GRC Specialist
Israel
Varonis
The world's only fully automated DSPM. Continuously discover and classify critical data, remove exposures, and stop threats in real-time with AI-powered automation.Summary Data has never been more valuable and vulnerable. As cybercriminals become more sophisticated and regulations more strict, organizations struggle to answer one key question: “Is my data safe? At Varonis, we see the world of cybersecurity differently. Instead of chasing threats, we believe the most practical approach is protecting data from the inside out. We’ve built the industry’s first fully autonomous Data Security Platform to help our customers dramatically reduce risk with minimal human effort. At Varonis, we move fast. We’re an ultra-collaborative company with brilliant people who care deeply about the details. Together, we’re solving interesting and complex puzzles to keep the world’s data safe.We work in a flexible, hybrid model, so you can choose the home-office balance that works best for you. Job Overview: We are seeking a highly skilled and experienced Security GRC (Governance, Risk, and Compliance) Specialist to join our team. The ideal candidate will report to the GRC manager, have a strong background in security governance, risk management, and compliance, with a proven track record of successfully implementing GRC programs. Key Responsibilities:
- Develop, implement, and maintain GRC frameworks, policies, and procedures.
- Respond to customer due diligence requests, assist with contract agreements, and participate in customer calls to address GRC-related inquiries.
- Conduct risk assessments and identify potential security threats and vulnerabilities.
- Collaborate with cross-functional teams to integrate GRC initiatives into business processes.
- Design and maintain security awareness program (e.g., conduct phishing simulations, generate newsletters, administer training platform)
- Monitor and report on the effectiveness of GRC programs and controls.
- Provide guidance and support to internal stakeholders on GRC-related matters.
- Stay up to date with industry trends and emerging threats to continuously improve the GRC program.
- Perform technical risk assessments.
- Bachelor’s degree in information security, Computer Science, or a related field.
- Minimum of 3 years of experience in GRC, and information security.
- Strong knowledge of regulatory requirements and industry standards (e.g., GDPR, HIPAA, ISO 27001).
- Experience in conducting customer due diligence, handling customer calls.
- Experience in conducting security audits such as SOC 2 and ISO 27000 family.
- Experience with GRC platforms, including third-party risk management, and security awareness.
- Excellent analytical, problem-solving, and communication skills.
- Ability to work independently and as part of a team in a fast-paced environment.
- Relevant certifications such as CISSP, CISM, or CRISC are preferred.
- Highly advantageous, experience with:
- Business Continuity Planning (BCP)
- performing technical risk assessments on various systems, including cloud, network, and application environments.
- Payment Card Industry (PCI) standards
- Cyber Essentials plus
- AI Security and Governance practices
- Managing Bug Bounty programs
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
2
0
0
Category:
Compliance Jobs
Tags: Audits CISM CISSP Cloud Compliance Computer Science CRISC GDPR Governance HIPAA ISO 27000 ISO 27001 Risk assessment Risk management SOC SOC 2 Vulnerabilities
Region:
Middle East
Country:
Israel
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Product Security Engineer jobsSecurity Operations Engineer jobsSenior Security Analyst jobsSystems Administrator jobsSenior Cybersecurity Engineer jobsSenior Information Security Analyst jobsCybersecurity Editor jobsCybersecurity Content Editor jobsCyber Security Specialist jobsInformation Security Manager jobsIT Security Analyst jobsSenior Network Security Engineer jobsSenior Information Security Engineer jobsSenior Product Security Engineer jobsInformation System Security Officer (ISSO) jobsSecurity Consultant jobsChief Information Security Officer jobsIT Security Engineer jobsInformation Systems Security Engineer jobsSecurity Specialist jobsSenior Cyber Security Engineer jobsCyber Threat Intelligence Analyst jobsSenior Software Engineer jobsCybersecurity Specialist jobsSenior IT Auditor jobs
EDR jobsTS/SCI jobsJava jobsEncryption jobsCEH jobsSplunk jobsTop Secret jobsSDLC jobsIDS jobsThreat detection jobsTerraform jobsIPS jobsMalware jobsFinance jobsRMF jobsSQL jobsDocker jobsForensics jobsSOC 2 jobsActive Directory jobsIntrusion detection jobsCompTIA jobsOWASP jobsITIL jobsTCP/IP jobs
HIPAA jobsCRISC jobsGIAC jobsAnsible jobsClearance Required jobsVPN jobsDoDD 8570 jobsMITRE ATT&CK jobsIT infrastructure jobsOSCP jobsJira jobsData Analytics jobsSOAR jobsDNS jobsSOX jobsJavaScript jobsBanking jobsUNIX jobsCCSP jobsIndustrial jobsZero Trust jobsCISO jobsGCIH jobsArtificial Intelligence jobsSANS jobs