Назад
Company hidden
1 день назад

Sr Manager, InfoSec Governance Risk and Compliance (GRC)

112 000 - 208 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Sr Manager, InfoSec Governance Risk and Compliance (GRC) (Information Security GRC): Leading Ivalua’s global GRC program, compliance certifications, audits, and a high-performing team with an accent on security frameworks, continuous control monitoring, and third-party risk. Focus on managing FedRAMP, ISO 27001, HIPAA, SOC, and PCI DSS compliance, addressing control gaps, and guiding customer and internal security assurance.

Location: New York City, New York, United States; hybrid working model with 3 days in the office per week.

Salary: USD 112,000–208,000 annually, plus medical, dental, vision, and transportation benefits.

Company

hirify.global provides a cloud-based spend management and procurement platform that helps organizations manage suppliers, improve profitability, strengthen ESG performance, and reduce risk.

What you will do

  • Lead and own the global Governance, Risk, and Compliance program while managing and developing a high-performing team.
  • Drive compliance efforts and audits for FedRAMP, IRAP, ISO 27001, HIPAA, SOC 1/SOC 2, PCI DSS, and other standards.
  • Act as a subject matter expert on NIST SP 800-53 Rev. 5, NIST 800-171, ITAR, PCI DSS, SOC 2, and FedRAMP frameworks.
  • Manage customer security audit requests and communicate the organization’s security posture to Sales, Marketing, Customer Success, prospects, and customers.
  • Monitor security controls, track remediation of audit deficiencies, and oversee third-party risk and vendor security assessments.
  • Maintain information security policies, standards, and plans, and lead the security awareness and training program.

Requirements

  • 7+ years of experience leading GRC programs and managing compliance certifications and audits.
  • 3+ years of direct people leadership experience.
  • Strong knowledge of security frameworks and standards, including NIST, FedRAMP, ITAR, PCI DSS, and SOC 2.
  • Experience influencing stakeholders across multiple departments and time zones.
  • Excellent project management, analytical, problem-solving, communication, and organizational skills.
  • Bachelor’s degree in a related field preferred, or equivalent experience and demonstrated skills.

Culture & Benefits

  • Hybrid work with regular office attendance.
  • Medical, dental, vision, and transportation benefits.
  • Training and career development opportunities.
  • International, diverse, and inclusive working environment.
  • Office snacks, weekly lunches, social events, and team activities.

Hiring process

  • Initial screening call with the Talent team.
  • Personalized interviews with internal stakeholders relevant to the role.
  • Interviews conducted virtually by video or onsite.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →