1 день назад
Sr Manager, InfoSec Governance Risk and Compliance (GRC)
112 000 - 208 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Sr Manager, InfoSec Governance Risk and Compliance (GRC) (Information Security GRC): Leading Ivalua’s global GRC program, compliance certifications, audits, and a high-performing team with an accent on security frameworks, continuous control monitoring, and third-party risk. Focus on managing FedRAMP, ISO 27001, HIPAA, SOC, and PCI DSS compliance, addressing control gaps, and guiding customer and internal security assurance.
Location: New York City, New York, United States; hybrid working model with 3 days in the office per week.
Salary: USD 112,000–208,000 annually, plus medical, dental, vision, and transportation benefits.
Company
provides a cloud-based spend management and procurement platform that helps organizations manage suppliers, improve profitability, strengthen ESG performance, and reduce risk.
What you will do
- Lead and own the global Governance, Risk, and Compliance program while managing and developing a high-performing team.
- Drive compliance efforts and audits for FedRAMP, IRAP, ISO 27001, HIPAA, SOC 1/SOC 2, PCI DSS, and other standards.
- Act as a subject matter expert on NIST SP 800-53 Rev. 5, NIST 800-171, ITAR, PCI DSS, SOC 2, and FedRAMP frameworks.
- Manage customer security audit requests and communicate the organization’s security posture to Sales, Marketing, Customer Success, prospects, and customers.
- Monitor security controls, track remediation of audit deficiencies, and oversee third-party risk and vendor security assessments.
- Maintain information security policies, standards, and plans, and lead the security awareness and training program.
Requirements
- 7+ years of experience leading GRC programs and managing compliance certifications and audits.
- 3+ years of direct people leadership experience.
- Strong knowledge of security frameworks and standards, including NIST, FedRAMP, ITAR, PCI DSS, and SOC 2.
- Experience influencing stakeholders across multiple departments and time zones.
- Excellent project management, analytical, problem-solving, communication, and organizational skills.
- Bachelor’s degree in a related field preferred, or equivalent experience and demonstrated skills.
Culture & Benefits
- Hybrid work with regular office attendance.
- Medical, dental, vision, and transportation benefits.
- Training and career development opportunities.
- International, diverse, and inclusive working environment.
- Office snacks, weekly lunches, social events, and team activities.
Hiring process
- Initial screening call with the Talent team.
- Personalized interviews with internal stakeholders relevant to the role.
- Interviews conducted virtually by video or onsite.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 дня назад
GRC Specialist (AI)
200 000 - 220 000$
4 дня назад
Principal Security GRC Analyst (FedRAMP)
150 000 - 200 000$
1 день назад
Security Governance Risk & Compliance (GRC) Analyst (Cybersecurity)
130 000 - 170 000$
2 дня назад
Senior Risk and Compliance Analyst (IT GRC)
96 700 - 148 100$
7 дней назад
GRC/IT Compliance Analyst
108 000 - 130 000$
1 день назад
GRC Analyst (AI)
135 000 - 165 000$