs, and prepare responses to customer security questionnaires, RFIs/RFPs, and regulatory inquiries.
Prioritize multiple concurrent workstreams, track remediation progress, identify blockers, escalate risks, and provide clear status reporting to management and stakeholders.
Conduct internal compliance assessments and gap analyses, recommending and validating remediation actions.
Serve as a trusted security and compliance point of review, providing guidance and risk-based approval recommendations for business, technology, and operational processes to ensure security requirements, risks, and control expectations are considered before implementation.