✦ Luna Orbit — Cybersecurity

Sr. Manager of Cybersecurity Governance, Risk Mgmt & Compliance

at United Rentals

📍 2 Locations Hybrid Posted April 03, 2026
Type Not Specified
Experience senior
Exp. Years 10+ years
Education Not Specified
Category Cybersecurity

Lead the firm's cybersecurity GRC (Governance, Risk Management & Compliance) program, owning the multi-year GRC strategy, budget, and Board liaison to mature policy, standards, and regulatory compliance across the organization.

  • Policy governance and standards; Strategic planning and budgeting; Compliance & data privacy; Risk management & reporting; Third-party & vendor risk management

Oversees policy governance, risk management, and compliance programs aligned to ISO 27001 and NIST CSF; manages regulatory requirements (GDPR, CMMC/DFARS, CCPA/CPRA, SOX) and third-party risk; leads adversarial readiness and data privacy initiatives.

The ideal candidate is a mid-to-senior level GRC leader with 10+ years in cybersecurity and governance, risk, and compliance programs, capable of aligning security investments to business objectives and reporting to the Board.

CRISC (Certified in Risk and Information Systems Control)CGEIT (Certified in the Governance of Enterprise IT)CISM (Certified Information Security Manager)CISA (Certified Information Systems Auditor)
CISSP (Certified Information Systems Security Professional)
GRCGovernanceRisk ManagementComplianceData PrivacyGDPRCMMCDFARSCCPA/CPRASOXISO 27001NIST CSFKRIsKPIsThird-Party Risk ManagementIncident ResponseRed TeamSecurity TrainingBudget ManagementBoard Reporting
NIST Cybersecurity FrameworkISO 27001GDPRPCI DSSDFARS/CMMCCCPA/CPRASOXKRIsKPIsRisk ManagementThird-Party Risk ManagementIncident ResponsePenetration TestingPolicy GovernanceTraining & Awareness
LeadershipStrategic PlanningBudget ManagementCommunicationExecutive LiaisonCollaboration

Required

CRISC (Certified in Risk and Information Systems Control)CGEIT (Certified in the Governance of Enterprise IT)CISM (Certified Information Security Manager)CISA (Certified Information Systems Auditor)

Preferred

CISSP (Certified Information Systems Security Professional)
Industry Logistics
Job Function Own and mature the organization’s GRC program and data privacy posture, aligning security investments to business objectives and reporting to executive leadership.
Role Subtype GRC Manager
Tech Domains Cybersecurity
GRCGovernanceRisk Management & ComplianceNIST Cybersecurity FrameworkISO 27001GDPRDFARS/CMMCCCPA/CPRASOXCRISCCGEITCISMCISACISSPvendor risk managementprivacydata privacyboard liaisonbudget managementpolicy governancedata classificationDLPNIST CSF

Less than 10 years in cybersecurity, No leadership experience in GRC, No experience with GDPR/CCPA/DFARS/CMMC

Apply for this Position →

Get matched to jobs like this

Luna finds roles that fit your skills and career goals — no endless scrolling required.

Create a Free Profile