GRC Specialist (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
GRC Specialist (Cybersecurity): Driving compliance, risk management, and security assurance for a global media technology company with an accent on Third-Party Risk Management (TPRM) and security questionnaires. Focus on mapping evidence to NIST/SSDF frameworks, managing the risk register, and coordinating security audits.
Location: Remote (Must be based in the Philippines). Shift: 6:00 PM to 3:00 AM Manila Time.
Company
provides collaborative technology and tools for creators in film, television, news, and music.
What you will do
- Respond to and maintain customer and partner security questionnaires.
- Own the Third-Party Risk Management (TPRM) program, including vendor intake, assessment, and risk determination.
- Maintain the Risk Register by logging risk acceptances and tracking renewal dates.
- Perform self-assessments against NIST 800-53 and NIST CSF control families.
- Map security pipeline evidence to NIST SSDF and OWASP control practices.
- Coordinate security audits and provide technical security input for contract and data protection reviews.
Requirements
- 2-3+ years of experience in security compliance, audit support, or GRC-adjacent work.
- Familiarity with NIST 800-53, NIST CSF, or SSDF.
- Must be based in the Philippines.
- Strong English written and verbal communication skills.
- Ability to manage multiple parallel workstreams and coordinate with technical and non-technical stakeholders.
Nice to have
- Exposure to SOC 2 or similar third-party audit processes.
- Certifications: ISC2 CC, CompTIA Security+, ISO/IEC 27001 Foundation, GIAC GSEC, CCSK, or AWS Cloud Practitioner.
- Advanced certifications: CISSP, CISM, CISA, CRISC, CGEIT, CGRC, GRCP, or ISO 27001 Lead Auditor/Implementer.
Culture & Benefits
- Remote work model offering flexibility for work-life balance.
- Access to development programs with strong mentoring and growth support.
- Comprehensive benefits package including health and life insurance.
- Inclusive global team environment committed to diversity.
- Generous leave policies and referral rewards.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →