Senior Manager, Information Security GRC
USD 90K-100K (estimate) Senior-level Full Time
Tasks
- Advise security risk posture to senior leadership
- Build and lead GRC function
- Collect evidence and remediate audit findings
- Conduct internal control audits
- Conduct security due diligence and vendor risk reviews
- Configure and administer GRC platform and workflows
- Develop approve enforce and review security policies
- Direct third party partners for GRC delivery
- Ensure timely access remediation
- Establish GRC metrics dashboards and KPIs
- Lead information security risk management program
- Maintain control library and reporting
- Maintain vendor risk inventory
- Manage responses to audits and security questionnaires
- Monitor changes in laws regulations and industry standards
- Operate security awareness training program
- Oversee compliance assessments
- Oversee phishing simulation program and results analysis
- Oversee remediation tracking for vendors
- Own GRC program roadmap and strategy
- Own information security policy framework
- Own third party risk management program
- Plan and drive risk remediation with control owners
- Run risk assessments and maintain risk register
- Run user access and privileged access reviews
- Support ESI identification preservation collection and chain of custody
- Translate regulatory changes into business requirements
Perks/Benefits
- 401k company match
- Charitable giving program
- Critical Illness Accident Hospital Indemnity
- Employee Medical Dental Vision and Disability Life Insurance
- Employee assistance program
- Legal plans
- Onsite housing discount
- Paid parental leave
- Paid sabbatical
- Paid time off
- Pet insurance
Skills/Tech-stack
800-53 | AI RMF | AWS | Access Management | Access reviews | Audit management | Awareness Training | Azure | CCPA | Cloud Risk and Compliance | Cloud platform | Cloud risk | Compliance Management | Control Testing | Due Diligence | Evidence collection | GDPR | GRC platform | Google Cloud | Google Cloud Platform | Governance Risk | Governance Risk and Compliance | ISO 27001 | ISO 42001 | Information Security Policy | Information security | KPI Reporting | NIST | NIST 800 | NIST 800-53 | NIST AI | NIST AI RMF | PCI DSS | Phishing simulation | Policy Management | Privileged Access | Privileged Access Management | Risk Assessments | Risk Management | Risk and Compliance | Risk register | Risk treatment | SOC 2 | SOX | Security Awareness Training | Security Due Diligence | Security Policy | Security awareness | Segregation of Duties | Third Party | Third-Party Risk | Third-party risk management | Vendor Risk | Vendor risk management
Related jobs
-
API | Access Management | CSPM | Cloud Computing | DSPMDental insurance | Fully remote | Health insurance | Home office setup reimbursement | Life insuranceMid-level Full TimeCanada R7h ago
-
Access Management | Antivirus | Endpoint protection | Firewall | IDSIPS401k | Dental insurance | Medical insurance | Paid sick hours | Vision insuranceSenior-level Contract Full TimeIrvine, CA, United States12h ago
-
Senior Manager, Information Security Engineering USD 188K-235KAI Security | AI machine learning | CMMC | Data Loss Prevention | Data ProtectionEducation reimbursement | Parental leave options | Remote work | Retirement options | Time off plansSenior-level Full TimeRemote - USA R14h ago
-
Sr. Manager, Human Risk Management USD 150K-217KA/B | A/B Testing | AI | Access Management | AnalyticsSenior-level Full TimeUS-Headquarters, United States1d ago
-
Sr. Manager, Third Party Risk Management USD 95K-151KAudit Readiness | BC/DR | BitSight | Business Continuity | Business Continuity PlanningSenior-level Full TimeUS-Headquarters, United States1d ago
-
Sr. Director, Cyber Risk and Trust USD 150K-215KAudit Readiness | CIS Controls | Contract Security Reviews | Control mapping | Control maturitySenior-level Full TimeUS-Headquarters, United States1d ago
-
Cybersecurity Portfolio & Operations Lead USD 130K-205KBudgeting | Contract Management | Executive reporting | Financial Forecasting | Financial GovernanceDental insurance | Employee assistance program | Flexible spending account | Generous time off | Health insuranceSenior-level Full TimeTEX01 - Houston, Texas (TEX01), United …1d ago
