Назад
Company hidden
7 дней назад

GRC Technical Program Manager (Cloud)

129 200 - 192 500$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
GRC Technical Program Manager (Cloud) (AWS/Azure, AI): Building and improving cloud security compliance programs for assessments and certifications with an accent on risk management, technical controls, and automated evidence collection. Focus on translating regulatory requirements into engineering outcomes, applying AI to compliance workflows, and coordinating complex initiatives across engineering, security, auditors, and hyperscaler partners.

Location: Morrisville, North Carolina, United States; hybrid working environment with in-office and in-person expectations

Salary: 129,200–192,500 USD target range, based on On Target Earnings

Company

hirify.global delivers enterprise data infrastructure, unified storage, integrated data services, and cloud solutions across Google Cloud, AWS, and Microsoft Azure.

What you will do

  • Design, maintain, and improve compliance programs supporting ISO/IEC 27001, SOC 2, PCI DSS, NIST, and FedRAMP assessments and certifications.
  • Perform technical gap and risk assessments across infrastructure, applications, and cloud engineering processes.
  • Translate regulatory controls into measurable engineering and security requirements and advise owners on remediation.
  • Partner with engineering and security teams to automate detection, remediation, evidence collection, and continuous compliance monitoring.
  • Apply AI and related tooling to improve compliance workflows.
  • Coordinate Engineering, SRE, Product, Cloud Security, Legal, Privacy, Corporate Security, auditors, and hyperscaler partners.

Requirements

  • 6+ years of experience building and managing security risk and compliance programs through certification.
  • Deep knowledge of ISO/IEC 27001, SOC 2, PCI DSS, NIST, and FedRAMP.
  • Experience partnering with engineering teams and influencing senior stakeholders and external partners without direct authority.
  • Strong technical fluency in AWS, Azure, Kubernetes, containers, virtual machines, identity and access control, network security, cryptography, logging and monitoring, incident response, DevOps, and CI/CD.
  • Familiarity with SIEM, vulnerability scanning, cloud security posture management, and endpoint detection and response.
  • Bachelor’s or Master’s degree in engineering, computer science, information technology, or a related field, or equivalent professional experience.

Nice to have

  • Experience with FedRAMP, GovRAMP, CMMC, CJIS, NIST 800-53/800-171, or NIST AI RMF and ISO/IEC 42001.
  • Experience applying AI or large language model tooling to compliance workflows.
  • Security, compliance, or cloud certifications such as CISA, CISSP, CRISC, CCSK, CCSP, CIPP, AWS certifications, or ISO 27001 Lead Implementer / Lead Auditor.

Culture & Benefits

  • Hybrid work designed to support collaboration and connection.
  • Health insurance, life insurance, retirement or pension plans, paid time off, and leave options.
  • Employee stock purchase plan and/or restricted stock units, subject to regional variations.
  • Culture focused on initiative, ownership, impact, inclusion, and work-life flexibility.

Hiring process

  • Applications are reviewed through the company website.
  • Some stages may use AI-assisted evaluation tools alongside human decision-making.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →