
Cosm is a global technology company that brings experiences to life in immersive environments. We help our partners create spaces and content that blur the lines of real and virtual across three primary markets: Sports and Entertainment, Science and Education, and Parks and Attractions. Cosm was born from the fusion of some of the greatest innovators in the history of technology. Evans & Sutherland, Spitz, Inc., and Cosm Immersive combined forces to power the immersive experiences of the future as Cosm. Innovation is in our DNA.
IMPORTANT NOTICE FROM THE COSM HUMAN RESOURCES & RECRUITING TEAM REGARDING A RECRUITING SCAM: Your security and trust matter to us. Please note that Cosm Recruiters will ALWAYS communicate with you from an official "@Cosm.com" email address or through authorized platforms such as LinkedIn. We will NEVER request payments, banking details, or personal financial information during the recruitment process. If you receive a suspicious communication or job offer claiming to be from Cosm, please do not respond or share personal information. For official Cosm opportunities, always visit www.cosm.com/careers.
Summary:
Cosm is seeking a seasoned Governance, Risk, and Compliance (GRC) professional to help lead and evolve our enterprise-wide security governance and risk management programs. Reporting to the Information Security Officer (ISO), you will define and operationalize GRC frameworks that ensure alignment with industry standards such as NIST CSF 2.0, SOX ITGC, and the Trusted Partner Network (TPN) content-security standard. You will operate and mature our enterprise risk register, oversee regulatory compliance, provide independent assurance over the controls that protect Cosm's platforms and creative content, and drive the policy development that strengthens our security posture and supports business growth, including our path toward IPO readiness.
As an early member of a growing InfoSec team, you will have the opportunity to shape the GRC function from the ground up, with room to grow as the team and program mature. This role is expected to build and lead the GRC function as the program scales, including hiring and developing the team that supports it. The ideal candidate brings a strong background in IT controls, audit readiness, and cross-functional collaboration, along with a passion for fostering a culture of accountability, security, and continuous improvement.
Risk Management
Independent Assurance and Control Verification
Compliance and Audit Readiness
Third-Party and Vendor Risk
Policy and Control Framework
Training and Awareness
Metrics, Reporting, and Board Governance
Incident Support
Team and Function Development
The annualized salary range for this position in California is $210,000 to $225,000. The base pay offered will factor in internal equity and may also vary depending on the candidate's geographic region, job-related knowledge, skills, and relevant experience, among other factors
All applicants must be at least 18 years of age at the time of employment. This requirement is in accordance with applicable federal, state, and local labor laws. Cosm is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.

Cosm is a global technology company that builds end-to-end solutions for immersive experiences. We provide a full stack experience solution including the physical design, engineering, and manufacturing; as well as the software, display engine, and content needs to deliver immersive experiences at scale. Our technology enables people to experience entertainment in a new way across three primary markets: Sports and Entertainment, Science and Education, and Parks and Attractions.
IMPORTANT NOTICE FROM THE COSM HR & RECRUITING TEAM:
Your security and trust matter to us. Please note that Cosm Recruiters will ALWAYS communicate with you from an official "@Cosm.com" email address or through authorized platforms like LinkedIn. We will NEVER request payments, banking details, or personal financial information during the recruitment process.
If you receive a suspicious job offer claiming to be from Cosm, do not respond or share personal information. For official Cosm opportunities, always visit www.cosm.com/careers.