In pursuit of digital trust
Certification Program Compliance and Risk Manager
Location
United States
Posted
3 days ago
Salary
$85.8K - $128.8K / year
Seniority
Senior
Job Description
Certification Program Compliance and Risk Manager
ISACA
• Identify and document risk scenarios and work with internal and external stakeholders to develop, implement, and test controls to mitigate impact. • Maintain ISACA’s Certification Impartiality Threat Analysis to address emerging threats within ISACA’s certification landscape. • Own the governance, review, and continuous improvement of the Certification Policies and Procedures Manual, ensuring certification policies, processes, and controls remain compliant with ISO/IEC 17024:2026 requirements. • Assess the impact of policy changes, identify compliance risks and gaps, and partner with Sr. Management to implement corrective actions and maintain accreditation readiness. • Manage the completion and maintenance of ANSI accreditation process documentation required for the annual surveillance application of ISACA certification programs. • Coordinate with internal stakeholders to gather, review, and validate evidence of compliance with accreditation requirements, ensuring documentation is accurate, complete, and submitted within established timelines. • Assist in the evaluation of surveillance findings, contribute to root cause analyses of identified nonconformities, and manage the development, implementation, monitoring, and validation of corrective actions to address compliance risks and maintain continued accreditation status for ISACA certifications. • Maintain and update certification-control documents (ECG, CPE Policy,) and verify ISACA external (e.g. website) information aligns to updated policy or procedures. • Conduct compliance reviews of the certification management system to ensure continuous compliance with the ISO/IEC 17024:2026 Standard. • Conduct periodic certification management system review meetings with Senior Management to identify inefficiencies and potential enhancements, document and implement resolutions. • Oversee the conduct of investigations into suspected fraudulent cases, document findings, and report to appropriate stakeholders. • Develop and analyze KRIs for each certification-related risk. • Coordinate with legal, cybersecurity, IT and product teams to address large-scale certification fraud. • Analyze data and create reports for management on potential fraud risks, trends, and the results of investigations. • Prepare and present certification compliance metrics, annual assessment results, and accreditation-related reporting for governance bodies, including the Audit and Risk Committee (ARC), ensuring transparency, accountability, and informed decision-making. • Manage the Certification Audit Program and serve as liaison to annual policy audits. • Manage reports related to credentialing status, compliance metrics, and operational performance. • Manage the Preventive and Corrective Actions Tracking process and worksheet to ensure identified controls have been implemented according to the timeline.
Job Requirements
- Bachelor's degree in business, Law, Certification, Risk, or related field
- 5+ years of experience in accreditation credentialing standards (e.g.ANAB ISO/IEC 17024), compliance, quality assurance, risk mitigation, exam security and fraud prevention including minimum of 2 years or supervisory or project management.
- 3+ years of direct experience managing certification program governance, risk, compliance, or accreditation activities.
- Experience supporting accredited certification programs and maintaining compliance with accreditation standards (e.g., ANAB ISO/IEC 17024), including applying regulatory, legal, and ethical requirements in credentialing environments.
- Proven track record in enterprise risk management, including risk identification, assessment, mitigation planning, risk register management, and development of compliance monitoring frameworks and internal controls.
- Experience managing compliance operations, including corrective and preventive action (CAPA) processes, audit readiness activities, and execution of compliance reviews or accreditation assessments.
- Advanced experience overseeing credentialing integrity functions, including investigation of exam irregularities, misconduct, and certification violations, as well as implementation of exam security, fraud prevention, and test integrity controls.
- Proficiency in developing governance documentation, including policies, SOPs, procedures, and control frameworks.
- Advanced skills in analyzing compliance and operational data, building dashboards and risk reporting tools, and preparing and presenting findings to leadership.
- Experience working with certification management systems or credentialing platforms, as well as workflow or case management tools (e.g., Jira or similar systems).
- Proven track record managing cross-functional initiatives and stakeholder groups across compliance, operations, and program functions.
Benefits
- ISACA Career Opportunities and Benefits Options
Related Guides
Related Categories
Related Job Pages
More Compliance Jobs
• Represent Regulatory Affairs in various internal cross-functional project teams, improvement initiatives and providing regulatory positions on various CMC related topics. • Manage the collection, review, coordination, and preparation of documentation for regulatory CMC submissions, including maintaining comprehensive trackers for documentation requests and timelines. • Manage preparation of responses to queries from regulatory authorities. • Ensure conformance to commitments made with various regulatory agencies. • Collaborate with cross-functional project teams and external business partners to develop regulatory strategies and identify regulatory risks. • Manage coordination, preparation, and timely submission of regulatory documents and filings. • Review and approve change controls related to proposed product/process changes and assess their impact against regulatory requirements. • Cultivate productive working relationships with the Regulatory team and other departments. • Coordinate responses to CMC-related queries from Health Authorities.
