Sr Manager, InfoSec Governance Risk and Compliance (GRC)
Core
Lead the global Governance, Risk, and Compliance (GRC) program to ensure adherence to security standards and certifications while managing supply chain risks.
Role type
Senior Manager, InfoSec GRC
Builds
Global GRC program, compliance certifications, security awareness culture
Domain
Information Security, Cloud Procurement, Supply Chain
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
GRC program leadership, compliance audit management, security frameworks expertise, stakeholder influence, project management, policy development, third-party risk management
Preferred skills
Team management, cross-functional collaboration, independent initiative
Technologies
NIST SP 800-53, NIST 800-171, ITAR, FedRAMP, PCI DSS, SOC2, ISO 27001, HIPAA, IRAP
Responsibilities
Lead and own the global GRC program; Manage and drive compliance efforts and audits for certifications; Serve as SME on security frameworks; Manage customer security audit requests; Maintain continuous compliance monitoring; Collaborate with Sales/Marketing on security posture; Review and negotiate security exhibits; Lead Security Awareness and Training program; Track and drive remediation for control deficiencies; Oversee Third Party Risk and Vendor Security Assessment; Develop and enforce InfoSec policies.
Seniority
Senior, hands-on IC with team leadership