-
VP Cyber Threat Intelligence USD 210K-330KAdversary Analysis | CTI Vendor Management | Cyber Threat | Cyber Threat Intelligence | Executive reportingAnnual incentive opportunity | Off hours availability as needed | On-site workExecutive-level Full TimeBerkeley Heights, New Jersey, United States1d ago
-
ACAS | Audit Reduction | Continuous Monitoring | DISA STIG | HBSSSenior-level Full TimeUSA - Berkeley, MO, United States1d ago
-
Cybersecurity Portfolio & Operations Lead USD 130K-205KBudgeting | Contract Management | Executive reporting | Financial planning | ForecastingDental insurance | Employee assistance program | Flexible spending account | Flexible vacation and sick leave | Health insuranceSenior-level Full TimeTEX01 - Houston, Texas (TEX01), United …1d ago
-
Cybersecurity Technology Manager USD 160K-220KApplication Security | Authentication | Azure | Cloud Security | Control DeviationsHealth insurance | Professional development | Time offMid-level Full TimeJersey City, United States1d ago
-
Cyber GRC Transformation Manager USD 95K-178KAI RMF | APIs | Archer | Automation | Compliance ManagementFlexible work arrangements | In-person collaborationMid-level Full TimeFL001 - Florida, USA (FL001), United …1d ago
-
Cyber Engagement Program Lead USD 105K-161KAI Governance | AI Risk | AI risk management | Analytics | Application SecurityDental insurance | Employee assistance program | Flexible paid vacation and sick leave | Flexible spending account | Generous time offSenior-level Full TimeTEX01 - Houston, Texas (TEX01), United …1d ago
-
Manager, Information Security Office Consultant USD 179K-245KAWS | Access Management | Application Security | Architecture Review | AzureMid-level Full TimeMcLean, VA, United States1d ago
-
Risk Manager, Endpoint Security USD 179K-245K800-53 | Access Management | Amazon Web Services | Anti-Malware | Anti-virusMid-level Full TimeMcLean, VA, United States1d ago
-
Investment Risk Manager - Liquidity USD 175K-190KAI | Aladdin | Data Analysis | Data Visualization | MSCI BarraOne401k company match | Dental insurance | Employee stock investment plan | Health insurance | Learning education assistance programSenior-level Full TimeUSA-BAL1201-Baltimore, United States1d ago
-
Security Support Manager USD 140K-165K800-53 | Active Directory | DNS | Email Security | Endpoint ManagementPaid time off | Travel 10 percentMid-level Full TimeChicago - IL - 200 N. …1d ago
-
AWS | AWS CloudFormation | Access Control | Active Directory | BashFamily leave | Health care plan | Paid time off | Retirement plan | Training and developmentSenior-level Full TimeUtah, United States - Remote R2d ago
-
AWS | Access Control | Active Directory | Bash | Cloud platformFamily leave | Health care plan | Paid time off | Retirement plan | Training and developmentSenior-level Full TimePennsylvania, United States - Remote R2d ago
-
AWS | Active Directory | Bash | Change Management | CloudFormationFamily leave | Health care plan | Paid time off | Retirement plan | Training and developmentSenior-level Full TimeWyoming, United States - Remote R2d ago
-
AWS | Active Directory | Bash | Cloud platform | CloudFormationFamily leave | Health care plan | Paid time off | Retirement plan | Training and developmentSenior-level Full TimeIndiana, United States - Remote R2d ago
-
AWS CloudFormation | Access Control | Active Directory | Amazon Web Services | Azure ResourceFamily leave | Health care plan | Paid time off | Retirement plan | Training and developmentSenior-level Full TimeMontana, United States - Remote R2d ago
-
AWS | AWS CloudFormation | Access Control | Active Directory | AzureFamily leave | Health care plan | Paid time off | Retirement plan | Training and developmentSenior-level Full TimeMaryland, United States - Remote R2d ago
-
AWS | AWS CloudFormation | Access Control | Active Directory | BashFamily leave | Health care plan | Paid time off | Retirement plan | Training and developmentSenior-level Full TimeConnecticut, United States - Remote R2d ago
-
AWS CloudFormation | Access Control | Active Directory | Amazon Web Services | BashFamily leave | Health care plan | Paid time off | Retirement plan | Training and developmentSenior-level Full TimeAlabama, United States - Remote R2d ago