As Director, Governance Risk and Compliance (GRC), you will be a hands-on people leader
responsible for our security governance, risk, and compliance programs in a technology-driven
organization. Partnering with our technology, business and legal teams, you will play a key role
in influencing the organization’s cybersecurity posture through assessing and driving remediation
of security risks and ensuring compliance with relevant frameworks and contracts. Your technical
expertise of security frameworks and understanding of cloud infrastructure will be crucial in
ensuring security posture aligns with industry best practices. This role offers the opportunity to
make strategic decisions, provide valuable recommendations, and collaborate with a broad group
of bright and energetic individuals throughout the company.
• Drive adoption of relevant security compliance requirements through thorough analysis
and prescriptive guidance
• Define and lead security risk management process, leveraging automation and partnering
with stakeholders to perform hands-on risk assessments
• Oversee the policies and standards lifecycle process to ensure they address all relevant
cybersecurity requirements
• Define and lead cybersecurity awareness programs including annual training, topical
awareness campaigns in partnership with corporate communications, and phishing
simulations
• Proactively identify compliance gaps through continuous monitoring, working closely
with control owners to identify ways to effectively monitor compliance posture through
automation
• Oversee documentation and reporting identified security or compliance issues and work
with control owners on remediation requirements, strategy, and execution, providing
recommendations that can be reasonably adopted
• Regularly monitor remediation activities for noted findings, and escalate on remediation
plans that are at-risk of being overdue
• Develop and maintain security reporting to provide real-time and on-demand compliance
status
• Maintain an up-to-date understanding of emerging trends in information security risks;
apply new techniques and trends, in-line with overall information security objectives
• Establish partnerships with cross-functional teams such as IT, Legal, HR and Privacy to
ensure they understand their roles when supporting the security GRC programs
• Partner with the broader security team in establishing annual and long-term goals,
objectives, metrics, and reporting mechanisms
Software Powered by iCIMS
www.icims.com