
Senior Security Governance, Risk & Compliance Specialist
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Assist in the development and enhancement of the organization's Security GRC program.
• Ensure that IT, Product, and Information Security controls are in line with policies, standards, regulations, and best practices.
• Organize and facilitate external client audits, certifications, and assessments, including SOC 1, SOC 2, ISO 27001/2700x, client audits, and other evaluations or accreditations.
• Assess compliance status, identify control deficiencies, create remediation plans, monitor progress, and drive issues to resolution.
• Aid in the risk management framework, encompassing inherent and residual risk assessments, risk tolerance evaluations, risk discussions, and both internal and third-party risk assessments.
• Evaluate, monitor, and manage information security risks linked to third parties, vendors, and external partners.
• Assist with audit responses, client questionnaires, RFPs, findings, and assurance requests.
• Create, maintain, and govern Information Security policies, standards, procedures, and documentation.
• Identify and suggest enhancements to IT and Information Security compliance processes.
• Implement ISO/IEC 27001, NIST, COBIT, and ITIL frameworks.
• Generate compliance and risk reports, metrics, and management insights.
• Support security education and awareness initiatives.
• Collaborate with both technical and non-technical teams and influence stakeholders.
• Contribute to GRC tools, platforms, processes, and operational procedures.
• Manage multiple initiatives and deliverables while ensuring quality and attention to detail.
• Undertake other related duties and projects as assigned.
• Bachelor’s degree in Information Systems, Information Technology, Cybersecurity, or a related discipline; an Associate’s degree may be accepted based on relevant experience and certifications.
• Over 5 years of experience in Information Technology, Information Security, Governance, Risk, and/or Compliance.
• Significant experience in building, maintaining, or enhancing Security Governance, Risk, and Compliance programs.
• Strong comprehension of information security risk management and compliance methodologies.
• Proven experience in facilitating and leading risk discussions utilizing both qualitative and quantitative data.
• Familiarity with ISO/IEC 27001, NIST Cybersecurity Framework, NIST 800-53, COBIT, and ITIL.
• Experience in supporting or coordinating security audits, assessments, certifications, and client assurance activities.
• Experience in managing third-party/vendor security risks.
• Understanding of solution lifecycle management and associated information security and compliance requirements.
• Experience in developing and implementing SOPs, policies, and processes.
• Capacity to influence and work collaboratively with stakeholders at various levels without formal authority.
• Ability to establish and utilize internal and external cross-functional relationships.
• Strong business acumen with the ability to translate business needs into practical security and compliance solutions.
• Exceptional written and verbal communication skills for both technical and non-technical audiences.
• Experience collaborating with globally distributed teams and stakeholders.
• Adaptability to changing security risks, regulations, technologies, and business needs.
• Preferred relevant security certifications such as CISSP, CRISC, CISM, CISA, or FAIR.
• Competitive salary and performance-based incentives.
• Comprehensive health, dental, and vision insurance plans.
• Opportunities for professional development and continuous learning.
• Flexible work arrangements, including remote working options.
• A collaborative and inclusive work environment.
Coalfire
Ennoble Care
Telix Pharmaceuticals Limited
Get handpicked remote jobs straight to your inbox weekly.