5 часов назад
Director, Cybersecurity GRC
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Director, Cybersecurity GRC (Cybersecurity/GRC): Leading governance, risk, compliance, audit support, and cybersecurity program activities for a cloud software provider with an accent on ISMS governance, regulatory alignment, client audits, and contractual compliance. Focus on managing GRC people, processes, and technology, integrating AI governance, assessing technical controls, and translating executive priorities into operational cybersecurity initiatives.
Location: Remote, United States only. Employment requires eligibility to work in the United States without sponsorship.
Company
Cloud software and services support more than 20,000 purpose-driven organizations in over 30 countries across fundraising, learning, events, careers, volunteering, accounting, and association management.
What you will do
- Lead the cybersecurity Governance, Risk, and Compliance program, including governance, risk assessments, compliance operations, audit support, and GRC technology.
- Maintain and improve the Information Security Management System, including policies, standards, procedures, controls, metrics, and risk treatment plans.
- Support client audits, RFP responses, regulatory reviews, contract assessments, and compliance with applicable regulatory and certification requirements.
- Partner with Cybersecurity Operations, Engineering, Legal, business owners, and the Director of AI Governance to integrate security and AI governance practices.
- Manage the GRC team, budget, third-party risk activities, awareness program, phishing simulations, and executive reporting.
- Contribute to incident response, disaster recovery and business continuity planning, cybersecurity strategy, and roadmap development.
Requirements
- 10–12+ years of cybersecurity experience, including 3–5 years in leadership or program management.
- Experience with at least one major eGRC or ITGRC platform, such as ServiceNow GRC, Archer, OneTrust, or LogicGate.
- Strong knowledge of NIST CSF, CIS Controls, SOC 2 Type 2, COBIT, and common regulatory schemes including GDPR, PCI-DSS, GLBA, FISMA, HIPAA, and ITAR.
- Advanced understanding of technical controls, risk mapping, network and infrastructure concepts, Active Directory, SIEM, IDS, log management, and vulnerability assessment.
- Strong leadership, communication, public speaking, analytical, prioritization, and operational oversight skills.
- Must be eligible to work in the United States without sponsorship.
Nice to have
- CISSP, CISM, or CRISC certification.
- ISO 27001 Lead Implementer or Lead Auditor certification.
Culture & Benefits
- Remote work flexibility and work-life balance.
- Medical, dental, and vision benefits.
- 401(k) savings plan with company match.
- Flexible planned paid time off, generous sick leave, and employer-paid parental leave.
- Employer-paid short-term disability coverage and an inclusive, purpose-driven culture.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Senior GRC Security Specialist (Cybersecurity)
6 дней назад
Lead Security Analyst - GRC (Cybersecurity)
138 000 - 215 625$
12 часов назад
Cyber Governance, Risk & Compliance Lead (GRC)
50 000 - 60 000GBP
5 дней назад
Senior IT Governance & Compliance Manager (AI GRC)
115 000 - 140 000$
6 дней назад
GRC Security Analyst (AI Governance)
114 000 - 139 000$
3 дня назад
Sr. Cyber Risk 3rd Party Analyst
145 900 - 234 200$