GRC Manager

Deepwatch, inc. • Remote

Company

Deepwatch, inc.

Location

Remote

Type

Full Time

Job Description

Come join Deepwatch’s team of world-class cybersecurity professionals and the brightest minds in the industry. If you're ready to challenge yourself with work that matters, then this is the place for you. We're redefining cybersecurity as one of the fastest growing companies in the U.S. – and we have a blast doing it!

Who We Are

Deepwatch is the leader in managed security services, protecting organizations from ever-increasing cyber threats 24/7/365. Powered by Deepwatch’s cloud-based security operations platform, Deepwatch provides the industry’s fastest, most comprehensive detection and automated response to cyber threats together with tailored guidance from dedicated experts to mitigate risk and measurably improve security posture. Hundreds of organizations, from Fortune 100 to mid-sized enterprises, trust Deepwatch to protect their business. 

Our core values drive everything we do at Deepwatch, including our approach to tackling tough cyber challenges. We seek out tenacious individuals who are passionate about solving complex problems and protecting our customers. At Deepwatch, every decision, process, and hire is made with a focus on improving our cybersecurity solutions and delivering an exceptional experience for our customers. By embracing our values, we create a culture of excellence that is dedicated to empowering our team members to explore their potential, expand their skill sets, and achieve their career aspirations, which is supported by our unique annual professional development benefit.

Deepwatch recognition includes:

  • 2023, 2022 and 2021 Great Place to Work® Certified
  • 2023 and 2022 Forbes America’s Best Startup Employers
  • 2023 and 2022 Fortress Cybersecurity Award
  • 2023 $180M Series C investment from Springcoast Capital Partners, Splunk Ventures, and Vista Credit Partners of Vista Equity Partners
  • 2022 Cigna Healthy Workforce Silver Designation
  • 2022 Cybersecurity Excellence Award for MDR

Position Summary:

We seek an accomplished and results-driven GRC Manager to lead and manage critical functions within our organization, reporting directly to the Senior Director of Security and Compliance. 

As the GRC Manager, you will be pivotal in overseeing multiple key areas throughout Deepwatch. Your expertise in security, compliance, regulatory frameworks, platform management, vendor security reviews, customer interactions, cross-functional collaboration, and reporting will be instrumental in creating a strong synergy between our security and information security functions and providing valuable insights to leadership. You will be a critical people leader in advancing our security and compliance efforts and contributing to strategic decision-making and serve as a role model of Deepwatch’s Core Values. You should embody the Deepwatch Leadership Attributes of ownership, delivering results, hiring & developing the best talent in the industry, having backbone and ability to disagree and then commit, while earning trust.

In this role you’ll be responsible for:

  • Compliance and Auditing:
    • Lead and manage the organization’s compliance efforts for PCI, SOC 2, and other regulatory and security frameworks
    • Collaborate closely with our third-party auditing firms, coordinating audit activities and providing the necessary evidence
    • Conduct thorough assessments to ensure alignment with regulatory requirements and industry standards
    • Drive the timely resolution of audit findings by working with relevant teams to implement effective controls and solutions.
  • Maturity Assessments:
    • Oversee the implementation of the Blue Lava and NIST security framework to assess and enhance the organization’s security maturity
    • Lead the development and execution of security maturity assessments using Blue Lava, identifying gaps, vulnerabilities, and areas for improvement
    • Translate assessment results into actionable recommendations and strategic plans to enhance security posture
  • Continuous Compliance Management:
    • Take ownership of the Drata continuous compliance monitoring platform
    • Utilize Drata to monitor and maintain ongoing compliance with regulatory requirements and industry standards
    • Leverage Drata insights to drive continuous improvement in our security controls and compliance practices
  • Legal and Contract Collaboration:
    • Work closely with the Legal and Contract team to ensure compliance with data protection regulations and contractual obligations
    • Review, negotiate, and redline contracts, including Data Protection Agreements (DPAs), with third-party vendors, partners, and customers to ensure data privacy and protection
    • Ensure that security and compliance considerations get integrated into contract negotiations and agreements
  • Vendor Security Reviews:
    • Lead vendor security reviews to assess the security posture of third-party vendors and partners
    • Conduct thorough evaluations of vendor security controls, policies, and practices to ensure they align with our security standards
    • Provide recommendations for risk mitigation and security improvements based on vendor security assessments
  • Customer Requests:
    • Handle customer questionnaires and requests related to our security attestations
    • Provide accurate and timely responses to customer inquiries, ensuring that customer concerns regarding security get addressed effectively
    • Liaise with cross-functional teams to gather necessary information and documentation for customer attestations
  • Collaboration with Information Security Manager:
    • Work hand in hand with our Information Security Manager to create synergy and alignment across security and compliance functions
    • Collaborate closely to develop and implement security strategies, initiatives, and risk management plans
    • Ensure consistent communication, knowledge sharing, and coordination between security and compliance efforts
  • Reporting and Communication:
    • Provide regular updates and reports to the Senior Director of Security and Compliance on the status of cybersecurity, compliance, and risk management initiatives
    • Collaborate on strategic planning, goal setting, and decision-making to advance the organization’s security and compliance objectives
  • Team Development and Performance:
    • Identify team members’ strengths, areas for growth, and professional development opportunities
    • Foster a culture of accountability and excellence, promoting collaboration, knowledge sharing, and continuous learning within the team

To be successful in this role, you’ll need to:

  • Have clearly defined management experience focusing on security, compliance, team leadership, hiring, and coaching
  • Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Information Systems Auditor (CISA) are highly desirable.
  • Demonstrate experience in audit coordination, maturity assessment, vendor security reviews, customer communication, or similar roles within a complex organizational environment
  • Exhibit extensive knowledge of security frameworks, regulations, and standards (e.g., PCI, SOC 2, GDPR, NIST, ISO 27001), alongside practical experience in implementing and managing compliance initiatives
  • Be proficient with continuous compliance monitoring platforms, including managing and maximizing the utilization of the platform
  • Concurrently lead and coordinate multiple initiatives while demonstrating strong project management skills
  • Enable effective collaboration with technical and non-technical stakeholders
  • Showcase leadership skills with the ability to drive change, influence, and guide cross-functional teams
  • Collaborate with the internal legal and contract team to ensure compliance with data protection and contractual requirements

Statutory Pay Disclosure:

For applicants in NYC, CO, CA, RI, and WA, the salary range for this role is $140,000 to $210,000 + stock options + benefits. Actual compensation may vary from posted hiring range based upon geographic location, work experience, education, and/or skill level.

#LI-KH1

What We Offer:

Deepwatch is excited to provide benefits designed to support team members and their families. Including:

  • Medical, dental, vision, and disability insurance
  • Flexible Time Off (FTO), 9 company holidays, sick leave and 8-Weeks Paid Parental Leave
  • Unique professional development benefits, starting at $3,000 annually
  • Wellness contests and monthly educational programs
  • 401(K) retirement program with employer match
  • Learn more here: Deepwatch Benefits

We know the confidence gap and imposter syndrome can get in the way of meeting spectacular candidates, so please don’t hesitate to apply — we’d love to hear from you.  Please review our DEI Statement here.

Deepwatch welcomes and encourages applications from people with disabilities and accommodations are available on request for candidates taking part in all aspects of the selection process. Please inform your recruiter or contact [email protected] for further information.

All Deepwatch employees are expected to:

  • Be interested in and able to work remotely from a home office when not at a corporate office
  • Pass a pre-employment background and drug screen in accordance with applicable laws

Deepwatch is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability status, marital status, sexual orientation, gender identity, genetic information, protected veteran status, or any other characteristic protected by law.  In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification document form upon hire.

By submitting your application, you agree that Deepwatch may collect your personal data for recruiting, global organization planning, and related purposes. The Deepwatch Privacy Policy explains what personal information we may process, where we may process your personal information, our purposes for processing your personal information, and the rights you can exercise over Deepwatch’s use of your personal information. 

Apply Now

Date Posted

09/01/2023

Views

37

Back to Job Listings ❤️Add To Job List Company Info View Company Reviews
Positive
Subjectivity Score: 0.8

Similar Jobs

Account Manager, Care Partnerships - Headway

Views in the last 30 days - 0

Headway a mental health care company founded in 2019 aims to revolutionize mental healthcare by building a national network of providers accepting ins...

View Details

Director of Pricing - Garner Health

Views in the last 30 days - 0

Garner Health is a rapidly growing company backed by toptier venture capital firms Their mission is to transform the healthcare economy by delivering ...

View Details

Director, Product, Customer, and Lifecycle Marketing - Garner Health

Views in the last 30 days - 0

Garner Health is seeking an experienced Product Marketing Leader to join their team The ideal candidate will lead the product marketing efforts focusi...

View Details

Data Analyst - Agero

Views in the last 30 days - 0

Agero a leading B2B whitelabel provider of digital driver assistance services is revolutionizing the vehicle ownership experience through datadriven t...

View Details

Director, Product (Remote) - Dscout

Views in the last 30 days - 0

Dscout is a leading company in experience research technology offering a platform for major companies to gain insights into user needs and behaviors T...

View Details

Technical Architect - CDW

Views in the last 30 days - 0

CDW offers a rewarding career opportunity for a Technical Architect with expertise in ServiceNow The role involves delighting customers by collaborati...

View Details