Role OverviewWe are seeking a hands-on technical manager to join an impactful Information Security Governance, Risk, and Compliance (GRC) team. The role will support an enterprise-wide governance, risk, and compliance program focusing on security control assurance, security risk management, policies and standards, continuous control monitoring, and ensuring compliance with internal and external security requirements.
What You Will Do
The primary responsibilities include managing a security control assurance program, managing compliance with external regulatory obligations, building a continuous control monitoring program, interfacing with technical engineering teams, reporting on compliance and control assessment results, and leading a team of practitioners.
Why It Might Be a Fit
An ideal candidate cares deeply about automation and reducing friction, with technical depth and communication range to brief audiences from system engineers to senior leadership. The candidate should possess competencies that allow them to bring noticeable and measurable improvements in some of the above-mentioned areas.
Requirements
- Domain expertise in cyber security standard methodologies and security control frameworks
- Experience in a public company environment managing compliance across multiple regulatory and security frameworks
- Technical understanding of security controls, identifying control objectives, and how to implement them in a complex enterprise IT environment
- Ability to creatively develop and refine control tests tailored to specific control implementations
- 8+ years progressively responsible experience in information security governance, risk, compliance, or security assessment/audit
- 4+ years of security control assessment experience
- 2+ years of related experience leading or managing others
- Professional security management certification, such as a CISSP, CISA, CISM, or CRISC
- Bachelor's degree in Information Systems, Computer Science, or related field, or equivalent experience
Benefits
- Competitive benefits
- Discretionary bonus based on individual and company performance
- Certain roles may be eligible for discretionary stock awards
]]>