Demo

Program Lead (NO H1B/ OPT)

IT ENGAGEMENTS INC
San Francisco, CA Contractor
POSTED ON 12/30/2025
AVAILABLE BEFORE 2/28/2026
Greetings from IT Engagements Role: Program Lead (NO H1B/ OPT)Location: Vernon \ Los Angels, CA (Hybrid Preferred)  Must Have:·                    LinkedIn with a picture·                    10–15 years progressive experience in IT Audit/Controls, or Enterprise Risk·                    5 years leading GRC programs in public companies.·                    End‐to‐end ISO 27001 implementation experience (ISMS design through certification). SOX 404 ITGC ownership experience, including scoping, control design, testing, and remediation across ERP (e.g., SAP/Oracle) and key business applications.·                    Must have Certification - ISO/IEC 27001 Lead Implementer and/or Lead Auditor  About the RoleForgent is seeking a hands-on Program Lead for Governance, Risk & Compliance (GRC) to build, lead, and mature our enterprise GRC program. This role is accountable for ISO/IEC 27001 certification readiness and maintenance and Sarbanes–Oxley (SOX) IT compliance, spanning IT general controls (ITGCs), application controls, and operational technology (OT) considerations in a manufacturing context. You will lead cross-functional teams of internal employees and external vendors, drive governance processes, operationalize risk management, coordinate audits, and ensure continuous compliance across our global footprint. Key ResponsibilitiesGovernance & Program Leadership:Establish and mature the enterprise GRC program aligned to ISO 27001, SOX, NIST CSF, CIS Controls and relevant regulatory requirements.Own the Information Security Management System (ISMS) lifecycle: scope definition, risk assessment, Statement of Applicability (SoA), control implementation, internal audit, management review, corrective actions, and surveillance/recertification readiness.Define and maintain policies, standards, and procedures (e.g., access control, change management, vulnerability management, secure SDLC, incident response, supplier security).Chair/coordinate governance forums (e.g., Risk & Compliance Steering Committee, Change Advisory Board, Management Review meetings). Risk Management:Implement enterprise risk management (ERM) for information and technology risks: risk identification, assessment (qualitative/quantitative), treatment plans, and risk acceptance with accountable owners.Build third‐party/vendor risk management (TPRM) including due diligence, contractual controls, continuous monitoring, and remediation.Integrate operational technology (OT) risk (ICS/SCADA, IIoT) into the enterprise risk register with pragmatic controls that do not disrupt production. Compliance: ISO 27001 & SOX:Lead ISO 27001 certification journey: gap analysis, roadmap, control implementation, training/awareness, internal audits, and liaison with external certification bodies.Own SOX ITGCs and application controls: design, documentation, testing coordination, remediation tracking, and /Disclosure Committee reporting.Align identity & access management, change management, computer operations, and IT service delivery to SOX and ISO control objectives; ensure evidence quality and audit readiness.Coordinate with Finance/Accounting on financial reporting risks. Audit & Assurance:Plan and execute internal audits (ISO 27001, policy compliance, control effectiveness) and coordinate external audits (SOX, ISO surveillance/certification, PCI).Build defensible control evidence repositories, ensure sampling precision, and drive timely remediation of findings.Develop and maintain control libraries, test plans, and mapping across frameworks (ISO/NIST, SOX ITGC etc.). Tooling, Automation & Metrics:Select, implement, and administer GRC platforms (e.g., Archer/Drata/Vanta, ServiceNow GRC/IRM, OneTrust) and integrate with ticketing, IAM, CMDB, SIEM, and ERP (e.g., SAP/Oracle).Operationalize continuous control monitoring (CCM) and control analytics (e.g., access outliers, change exceptions, segregation of duties conflicts).Define and publish KPIs/KRIs and Board/C‐suite dashboards: audit status, control effectiveness, residual risk, TPRM posture, policy adoption, incident trends. Team Leadership & Vendor Management:Lead a hybrid, geographically distributed team of employees and vendor/consulting resources; set objectives, coach, and develop talent.Build SOWs, manage budgets, and ensure vendor SLAs/KPIs and quality outcomes.Foster a culture of accountability, transparency, and continuous improvement. Training, Awareness & Change Management:Lead assessment and management of training phishing campaign platform and process (e.g., SOX for IT engineers, ISO control owners, plant operations staff).Drive change management communications to embed controls into daily operations without impeding manufacturing throughput. Incident, BCP/DR & Privacy Alignment:Ensure incident response processes are governed, tested, and produce audit-ready evidence.Oversee BCP/DR governance (business impact analysis, testing cadence, lessons learned).Partner with Legal/Privacy on data protection, records retention, and supplier agreements (e.g. CCPA). Qualifications EducationBachelor’s degree in Information Systems, Computer Science, Engineering, Accounting/Finance, or related field preferred. Advanced degree (MBA, MS Information Assurance) is a plus. Experience10–15 years progressive experience in IT Audit/Controls, or Enterprise Risk; 5 years leading GRC programs in public companies. End‐to‐end ISO 27001 implementation experience (ISMS design through certification). SOX 404 ITGC ownership experience, including scoping, control design, testing, and remediation across ERP (e.g., SAP/Oracle) and key business applications. Demonstrated success in leading mixed teams of internal staff and vendor/consultants, including multi‐site and global operations. Manufacturing/OT exposure: ICS/SCADA risk management, plant‐floor realities (safety, uptime, maintenance windows). Hands‐on with GRC platforms, IAM, CMDB, SIEM/SOAR, vulnerability management, and evidence repositories. Strong familiarity with NIST CSF, CIS Controls, and control mapping across frameworks. Certifications (Preferred)ISO/IEC 27001 Lead Implementer and/or Lead Auditor (MUST HAVE THIS ONE)CISA (Certified Information Systems Auditor)CISM or CISSPCRISCCGEITITIL Foundation Skills & CompetenciesHands-on control design and evidence creation; comfort reading logs, configs, and ERP control parameters.Risk quantification (basic FAIR or scenario analysis) and pragmatic prioritization.Stakeholder management with Finance, IT, Plant Ops, and external auditors.Analytical and documentation excellence; precision in scoping, testing, and remediation tracking.Clear executive communication—Board-level reporting with drill-down detail.Change leadership—able to balance compliance rigor with manufacturing agility. Success Metrics (12–18 Months)Achieve ISO 27001 certification (or surveillance audit pass) within agreed scope.Zero material weaknesses and timely SOX remediation of control deficiencies.Established TPRM program with risk‐tiered vendor controls and SLA tracking.Operational GRC platform with automated workflows and CCM for top controls.Published KPI/KRI dashboards with trend improvements (e.g., access review cycle time, change exceptions, incident MTTR, audit finding closure rates).Measurable policy adoption and training completion across IT and manufacturing sites. Reporting & CollaborationReports to CISO. Collaboration: Finance, IT Infrastructure & Applications, Internal Audit, Legal/Privacy, Plant Operations, Supply Chain, HR. Travel & Work Environment10–25% travel to manufacturing plants, data centers, and corporate offices for audits, walkthroughs, and stakeholder workshops. Thank youvinaya@itengagements.com