• Review, redline, and approve marketing and advertising materials submitted by loan officers, branches, and corporate marketing, including flyers, mailers, rate sheets, open-house collateral, presentations, and co-branded materials. • Evaluate all triggered-term advertising for required disclosures under TILA / Regulation Z §1026.24 (e.g., APR, payment, term, and rate disclosures), ensuring clear and conspicuous presentation. • Screen content for prohibited, deceptive, or misleading representations under the MAP Rule (Regulation N, 12 CFR Part 1014), including claims about rates, payments, government affiliation, FHA/VA programs, and “too good to be true” offers. • Confirm proper use of company NMLS ID, individual LO NMLS IDs, Equal Housing Lender language, licensing footers, and required state-specific advertising disclosures. • Audit company and loan-officer websites, landing pages, and microsites for accurate licensing disclosures, disclaimers, and compliant rate/payment presentations. • Review social media posts, paid digital ads, email campaigns, video, and text/SMS marketing for advertising-rule compliance across all channels. • Monitor third-party lead-generation, listing-site profiles, and co-marketing arrangements for compliance with advertising rules and RESPA Section 8 marketing-services considerations. • Maintain advertising review logs and retain commercial communications consistent with MAP Rule recordkeeping requirements (24-month retention) and company policy. • Track review turnaround times, recurring deficiencies, and approval status; report trends and risk areas to the Chief Compliance Officer. • Assist with updates to advertising policies, disclosure libraries, and pre-approved template language as regulations and guidance evolve. • Deliver targeted training and feedback to loan officers and marketing staff on common advertising violations and best practices. • Support regulatory examinations, audits, and investor/agency reviews by compiling advertising documentation and responding to findings.
Manager, RAAS I Governance, Risk, and Compliance, GRC
AprioTop 35 business advisory and CPA firm helping clients and team members achieve what's next.
• Lead assessments of financial reporting risks and key business processes, including order-to-cash, procure-to-pay, record-to-report, payroll, inventory, and revenue recognition. • Design, evaluate, and optimize process-level and entity-level controls, with a focus on accuracy, completeness, authorization, and segregation of duties. • Translate accounting and operational risks into practical control recommendations aligned with management’s business objectives. • Review and challenge management’s risk assessments, control narratives, and control rationales for sufficiency and audit-readiness. • Lead all phases of client engagements, including planning, execution, staffing, quality assurance, and reporting. • Serve as a trusted advisor to clients, ensuring alignment with their risk management and compliance objectives. • Partner with CFOs, Controllers, and Finance leaders to address financial reporting risk, audit readiness, and control maturity. • Assist with sales efforts and contribute to expanding the GRC practice. • Identify opportunities for additional services and value-added solutions. • Coach, mentor, and develop team members to support career growth and engagement quality. • Foster a positive, collaborative work environment. • Perform and oversee engagements such as SOX 404 advisory, financial and operational internal audits, SOC 1 examinations, business process reviews, and related compliance frameworks, with a strong emphasis on financial reporting risk and control effectiveness. • Stay current on regulatory changes and industry best practices. • Lead internal projects and contribute to continuous improvement of methodologies and processes. • Approximately 30% travel required.
Senior GRC Analyst
Prosper MarketplaceProviding affordable financial solutions to consumers across the credit spectrum.
• Automated Compliance Monitoring: Review, audit, and monitor security compliance programs against frameworks like PCI-DSS, NIST CSFv2, and SOC 1/2, leveraging automation tools to continuously assess control health • Process Optimization & AI Integration: Identify opportunities to leverage AI tools and LLMs to accelerate risk assessments, summarize complex regulatory requirements, and streamline process improvements • Code-Assisted Evidence Collection: Lead and automate evidence collection for external audits (SOC 1, PCI Level 1), reducing manual overhead for engineering and product teams • Identity & Access Management (IAM): Oversee user access management and quarterly user access reviews, exploring ways to automate provisioning audits and detect anomalies • Cross-Functional Collaboration: Build and cultivate positive working relationships with engineering, DevOps, and product stakeholders to bake compliance directly into the CI/CD pipeline and cloud infrastructure




