
Director β Governance, Risk and Compliance
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in United States.
β’ Spearhead initiatives to evaluate the confidentiality, integrity, and availability of information via the company's global ISMS framework.
β’ Create and uphold ISMS documentation, which encompasses policies, standards, and procedures.
β’ Advise the CISO, Product Management, Legal, and Finance leadership teams on aligning the security program with compliance requirements.
β’ Oversee information risk and collaboratively design and evaluate information security controls, including identity and access management.
β’ Keep track of regulatory environments, security threats, and compliance best practices; revise policies and procedures accordingly.
β’ Enhance and sustain organizational information security awareness.
β’ Convert business and information security requirements into the ISMS framework.
β’ Organize external audits with 3PAO, ISO/SOC auditors, PCI DSS QSA firms, and other assessors.
β’ Coordinate responses to audits and remediation initiatives.
β’ Perform vendor risk evaluations and ensure third-party adherence to security and privacy standards.
β’ Review and supervise Security Incident Response and Business Continuity Management activities.
β’ Assess the effectiveness of ISMS controls and communicate results to senior management.
β’ Implement document control management processes for the ISMS.
β’ Support forecasting, planning, and risk evaluation aligned with technology strategy.
β’ Stay updated with industry knowledge and suggest new technologies.
β’ Manage projects, including requirements analysis, project planning, and tracking completion.
β’ Assist with vendor management, forecasting, and program budget oversight.
β’ Guide personnel through mentoring and cross-training.
β’ Must be a US Citizen.
β’ At least 10 years of practical experience in IT audit and/or compliance.
β’ Excellent documentation and communication abilities.
β’ Strong comprehension of the ISO27000 series, NIST Special Publication 800 series, SOC audits, and the security requirements of Data Privacy laws.
β’ Prior experience in obtaining an ATO or P-ATO for a cloud deployment under FedRAMP, GovRAMP, or IL-4 programs.
β’ Knowledge of software development lifecycle methodologies, cloud and server infrastructure, and network technologies.
β’ Experience in managing security personnel and collaborating with global teams.
β’ Proficient in written and spoken English.
β’ Current CISA, CISM, CISSP, or equivalent certification is highly preferred.
β’ Must be legally authorized to work in the country of the role.
β’ Must maintain work authorization throughout the duration of employment.
β’ No visa sponsorship or immigration assistance will be provided.
β’ Additional compensation options, such as company bonuses or benefits.
β’ Equal employment opportunity/affirmative action protections.
biBerk Business Insurance
Doppel
PingWind Inc. (SDVOSB)
The Standard
Get handpicked remote jobs straight to your inbox weekly.