
Senior Governance Risk and Compliance Associate – Third Party Risk
Posted Aug 28

Posted Aug 28
This is a fully remote position, open to applicants in United States.
• Oversee and examine cybersecurity risks, threats, and potential opportunities.
• Recognize, assess, and recommend strategies for mitigating incidents across strategic, business, operational, and technical areas.
• Collaborate in the development and maintenance of operational policies, standards, playbooks, guidelines, and procedures.
• Assist in the implementation of technical platforms and process enhancements that bolster cybersecurity.
• Conduct compliance gap analyses and generate risk and remediation reports.
• Engage in internal cybersecurity initiatives that improve organizational resilience.
• Work together on incident response and use case development.
• Support Third-Party Risk Management (TPRM) initiatives and vendor evaluations.
• Help with the administration, monitoring, and reporting for designated technology platforms.
• Aid in business continuity planning and disaster recovery compliance, data loss prevention, third-party risk management, and incident response efforts.
• Perform additional tasks assigned by the manager.
• Bachelor’s degree in a related field or a comparable combination of education and experience.
• Over 5 years of industry and/or relevant experience, typically including at least 1 year in an Associate level position or external equivalent.
• More than 4 years in Governance, Risk, Compliance, Audit, or Cybersecurity roles.
• Possession of at least one certification, such as CISSP, CISM, CISA, CRISC, CCSP, or an equivalent.
• Experience in applying risk management frameworks to identify and monitor risks and associated action items.
• Capability to assist with risk assessments, compliance gap analyses, and remediation planning.
• Practical proficiency with information security tools related to attack surface management, email security, data security posture management, and data loss prevention.
• Familiarity with supporting Third-Party Risk Management (TPRM) activities and vendor assessments.
• Working knowledge of incident investigation techniques and incident response procedures.
• Ability to develop policies, identify compliance challenges, and establish risks for monitoring.
• Comprehensive understanding of cybersecurity principles and network security.
• Knowledge of Mac, Windows, and Linux endpoints and operating systems.
• Awareness of AWS and Azure cloud security best practices.
• Ability to create, monitor, enhance, and report on Key Risk Indicators (KRIs).
• Understanding of regulatory requirements and frameworks, including GDPR, CCPA, PCI, SOX, GLBA, and NIST.
• Insight into how compliance with laws and regulations impacts security strategy.
• Strong analytical, problem-solving, and interpersonal capabilities.
• Excellent skills in communication, documentation, and stakeholder management.
• Competence in producing reports, dashboards, and technical documentation.
• Eligibility for discretionary bonuses for specific positions.
• Paid time off (PTO).
• Paid holidays.
• Medical insurance.
• Dental insurance.
• Vision insurance.
• Life insurance.
• Disability insurance.
• Participation in a 401(k) plan.
LabConnect
Ripple Effect
Binance
biBerk Business Insurance
Get handpicked remote jobs straight to your inbox weekly.