Job Description
Position Summary:
The Director of Security Governance Risk and Compliance (GRC) is focused on ensuring Pax8’s security policy framework exception management risk assessment and compliance efforts are operating effectively. They oversee the delivery of the security policy and standards including management tracking and remediation of deviations from the security policies. Additionally the Director supports the efforts of measuring the control effectiveness through risk assessment efforts to promote further maturity of the security program. They are a key member of the GRC team providing guidance and direction to GRC professionals and collaborating with other departments across our organization.
Essential Responsibilities:
-
Manage inquiries and requests to update the security policy and standards through cross-functional team coordination.
-
Establish implement and manage requests for policy exceptions evaluating based on a risk model and promoting policy adherence and remediation.
-
Oversee control effectiveness and program maturity assessment efforts to support security program prioritization.
-
Participate in security automation and tool selection efforts aligned with the security policies and standards.
-
Develop and maintain security procedures including defining and documenting security best practices for managing a risk-based process.
-
Stay up to date on industry trends and best practices including continuously learning and adapting the security program to address evolving threats.
-
Collaborate with other departments including IT engineering legal data management office HR and other departments to ensure security considerations are integrated into all business processes.
-
Measure and report on security performance by tracking key metrics (KPIs/KRIs) identifying areas for improvement and reporting to the GRC leader and other stakeholders.
Ideal Skills Experience and Competencies:
-
At least (10) years of experience in an IT security GRC role.
-
Proven experience in policy management exception management remediation tracking risk assessment and risk-based prioritization efforts (e.g. asset criticality data classification BIA).
-
Understanding of public cloud deployments and associated security risks and controls.
-
Experience working in a Zero Trust focused security program
-
Strong understanding of security best practices and frameworks (e.g. MITRE ATT&CK NIST Cybersecurity Framework ISO 27001:2022 SOC2 audit efforts).
-
Experience with incident management and response planning efforts.
-
Excellent communication interpersonal and leadership skills.
-
Ability to perform risk assessment efforts and deliver on security program initiatives.
Required Education & Certifications:
-
B.A./B.S. in related field or equivalent work experience.
-
Risk-focused certifications (e.g. CISA CRISC CISSP) preferred.
Compensation:
-
Qualified candidates can expect a salary beginning at $150000 or more depending on experience
Expected Closing Date: 5/31/24
#LI-Remote #LI-AG1 #BI-Remote #DICE-A
Explore More
Date Posted
05/23/2024
Views
12
Similar Jobs
Engineering Manager - Software Supply Chain Security: Auth Infrastructure - GitLab
Views in the last 30 days - 0
This job description highlights a leadership role in developing secure scalable authentication infrastructure for GitLab It emphasizes technical exper...
View DetailsStaff Salesforce Engineer - CRM Systems - GitLab
Views in the last 30 days - 0
This job description outlines a Staff Salesforce Developer role focusing on designing building and scaling enterprisegrade solutions across Salesforce...
View DetailsGrowth Product Lead - Loyalty - Trafilea
Views in the last 30 days - 0
Trafilea promotes itself as a transformative consumer tech platform with AIdriven growth solutions highlighting achievements like 1B revenue and globa...
View DetailsSales Prospecting Account Executive - Financial Solutions - Blackbaud
Views in the last 30 days - 0
This job posting seeks Prospect Account Executives to sell Financial Management applications for nonprofits and governments Responsibilities include s...
View DetailsSolutions Architect - phData
Views in the last 30 days - 0
This job posting seeks a Solutions Architect to join phDatas Elastic Platform Operations team focusing on cloudnative data platforms like Snowflake AW...
View DetailsTeam Lead - Publisher Success Management (AdTech) - MGID
Views in the last 30 days - 0
MGID is a fastgrowing digital advertising company seeking a resultsdriven Team Lead to oversee client relationships and drive business growth in the U...
View Details