Salary : $85 - $90

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Program Lead (NO H1B/ OPT)?

Sign up to receive alerts about other jobs on the Program Lead (NO H1B/ OPT) career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$101,775 - $148,346
Income Estimation: 
$133,494 - $170,282
Income Estimation: 
$131,105 - $151,214
Income Estimation: 
$128,269 - $173,633
Income Estimation: 
$157,111 - $225,157
Income Estimation: 
$211,242 - $276,545
Income Estimation: 
$257,772 - $359,085
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at IT ENGAGEMENTS INC

  • IT ENGAGEMENTS INC San Francisco, CA
  • Role: Lab Technician (Contract W2)Location: San Francisco, CA The Opportunity:· Conduct daily operational maintenance of lab equipment, including incubator... more
  • 3 Days Ago

  • IT ENGAGEMENTS INC Englewood, NJ
  • Greetings from IT Engagements IT Engagements is a global staff augmentation firm providing a wide-range of talent on-demand and total workforce solutions. ... more
  • 4 Days Ago

  • IT ENGAGEMENTS INC San Francisco, CA
  • Greetings from IT Engagements IT Engagements is a global staff augmentation firm providing a wide-range of talent on-demand and total workforce solutions. ... more
  • 4 Days Ago

  • IT ENGAGEMENTS INC San Francisco, CA
  • Greetings from IT Engagements IT Engagements is a global staff augmentation firm providing a wide-range of talent on-demand and total workforce solutions. ... more
  • 6 Days Ago


Not the job you're looking for? Here are some other Program Lead (NO H1B/ OPT) jobs in the San Francisco, CA area that may be a better fit.

  • Lead San Francisco, CA
  • Lead is a fintech building banking infrastructure for embedded financial products and services. We operate an FDIC-insured bank headquartered in Kansas Cit... more
  • 5 Days Ago

  • Lead Star Security Inc San Francisco, CA
  • Lead Star Security, a fully licensed and insured private security company, is seeking a dedicated individual to join our esteemed team as an Unarmed Securi... more
  • 1 Month Ago

AI Assistant is available now!

Feel free to start your new journey!