Cosm logo
Cosm

29 open roles

Director; Governance, Risk & Compliance

$210k to $225k

Los Angeles, CA, USAPosted Oct 9, 2026

Job description

Cosm is a global technology company that brings experiences to life in immersive environments. We help our partners create spaces and content that blur the lines of real and virtual across three primary markets: Sports and Entertainment, Science and Education, and Parks and Attractions. Cosm was born from the fusion of some of the greatest innovators in the history of technology.

Evans & Sutherland, Spitz, Inc., and Cosm Immersive combined forces to power the immersive experiences of the future as Cosm. Innovation is in our DNA. IMPORTANT NOTICE FROM THE COSM HUMAN RESOURCES & RECRUITING TEAM REGARDING A RECRUITING SCAM: Your security and trust matter to us. Please note that Cosm Recruiters will ALWAYS communicate with you from an official "@Cosm.

com" email address or through authorized platforms such as LinkedIn. We will NEVER request payments, banking details, or personal financial information during the recruitment process. If you receive a suspicious communication or job offer claiming to be from Cosm, please do not respond or share personal information. For official Cosm opportunities, always visit www.

cosm.com/careers . Summary: Cosm is building its information security program, and this role owns the governance backbone. We operate immersive venues, produce and handle premium content under studio and Trusted Partner Network security requirements, and we are building toward the control maturity that comes with rapid growth and external scrutiny.

That combination means regulatory exposure and audit scrutiny from partners who take content security seriously. Reporting to the Information Security Officer, you will own the risk register and the appetite framework behind it, independent verification of controls that Engineering, Security Engineering, and IT build and operate, the control catalog and evidence program supporting NIST CSF 2.

0, SOX ITGC, and TPN, third-party risk across the vendor lifecycle, security policy and awareness, and the metrics and reporting that senior leadership relies on to make risk acceptance decisions. Independence is the point of the role. You will assure controls you did not build, audit technical standards written by the engineers who own them, and tell senior stakeholders when residual risk exceeds what the business has agreed to carry.

That takes someone who can hold that line with credibility rather than authority. This is a build role, not a maintenance one. You will stand the function up from the ground, and grow it into a team as the program matures.

Responsibilities

Enterprise cyber risk Operate and mature the risk register from initial population to a sustained program: scoring methodology, business impact analysis, and treatment-versus-acceptance decisions tracked to closure with named owners. Facilitate the executive risk review cycle, surfacing residual risks that exceed appetite.

Maintain the risk appetite framework so that scoring, escalation thresholds, and "exceeds appetite" triggers stay aligned to what the Audit Committee has approved, and support its annual review. Independent assurance Verify that controls built and operated by Engineering, Security Engineering, and IT are designed correctly and working, maintaining separation between those who build controls and those who assure them.

This includes auditing technical standards authored by Security Engineering, such as firewall and hardening baselines, against policy and framework requirements. Own the control evidence program in Vanta: every control with an assigned owner and defined evidence, collected on cadence, with coverage and freshness monitored and gaps closed ahead of audits.

Track control deficiencies to remediation and report residual exposure to leadership. Compliance and audit readiness NIST CSF 2.0, SOX ITGC, and TPN. Plan and run internal audits, perform and document control testing, support external assessments, and lead customer and partner security due diligence. Third-party risk Own the vendor security program end to end: intake, security review, risk rating, attestation collection, and ongoing monitoring across the vendor lifecycle.

Partner with Legal and Procurement to get security requirements into onboarding and contracts. Policy and control framework Author and maintain security policies, and drive them through ratification, distribution, and tracked acknowledgment where they bind individuals, including contractors before access is granted. Manage the control catalog that maps Cosm's controls to its frameworks, and coordinate control ownership across the organization.

Technical standards are authored by Security Engineering; you review them for policy alignment and audit against them. Security awareness Own the awareness and role-based training program end to end: content, cadence, delivery, phishing simulation, completion tracking, and role-specific training for administrators, privileged users, and developers.

Board reporting and metrics Design the metrics framework, KPIs and KRIs tied to risk appetite rather than activity volume. Define the escalation triggers that force an off-cycle report to the Audit Committee, such as a critical vulnerability past its SLA or a control failure in a high-criticality area. Produce the quarterly Audit Committee package: maturity movement with rationale, top gaps with owners and dates, incidents mapped to previously identified gaps, and resourcing tied to specific exposures.

Present to senior leadership, the Cybersecurity Executive Steering Committee, and the Audit Committee. Incident support Provide risk, control, and impact context to the decision-makers assessing whether an incident is material, and own the control and maturity findings that come out of post-incident review. Experience: 8 to 12 years in IT governance, risk, and compliance, including leading GRC programs or major initiatives in enterprise environments Hands-on experience operating and maturing risk registers, running risk assessments, gap analyses, and business impact analyses, and driving treatment decisions to closure Independent control testing experience supporting SOX ITGC Experience planning and executing internal audits Experience owning a third-party risk program, including review of vendor security attestations Experience running continuous-compliance and evidence collection in a GRC platform.

We use Vanta Expertise authoring IT and security policies that meet regulatory requirements, and running them through review, ratification, and acknowledgment Track record producing board or audit-committee-level reporting on maturity, risk posture, and remediation, and designing metrics tied to risk appetite Experience building training and awareness programs Deep working knowledge of NIST CSF 2.

0 and 800-53; familiarity with SOC 2, ISO 27001, COBIT, and CIS Controls Ability to explain complex risk to non-technical senior stakeholders and influence decisions Bachelor's degree in a related field, or equivalent experience Helpful, not required: content, media, or entertainment security experience including TPN; certifications such as CISM, CRISC, CISA, CGEIT, or CISSP.

The annualized salary range for this position in California is $210,000 to $225,000. The base pay offered will factor in internal equity and may also vary depending on the candidate's geographic region, job-related knowledge, skills, and relevant experience, among other factors All applicants must be at least 18 years of age at the time of employment.

This requirement is in accordance with applicable federal, state, and local labor laws. Cosm is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.

Description copied from Cosm's careers page. Read the full posting before you apply.

More jobs at Cosm

See all openings at Cosm

More jobs in Los Angeles