Назад
Company hidden
обновлено 3 дня назад

GRC Specialist (Cybersecurity)

116 000 - 157 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
GRC Specialist (Cybersecurity): Executing governance, risk, compliance, third-party risk, vulnerability management, and audit activities with an accent on control evidence, vendor due diligence, remediation tracking, and regulatory frameworks. Focus on evaluating security documentation, coordinating vulnerability and audit remediation, maintaining risk metrics, and improving consistent risk processes.

Location: Hybrid in Short Hills, New Jersey; Hartford, Connecticut; or Charlotte, North Carolina

Salary: USD $116,000–$157,000 per year

Company

hirify.global is a midsized U.S. property and casualty insurance company providing insurance products and risk protection services.

What you will do

  • Execute GRC activities including risk documentation, control mapping, exception tracking, and assessment maintenance.
  • Coordinate third-party risk assessments, vendor due diligence, stakeholder follow-ups, and remediation through closure.
  • Review SOC reports, ISO certifications, penetration test summaries, vulnerability information, and business continuity documentation.
  • Track vulnerability remediation, risk exceptions, risk acceptances, aging issues, and control gaps.
  • Collect and validate audit evidence and support regulatory, compliance, and audit remediation activities.
  • Maintain risk metrics and improve templates, procedures, evidence requests, and process consistency.

Requirements

  • Working knowledge of cybersecurity, risk management, compliance, vulnerability management, audit, or third-party risk concepts.
  • Ability to evaluate security evidence, identify incomplete or inconsistent information, and escalate risk concerns.
  • Strong attention to detail, documentation discipline, and ability to manage multiple assessments or remediation activities.
  • Clear written and verbal communication skills for summarizing technical and control information to business stakeholders.
  • Proficiency with Microsoft Office; experience with GRC, vendor risk, vulnerability management, ticketing, or reporting tools is preferred.

Nice to have

  • 3–5 years of experience in GRC, cybersecurity, third-party risk, vulnerability management, audit, compliance, procurement risk, or vendor management.
  • Experience with audits, regulatory compliance, control testing, risk assessments, or vendor due diligence reviews.
  • Familiarity with NIST CSF, NIST 800-53, NYDFS, GLBA, SOX, SOC reporting, or ISO 27001.
  • CRISC, CISA, Security+, CDPSE, CTPRP, or a similar certification.

Culture & Benefits

  • Competitive base salary and incentive plan eligibility.
  • Health care plans, retirement savings with company match, and discounted employee stock purchase program.
  • Tuition assistance and reimbursement programs.
  • 20 days of paid time off.
  • Inclusive workplace focused on diversity, equity, and belonging.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →