Sr Manager, InfoSec Governance Risk and Compliance (GRC)
Core
Lead the global Governance, Risk, and Compliance (GRC) program to ensure adherence to security standards and certifications while managing audit responses and third-party risk.
Role type
Senior Manager, InfoSec GRC
Builds
Global GRC program, compliance certifications, security awareness culture
Domain
Information Security, Cloud Procurement, Regulatory Compliance
Required skills
GRC program leadership, compliance certification management, security framework expertise, stakeholder management, project management, policy development, third-party risk assessment
Preferred skills
Team management, audit remediation, contract negotiation, security training program leadership
Technologies
NIST SP 800-53, NIST 800-171, ITAR, FedRAMP, PCI DSS, SOC2, ISO 27001, HIPAA, IRAP
Responsibilities
Lead and own the global GRC program; manage and drive compliance efforts and audits for certifications; serve as SME on security frameworks; manage customer security audit requests; maintain continuous compliance monitoring; collaborate with Sales and Customer Success on security posture; review and negotiate security exhibits; lead Security Awareness and Training program; track and drive remediation for control deficiencies; oversee Third Party Risk and Vendor Security Assessment program; develop and enforce InfoSec policies.
Seniority
Senior Manager, hands-on IC with team leadership
