Cosm

Director; Governance, Risk & Compliance

Cosm  •  $210k - $225k/yr  •  Los Angeles, CA (Onsite)  •  4 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Cosm is a global technology company that brings experiences to life in immersive environments. We help our partners create spaces and content that blur the lines of real and virtual across three primary markets: Sports and Entertainment, Science and Education, and Parks and Attractions. Cosm was born from the fusion of some of the greatest innovators in the history of technology. Evans & Sutherland, Spitz, Inc., and Cosm Immersive combined forces to power the immersive experiences of the future as Cosm. Innovation is in our DNA.

IMPORTANT NOTICE FROM THE COSM HUMAN RESOURCES & RECRUITING TEAM REGARDING A RECRUITING SCAM: Your security and trust matter to us. Please note that Cosm Recruiters will ALWAYS communicate with you from an official "@Cosm.com" email address or through authorized platforms such as LinkedIn. We will NEVER request payments, banking details, or personal financial information during the recruitment process. If you receive a suspicious communication or job offer claiming to be from Cosm, please do not respond or share personal information. For official Cosm opportunities, always visit www.cosm.com/careers.

Summary:

Cosm is seeking a seasoned Governance, Risk, and Compliance (GRC) professional to help lead and evolve our enterprise-wide security governance and risk management programs. Reporting to the Information Security Officer (ISO), you will define and operationalize GRC frameworks that ensure alignment with industry standards such as NIST CSF 2.0, SOX ITGC, and the Trusted Partner Network (TPN) content-security standard. You will operate and mature our enterprise risk register, oversee regulatory compliance, provide independent assurance over the controls that protect Cosm's platforms and creative content, and drive the policy development that strengthens our security posture and supports business growth, including our path toward IPO readiness.

As an early member of a growing InfoSec team, you will have the opportunity to shape the GRC function from the ground up, with room to grow as the team and program mature. This role is expected to build and lead the GRC function as the program scales, including hiring and developing the team that supports it. The ideal candidate brings a strong background in IT controls, audit readiness, and cross-functional collaboration, along with a passion for fostering a culture of accountability, security, and continuous improvement.

Responsibilities

Risk Management

  • Operate and mature the enterprise cyber risk register, from initial population to a sustained program, including the inherent and residual scoring methodology
  • Conduct business impact analyses to identify critical assets, systems, and processes and their tolerance for disruption, and use the results to inform asset criticality and risk prioritization
  • Facilitate the executive risk review cycle: surface residual risks that exceed appetite, coordinate treatment versus acceptance decisions, and track risk owners and treatment plans to closure
  • Maintain the risk appetite framework so that scoring, escalation thresholds, and exceeds-appetite triggers stay aligned to what the Audit Committee has approved, and support its annual review

Independent Assurance and Control Verification

  • Provide independent verification of control design and operating effectiveness for controls implemented and operated by Engineering, Security Engineering, and IT, maintaining separation between those who build and operate controls and those who assure them
  • Audit technical standards authored by Security Engineering, such as firewall and hardening baselines, against policy and framework requirements
  • Own the control evidence program: ensure each control has an assigned owner and defined evidence, that collection happens on the required cadence, and that evidence remains current and audit ready
  • Monitor evidence coverage and freshness across the control catalog, and drive remediation of missing, stale, or failing evidence ahead of audits
  • Track control deficiencies to remediation and report residual exposure to leadership

Compliance and Audit Readiness

  • Track and ensure compliance with NIST CSF 2.0, SOX ITGC, TPN, and other applicable regulatory and contractual frameworks
  • Plan and execute internal audits and reviews, and perform and document control testing
  • Support external assessments and lead customer and partner security due diligence engagements

Third-Party and Vendor Risk

  • Own the third-party security risk program end to end: intake, security review, risk rating, and ongoing monitoring across the vendor lifecycle
  • Collect and review vendor and datacenter security attestations, tracking coverage and expiration
  • Partner with Legal and Procurement to embed security requirements into vendor onboarding and contracts

Policy and Control Framework

  • Author and maintain IT and security policies, and drive them through review, ratification, distribution, and tracked acknowledgment where they bind individuals, including contractors before access is granted
  • Review technical standards authored by Security Engineering for policy alignment
  • Manage the control catalog that maps Cosm's controls to its frameworks, and coordinate control ownership across the organization
  • Monitor and report on the coverage and health of the control framework as risks, business needs, and regulatory requirements evolve

Training and Awareness

  • Own the security awareness and role-based training program end to end: content, cadence, delivery, phishing simulation, and completion tracking
  • Deliver role-specific training for administrators, privileged users, and developers
  • Promote a culture of security and compliance across the organization

Metrics, Reporting, and Board Governance

  • Design and maintain the cybersecurity metrics framework: KPIs that show whether controls are achieving their objectives, and KRIs that provide forward-looking risk exposure, each tied to risk appetite rather than activity volume
  • Define and operate the escalation triggers that force an off-cycle report to the Audit Committee, such as a critical vulnerability unremediated beyond its SLA or a control failure in a high-criticality area
  • Produce the quarterly Audit Committee reporting package: maturity movement with rationale, top gaps with owner and remediation date, incidents mapped to previously identified gaps, and resourcing needs tied to closing specific gaps
  • Present risk and compliance reporting to senior leadership, the Cybersecurity Executive Steering Committee, and the Audit Committee
  • Communicate risk and compliance issues clearly to both technical and non-technical stakeholders

Incident Support

  • Provide risk, control, and impact context to the decision-makers assessing whether an incident is material
  • Own the control and maturity findings arising from post-incident review

Team and Function Development

  • Build and lead the GRC function as the program scales, including hiring and developing the team that supports it

Experience

  • 8 to 12 years in IT governance, risk, and compliance, including leading GRC programs or major initiatives in enterprise environments
  • Hands-on experience operating and maturing risk registers, running risk assessments, gap analyses, and business impact analyses, and driving treatment decisions to closure
  • Independent control testing experience supporting SOX ITGC or pre-IPO audit readiness
  • Experience planning and executing internal audits
  • Experience owning a third-party risk program, including review of vendor security attestations
  • Experience running continuous-compliance and evidence collection in a GRC platform. We use Vanta
  • Expertise authoring IT and security policies that meet regulatory requirements, and running them through review, ratification, and acknowledgment
  • Track record producing board or audit-committee-level reporting on maturity, risk posture, and remediation, and designing metrics tied to risk appetite
  • Experience building training and awareness programs
  • Deep working knowledge of NIST CSF 2.0 and 800-53; familiarity with SOC 2, ISO 27001, COBIT, and CIS Controls
  • Ability to explain complex risk to non-technical senior stakeholders and influence decisions
  • Bachelor's degree in a related field, or equivalent experience

The annualized salary range for this position in California is $210,000 to $225,000. The base pay offered will factor in internal equity and may also vary depending on the candidate's geographic region, job-related knowledge, skills, and relevant experience, among other factors

All applicants must be at least 18 years of age at the time of employment. This requirement is in accordance with applicable federal, state, and local labor laws. Cosm is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.

Cosm

About Cosm

Cosm is a global technology company that builds end-to-end solutions for immersive experiences. We provide a full stack experience solution including the physical design, engineering, and manufacturing; as well as the software, display engine, and content needs to deliver immersive experiences at scale. Our technology enables people to experience entertainment in a new way across three primary markets: Sports and Entertainment, Science and Education, and Parks and Attractions.

IMPORTANT NOTICE FROM THE COSM HR & RECRUITING TEAM:

Your security and trust matter to us. Please note that Cosm Recruiters will ALWAYS communicate with you from an official "@Cosm.com" email address or through authorized platforms like LinkedIn. We will NEVER request payments, banking details, or personal financial information during the recruitment process.

If you receive a suspicious job offer claiming to be from Cosm, do not respond or share personal information. For official Cosm opportunities, always visit www.cosm.com/careers.

Industry
Arts & Entertainment
Company Size
501-1,000 employees
Headquarters
Los Angeles, CA
Year Founded
2020
Website
cosm.com
Social Media