Senior Staff InfoSec Risk Specialist (GRC)
Core
Own the Security Risk Program, identifying, scoring, prioritizing, and driving down technical risk across the company while building predictive risk management capabilities.
Role type
Senior Staff Information Security Risk Specialist (GRC)
Builds
Governance, automation, and review processes for a predictive risk management capability.
Domain
Cybersecurity / GRC / Risk Management
Deliverable
production ML models | dashboards & analysis | client delivery
Required skills
Cybersecurity risk management, ISO 27005 methodology, GRC function building, executive communication, Jira mastery, risk register management, technical oversight of analysts
Preferred skills
AI/ML risk assessment, threat intelligence integration, SQL/Python/Automation, acting as GRC deputy
Technologies
Jira, SQL, Python, Google Apps Script, ISO 27005, NIST CSF, SOC 2, FedRAMP
Responsibilities
Own the Security Risk program cadence, scoring, reporting, and SOPs; Contribute to GRC functional strategy and roadmap; Manage escalation paths for critical risks; Validate likelihood and impact scoring; Enforce triage service levels; Prepare and facilitate recurring risk reviews; Adjudicate risk treatment decisions; Build automation and AI-assisted workflows for risk management.
Seniority
Senior Staff, hands-on IC with strategic oversight
