
Director, Governance Risk and Compliance
Posted 14 hours ago

Posted 14 hours ago
This is a fully remote position, open to applicants in United States.
β’ Lead initiatives to evaluate the confidentiality, integrity, and availability of information through the organization's global ISMS framework.
β’ Evaluate adherence to company security policies.
β’ Manage internal and third-party risk management processes.
β’ Analyze and assess the effectiveness of information security controls.
β’ Collaborate with and provide guidance to systems architecture, systems deployments, and application configuration teams.
β’ Create and sustain ISMS documentation, encompassing policies, standards, and procedures.
β’ Advise the CISO, Product Management, Legal, and Finance leadership teams on aligning security programs with compliance requirements.
β’ Oversee information risk and collaboratively design and evaluate information security controls, including identity and access management.
β’ Stay informed about evolving regulations, security threats, and compliance best practices, updating policies and procedures as necessary.
β’ Enhance and promote organizational information security awareness.
β’ Convert business and information security requirements into the ISMS framework.
β’ Coordinate external audits with 3PAO, ISO/SOC auditors, PCI DSS QSA firms, and other security evaluators, including managing responses and remediation efforts.
β’ Conduct vendor risk assessments and ensure compliance with security and privacy standards by third parties.
β’ Review and supervise Security Incident Response and Business Continuity Management activities throughout business continuity and disaster recovery phases.
β’ Assess the effectiveness of ISMS controls and communicate results to senior management.
β’ Implement document control management processes for the ISMS.
β’ Support forecasting, planning, and risk assessment for evolving security control coverage in alignment with technology strategy.
β’ Keep abreast of industry knowledge and best practices.
β’ Research and suggest new technologies.
β’ Manage projects, including business requirements analysis, project planning, and completion tracking.
β’ Assist with vendor management, forecasting, and program budget oversight.
β’ Oversee personnel, including mentoring and cross-training team members.
β’ US Citizenship is required.
β’ A minimum of 10 years of hands-on experience in IT audit and/or compliance.
β’ Excellent documentation and communication abilities.
β’ Strong grasp of security standards and frameworks, including ISO27000 series, NIST Special Publication 800 series, SOC audits, and security obligations of Data Privacy laws.
β’ Proven experience in obtaining an ATO or P-ATO for cloud implementations under the FedRAMP, GovRAMP, or IL-4 programs.
β’ Familiarity with software development lifecycle methodologies, cloud and server infrastructures, and network technologies.
β’ Experience in managing security personnel and building collaborative relationships with global teams.
β’ Proficient in written and spoken English.
β’ Current CISA, CISM, CISSP, or an equivalent certification is highly preferred.
β’ Candidates must be legally authorized to work in the country where the position is located at the time of hire and must maintain that authorization throughout their employment.
β’ This position does not offer visa sponsorship or immigration assistance.
β’ Additional compensation such as company bonuses or benefits.
β’ Equal employment opportunity and affirmative action protections.
ERGOMED
L3Harris Technologies
Jerry
Get handpicked remote jobs straight to your inbox weekly.