Lead GRC Architect – OneTrust
cognizantWashington, DC
Lead GRC Architect – OneTrust
cognizantWashington, DC
2 days ago
Occupations
Compliance ManagersComputer Systems Engineers/ArchitectsComputer and Information Systems ManagersIndustries
Computer Systems Design ServicesOther Management Consulting ServicesCustom Computer Programming ServicesAbout the role
Practice - CIS - Cloud, Infrastructure, and Security Services About Cloud Infrastructure & Security Services: Cognizant’s Cloud, Infrastructure, and Security Services Practice (CIS), is all about embracing digital transformation by driving core modernization holistically across layers. We help customers transform infrastructure and workplace to meet the rapidly evolving needs of the digital era. Our holistic approach delivers key results for our customers by achieving cloud driven modernization and workplace and operational transformation to run the business in a secure environment.
Job Summary:
We are seeking an experienced Lead GRC Architect – One Trust to lead the design, implementation, and enhancement of enterprise Governance, Risk, and Compliance (GRC) capabilities. This role focuses on leveraging One Trust to establish scalable risk management processes, compliance frameworks, control governance, and cybersecurity oversight across the organization. The ideal candidate will possess deep expertise in cybersecurity governance, risk management, regulatory compliance, and One Trust platform capabilities. This position requires strong stakeholder engagement, architecture leadership, and the ability to align security objectives with business priorities in a global enterprise environment.*Please note, this role is not able to offer visa transfer or sponsorship now or in the future*In this role, you will: Design and implement enterprise-wide cybersecurity governance, risk, and compliance architectures aligned with business objectives, regulatory requirements, and industry best practices. Configure, optimize, and manage One Trust capabilities including policy management, risk registers, issue management, assessments, and workflow automation. Develop and maintain integrated risk management frameworks to identify, assess, prioritize, and monitor technology and business risks. Establish control taxonomies, control libraries, and framework mappings across regulatory and security requirements. Lead security architecture and design reviews to ensure governance, risk, and compliance requirements are embedded into business and technology initiatives. Conduct and facilitate enterprise risk assessments, control evaluations, compliance reviews, and remediation planning activities. Develop dashboards, KPIs, KRIs, and executive reporting to communicate compliance posture, risk exposure, and remediation progress. Collaborate with business, technology, compliance, audit, and security teams to implement effective governance and risk management practices. Support cards and payments initiatives by ensuring security controls, governance standards, and regulatory requirements are appropriately integrated. Drive continuous improvement of GRC processes through adoption of emerging technologies, risk insights, regulatory updates, and industry best practices. Provide guidance and knowledge transfer to risk owners, architects, product managers, and operational teams on cybersecurity governance and compliance requirements. Ensure documentation, governance processes, and reporting standards are maintained and aligned with organizational and regulatory expectations. What you need to have to be considered 10+ years of experience in Cybersecurity Governance, Risk & Compliance (GRC), Technology Risk Management, Security Architecture, or Regulatory Compliance roles. Strong hands-on experience implementing and managing One Trust GRC capabilities including risk management, policy governance, assessments, and compliance programs. Deep understanding of cybersecurity risk management frameworks, governance practices, and control environments. Experience conducting enterprise risk assessments, control testing, compliance evaluations, and remediation management activities. Strong knowledge of security frameworks and regulations such as ISO 27001, NIST, PCI-DSS, SOX, GDPR, privacy regulations, and payment industry requirements. Experience supporting cards, payments, financial services, or other regulated environments is highly desirable. Strong understanding of policy management, risk registers, control mapping, issue management, audit support, and governance reporting. Proven ability to communicate complex security and compliance concepts to technical teams, business stakeholders, and executive leadership. Excellent stakeholder management, workshop facilitation, documentation, and presentation skills. Relevant certifications such as CISSP, CISM, CRISC, CGEIT, ISO 27001 Lead Auditor, One Trust Certification, or equivalent are preferred. Applications will be accepted until 14 Sep 2026.Salary and Other Compensation: The annual salary for this position is between $[134,000 - 154,500] depending on experience and other qualifications of the successful candidate. This position is also eligible for Cognizant’s discretionary annual incentive program, based on performance and subject to the terms of Cognizant’s applicable plans.
Benefits:
Cognizant offers the following benefits for this position, subject to applicable eligibility requirements: Medical/Dental/Vision/Life Insurance Paid holidays plus Paid Time Off 401(k) plan and contributions Long-term/Short-term Disability Paid Parental Leave Employee Stock Purchase Plan
Matching similar jobs
JOB OVERVIEW
Experience level
Manager
Location
Washington, DC
Occupation
Compliance Managers
Industry
Computer Systems Design Services
Posted
2 days ago
Tired of running searches?
Rank the roles you'd take once, and matches like these arrive on their own.
CREATE PROFILE