TL;DR
Risk Specialist (GRCP): Managing third-party security, compliance, and privacy risk assessments for SaaS/cloud vendors with an accent on reducing third-party risks and ensuring compliance with frameworks like SOC2, ISO27001, GDPR. Focus on conducting reviews, collaborating with internal teams, and improving due diligence processes.
Location: Remote within the United States or onsite in San Francisco, CA or Austin, TX
Salary: $148,000 - $222,000 USD
Company
hirify.global is a no-code app platform empowering organizations to accelerate critical business processes, trusted by over 500,000 organizations including 80% of the Fortune 100.
What you will do
- Conduct third-party security and privacy reviews on software, contractors, and services to reduce risks
- Identify business risks and recommend risk treatment options to stakeholders
- Define security contract requirements and liaise with Procurement and Legal teams
- Communicate with vendors and internal teams for compliance reviews, validations, and audits
- Perform annual reviews on critical vendors to meet compliance and customer requirements
- Collaborate cross-functionally to improve third-party due diligence processes
Requirements
- Must be located in the United States for remote work or onsite in San Francisco or Austin
- General understanding of security, compliance, and privacy frameworks such as SOC2, ISO27001, ISO27701, GDPR, CCPA
- Experience with SaaS/cloud suppliers and public cloud solutions (AWS)
- Ability to manage multiple projects independently and drive process improvements
- Detail-oriented, organized, and flexible to changing priorities
Nice to have
- Certifications such as CISA or CISSP
Culture & Benefits
- Equal opportunity employer embracing diversity and inclusion
- Comprehensive benefits package including restricted stock units and incentive compensation
- Remote work flexibility within the US
- Support for accommodations during application and interview process
Будьте осторожны: если вас просят войти в iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →