Назад
Company hidden
18 часов назад

Senior GRC Manager (Cybersecurity)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Senior GRC Manager (Cybersecurity): Leading governance, risk, and compliance programs across SOC 2, PCI, ISO 27001, CMMC, and NIST-aligned environments with an accent on audit readiness, risk management, policy lifecycle management, and control validation. Focus on designing repeatable evidence workflows, validating control effectiveness, managing remediation, and translating security posture into executive-level reporting.

Location: Remote in the United States

Company

hirify.global operates in technology and cybersecurity-focused environments requiring security governance, compliance, and customer assurance.

What you will do

  • Lead the GRC operating cadence, governance calendar, risk committees, policy schedules, audit milestones, and control validation programs.
  • Manage audit readiness, evidence collection and quality, control testing, sampling, remediation follow-up, and reusable evidence standards.
  • Administer the enterprise risk management program, including risk registers, ownership tracking, risk reviews, and executive reporting.
  • Manage the full policy lifecycle, exception processes, access governance oversight, and cross-framework control mapping.
  • Support AI governance, third-party risk, privacy governance, customer assurance, architecture reviews, and security review processes.
  • Partner with Security, IT, Legal, Privacy, Compliance, and business stakeholders while escalating significant risks and preparing leadership reports.

Requirements

  • Minimum seven years of experience in GRC, security compliance, IT audit, enterprise risk management, or security program management.
  • Strong knowledge of governance, risk management, policy management, control validation, audit readiness, and multi-framework compliance.
  • Experience with SOC 2, PCI, ISO 27001, CMMC, NIST-aligned standards, control testing, evidence validation, and remediation oversight.
  • Bachelor's degree in computer science, information technology, cybersecurity, business administration, risk management, or a related field, or equivalent experience.
  • Strong executive communication, writing, presentation, stakeholder management, and issue escalation skills.
  • Ability to manage multiple initiatives, governance forums, deadlines, and enterprise-wide policy processes.

Nice to have

  • Experience with GRC technology platforms and evidence-management workflows.
  • Customer assurance, vendor security reviews, due diligence, and security trust program experience.
  • Certifications such as CISSP, CISA, CRISC, ISO Lead Auditor, ISO Lead Implementer, or PCI QSA.
  • Experience in regulated, client-assurance-focused, or defense-adjacent environments.

Culture & Benefits

  • Work focuses on evidence quality, repeatable governance processes, accountability, and continuous improvement.
  • Cross-functional collaboration spans Security, Internal IT, Legal, Privacy, Compliance, and business teams.
  • The role involves prolonged desk and computer work and may require lifting up to 15 pounds.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →