Назад
Company hidden
5 часов назад

Director, Cybersecurity GRC

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
director
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Director, Cybersecurity GRC (Cybersecurity/GRC): Leading governance, risk, compliance, audit support, and cybersecurity program activities for a cloud software provider with an accent on ISMS governance, regulatory alignment, client audits, and contractual compliance. Focus on managing GRC people, processes, and technology, integrating AI governance, assessing technical controls, and translating executive priorities into operational cybersecurity initiatives.

Location: Remote, United States only. Employment requires eligibility to work in the United States without sponsorship.

Company

Cloud software and services support more than 20,000 purpose-driven organizations in over 30 countries across fundraising, learning, events, careers, volunteering, accounting, and association management.

What you will do

  • Lead the cybersecurity Governance, Risk, and Compliance program, including governance, risk assessments, compliance operations, audit support, and GRC technology.
  • Maintain and improve the Information Security Management System, including policies, standards, procedures, controls, metrics, and risk treatment plans.
  • Support client audits, RFP responses, regulatory reviews, contract assessments, and compliance with applicable regulatory and certification requirements.
  • Partner with Cybersecurity Operations, Engineering, Legal, business owners, and the Director of AI Governance to integrate security and AI governance practices.
  • Manage the GRC team, budget, third-party risk activities, awareness program, phishing simulations, and executive reporting.
  • Contribute to incident response, disaster recovery and business continuity planning, cybersecurity strategy, and roadmap development.

Requirements

  • 10–12+ years of cybersecurity experience, including 3–5 years in leadership or program management.
  • Experience with at least one major eGRC or ITGRC platform, such as ServiceNow GRC, Archer, OneTrust, or LogicGate.
  • Strong knowledge of NIST CSF, CIS Controls, SOC 2 Type 2, COBIT, and common regulatory schemes including GDPR, PCI-DSS, GLBA, FISMA, HIPAA, and ITAR.
  • Advanced understanding of technical controls, risk mapping, network and infrastructure concepts, Active Directory, SIEM, IDS, log management, and vulnerability assessment.
  • Strong leadership, communication, public speaking, analytical, prioritization, and operational oversight skills.
  • Must be eligible to work in the United States without sponsorship.

Nice to have

  • CISSP, CISM, or CRISC certification.
  • ISO 27001 Lead Implementer or Lead Auditor certification.

Culture & Benefits

  • Remote work flexibility and work-life balance.
  • Medical, dental, and vision benefits.
  • 401(k) savings plan with company match.
  • Flexible planned paid time off, generous sick leave, and employer-paid parental leave.
  • Employer-paid short-term disability coverage and an inclusive, purpose-driven culture.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →