Job Summary
We are seeking a highly skilled GRC Specialist with 8 to 12 years of experience to join our team. The ideal candidate will have expertise in Vulnerability Management Compliance Management SOC1(Type1&2)/SAAE18/SSAE16 SharedAssessment(SIGQuestion) Governance & Compliance-PCI DSS Governance & Compliance - GDPR Governance & Compliance - CCPA Risk Management Vendor Risk Management Policy Management and Audit Management. This is a hybrid role with day shifts and no travel required.
Responsibilities
Lead the development and implementation of GRC frameworks to ensure compliance with industry standards and regulations.Oversee vulnerability management processes to identify assess and mitigate security risks.Provide expertise in compliance management to ensure adherence to SOC1(Type1&2)/SAAE18/SSAE16 standards.Conduct SharedAssessment(SIGQuestion) evaluations to assess vendor risk and ensure compliance.Implement and manage governance and compliance programs for PCI DSS GDPR and CCPA.Develop and maintain risk management strategies to identify assess and mitigate potential risks.Manage vendor risk by conducting thorough assessments and ensuring compliance with company policies.Oversee policy management processes to ensure policies are up-to-date and in compliance with regulations.Conduct regular audits to ensure compliance with internal and external standards.Provide guidance and support to internal teams on GRC-related matters.Collaborate with cross-functional teams to ensure alignment with GRC objectives.Monitor and report on GRC metrics to senior management.Stay up-to-date with industry trends and best practices in GRC.
Qualifications
Must have strong experience in Vulnerability Management.Should have expertise in Compliance Management.Must be knowledgeable in SOC1(Type1&2)/SAAE18/SSAE16 standards.Should have experience with SharedAssessment(SIGQuestion).Must be proficient in Governance & Compliance-PCI DSS GDPR and CCPA.Should have strong skills in Risk Management.Must have experience in Vendor Risk Management.Should be proficient in Policy Management.
Certifications Required
Certified Information Systems Auditor (CISA) Certified in Risk and Information Systems Control (CRISC)