Назад
Company hidden
4 дня назад

Vulnerability Management Specialist - GRC (Hybrid)

116 000 - 157 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Vulnerability Management Specialist - GRC (Hybrid) (Cybersecurity): Supporting governance, risk, compliance, third-party risk, and vulnerability management activities with an accent on control evidence, risk assessments, remediation tracking, and stakeholder reporting. Focus on evaluating security documentation, coordinating vendor due diligence, managing vulnerability exceptions, and maintaining defensible audit and compliance records.

Location: Hybrid position based in Short Hills, New Jersey; Hartford, Connecticut; or Charlotte, North Carolina.

Salary: USD $116,000–$157,000 per year

Company

hirify.global is a midsized U.S. domestic property and casualty insurance company serving customers through insurance and risk mitigation services.

What you will do

  • Execute GRC activities including risk documentation, control mapping, exception tracking, and assessment record maintenance.
  • Coordinate third-party vendor assessments, due diligence requests, stakeholder follow-ups, and risk conclusions.
  • Review SOC reports, ISO certifications, penetration testing summaries, vulnerability information, and business continuity documentation.
  • Track vulnerability remediation, risk acceptances, exceptions, aging issues, and audit findings.
  • Collect and validate audit evidence aligned with cybersecurity frameworks and regulatory requirements.
  • Maintain risk metrics and improve templates, procedures, evidence requests, and reporting processes.

Requirements

  • Working knowledge of cybersecurity, risk management, compliance, vulnerability management, audit, or third-party risk concepts.
  • Ability to evaluate security evidence, identify incomplete or inconsistent information, and escalate risk concerns.
  • Strong attention to detail, documentation discipline, and ability to manage multiple assessments or remediation activities.
  • Clear written and verbal communication skills for summarizing technical and control information to business stakeholders.
  • Proficiency with Microsoft Office; familiarity with GRC, vendor risk, vulnerability management, ticketing, or reporting tools is preferred.
  • Preferred experience includes 3–5 years in GRC, cybersecurity, third-party risk, vulnerability management, audit, compliance, procurement risk, or vendor management.

Nice to have

  • Experience with audits, regulatory compliance, control testing, risk assessments, or vendor due diligence.
  • Familiarity with NIST CSF, NIST 800-53, NYDFS, GLBA, SOX, SOC reporting, or ISO 27001.
  • CRISC, CISA, Security+, CDPSE, CTPRP, or a similar certification or certification progress.

Culture & Benefits

  • Hybrid work environment with a focus on inclusion, diverse perspectives, and employee individuality.
  • Competitive base salary and incentive plan eligibility.
  • Health care plans, retirement savings with company match, and a discounted employee stock purchase program.
  • Tuition assistance and reimbursement programs.
  • 20 days of paid time off and benefits supporting work-life balance.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →