Sr Manager, InfoSec Governance Risk and Compliance (GRC)
Core
Lead the global Governance, Risk, and Compliance (GRC) program to ensure adherence to security standards and certifications, managing audits and mitigating risks for a cloud-based procurement platform.
Role type
Senior Manager, InfoSec GRC
Builds
Global GRC program, compliance certifications, security audit responses, third-party risk assessments
Domain
Cloud Security, Information Security Governance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
GRC program leadership, compliance certification management, security framework expertise, stakeholder management, project management, policy development, third-party risk assessment
Preferred skills
Team leadership, security awareness training, contract negotiation, audit remediation
Technologies
FedRAMP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, IRAP, NIST SP 800-53, NIST 800-171, ITAR
Responsibilities
Lead and own the global GRC program; manage and drive compliance efforts and audits; serve as SME on security frameworks; manage customer security audit requests; maintain continuous compliance monitoring; collaborate with Sales and Customer Success; review security exhibits and contracts; lead Security Awareness and Training; track and drive remediation of control deficiencies; oversee Third Party Risk and Vendor Security Assessment; develop and enforce InfoSec policies.
Seniority
Senior Manager, hands-on leadership
