Назад
Company hidden
обновлено 10 дней назад

Manager, Information Security Assurance Services (Cybersecurity GRC)

146 428 - 198 108$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Manager, Information Security Assurance Services (Cybersecurity GRC): Leading and maturing enterprise information security assurance programs across governance, control frameworks, audits, PCI DSS, third-party risk, policy governance, and security awareness with an accent on automation, regulatory alignment, and measurable control effectiveness. Focus on building scalable GRC capabilities, managing assurance professionals, improving evidence collection and control testing, and translating complex risk topics for executives, auditors, and regulators.

Location: Remote

Salary: $146,428–$198,108 per year

Company

hirify.global provides financial and insurance-related services focused on helping people manage money and live balanced, generous lives.

What you will do

  • Lead and continuously mature governance, controls design and testing, audit and regulatory response, security awareness, policy governance, third-party risk management, and the PCI DSS program.
  • Own control frameworks, control libraries, framework mappings, evidence models, and remediation processes aligned with NYDFS Part 500, NIST Cybersecurity Framework, CIS Controls, HIPAA, FDIC requirements, and PCI DSS v4.x.
  • Direct internal and external audit responses, regulatory examinations, PCI engagements, evidence packages, management responses, and high-risk remediation activities.
  • Build scalable processes and automate evidence collection, control testing, reporting, and assurance workflows using GRC/IRM platforms such as ServiceNow IRM.
  • Define KPIs and KRIs, deliver executive and board-ready reporting, and translate risk priorities into roadmaps, OKRs, and delivery plans.
  • Manage, coach, and develop a multidisciplinary assurance team while partnering with business, technology, regulatory, and third-party stakeholders.

Requirements

  • At least 10 years of progressive experience in GRC, information security, technology risk, audit, controls, or cybersecurity assurance.
  • At least 5 years of direct people leadership experience, including coaching, performance management, workforce planning, and talent development.
  • Hands-on experience with PCI DSS scope definition, control design, testing, remediation, evidence management, and QSA/ISA interaction.
  • Strong knowledge of NYDFS Part 500, NIST Cybersecurity Framework, CIS Controls, PCI DSS, IT general controls, and application-level controls.
  • Experience communicating complex risk and control topics to executives, audit committees, regulators, and cross-functional stakeholders.
  • Bachelor’s degree in Information Security, Computer Science, Information Systems, a related discipline, or equivalent professional experience.

Nice to have

  • Experience with ServiceNow IRM or comparable GRC platforms such as Archer, AuditBoard, OneTrust, or MetricStream.
  • Experience with product operating models, roadmap planning, backlog grooming, sprint delivery, and metrics-driven execution.
  • Financial services, banking, or other highly regulated industry experience, including interaction with banking regulators.
  • CISSP, CISA, CISM, CRISC, CGEIT, or CIA certification.
  • Experience improving control automation, continuous control monitoring, assurance testing efficiency, audit readiness, or evidence-as-code practices.

Culture & Benefits

  • Full-time employee position with a remote work arrangement.
  • Potential bonuses, including annual or long-term incentives.
  • Medical, dental, and vision insurance, plus health savings and flexible spending accounts.
  • 401(k), pension, life, disability, and supplemental protection insurance.
  • 20 days of paid time off, sick and safe time, paid holidays, volunteer time off, paid parental leave, and well-being benefits.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →