GRC Specialist

SevenRooms · New York City, NY

Company

SevenRooms

Location

New York City, NY

Type

Full Time

Job Description

About the Team & Role

The Governance, Risk Management and Compliance (GRC) team at SevenRooms is responsible for building a leading technology risk management practice and managing our IT compliance posture and information security capabilities. We are looking for an experienced GRC Specialist to implement and drive our IT compliance program by executing internal and external assessments, ensuring compliance with existing and emerging regulations and standards including PCI, SOC2, GDPR, CCPA/CPRA and overseeing other technology risk management activities.

You will work closely with stakeholders across the organization to understand existing IT policies, procedures, and processes, make recommendations related to applicable risk areas, mitigations, and process improvements, and implement meaningful solutions.  

What You'll Do
  • Execute our Technology GRC plan to ensure an effective internal control environment for PCI, SOC 2, ISO2700x and other regulatory requirements (e.g., GDPR, CCPA/CPRA) 
  • Coordinate with third parties/auditors for all matters related to PCI audits, SOC 2 audits, Vendor Security Reviews
  • Review, audit, monitor, and analyze security risks and vulnerabilities against policies, 
  • Support the management in identifying key technology risks, forward thinking mitigation strategies and improvements to the business process
  • Perform and manage security risk assessments on third party vendors
  • Review, implement and maintain a GRC tool to drive a risk aware and compliant-centric organization
  • Work together with the Sales team to provide responses for customer proposals and security addendums in contracts
  • Educate the organization on governance, risk and controls, and compliance concepts
  • Serve as a subject matter expert who will actively guide engineering, product and other teams on all security and compliance related risks and issues
  • Communicate effectively with the business, and have the ability to break down technical aspects of compliance into basic concepts
Who You Are
  • Relevant experience (ideally) with a Public Accounting firm (Big 4 preferred) or Software-as-a-Service (SaaS) company in one or more of the following areas: IT Compliance, IT Security, IT Audit/Assurance, IT Governance, Risk Management and/or Cyber Advisory role
  • Experience designing, implementing and managing a compliance program based on common frameworks like PCI, SOC 2, GDPR, ISO27001, ISO27017 etc.
  • Working knowledge of information security and computer networks, servers, database and SaaS technologies
  • General knowledge of IT audit and risk management/assessment process
  • Experience working implementing and monitoring data privacy controls across the organization based on leading regulations e.g., GDPR, CCPA/CPRA  
  • Experience developing and maintaining information security policies and procedures
  • Experience with cloud concepts, continuous integration/development methods
  • Working knowledge of GRC/Vendor Management tools e.g., LogicGate, Onetrust
  • Enthusiastic about navigating complex problems, proactively identifying recommendations and implementing solutions
  • Effective communicator; able to communicate technical concepts to a variety of audiences and stakeholders
  • Highly results-oriented, with the willingness to go above and beyond and have an impact
  • Passionate about technology compliance and learning new things
  • Bachelor’s degree in Information Security, Computer Science, Information Systems, or Accounting is preferred 
  • CISA, CISSP, CISM, CRISC or equivalent Information Technology audit or security certifications are preferred
What We Offer
  • A fresh start with a flexible and independent working schedule: SevenRooms provides all employees with their first two (2) weeks of employment as paid time off to relax and recharge before starting their journey with us. You'll also have access to unlimited paid time off, including tenure-based PTO minimums, paid parental leave, and the option to work anywhere at any time.
  • Equitable compensation: Our compensation packages are based on external market data. At SevenRooms, you can expect to be paid well for your contributions towards transforming the hospitality industry. We also offer equity for all employees as part of our commitment to everyone being an owner and working together to build an outstanding company.
    • The salary range for this role is $100,000.00-$110,000.00. This is the range SevenRooms in good faith believes is the range of possible compensation for this role at the time of the posting. This range is only applicable for jobs to be performed remotely in any US state. Base pay offered may vary depending on, but not limited to education, experience, skills, geographic location, travel requirements, sales or revenue-based metrics, and business needs. This range may be modified in the future. This job is also bonus eligible. No amount is considered to be wages or compensation until such amount is earned, vested, and determinable.
  • Comprehensive benefits package: We offer a full slate of benefits for our employees and their families: comprehensive medical, dental, and vision benefits, commuter benefits, gym reimbursement, 401K plan, life insurance, and unique wellness offerings including One Medical, Spring Health, Carrot, and Headspace.
  • Employee programs and recognition: Through our Roomie's Choice program, all employees at SevenRooms receive a monthly stipend to spend however they see fit. You'll receive an additional quarterly dining credit to use towards SevenRooms clients and a unique milestone reward for every year you're a part of our team.
  • Opportunities for training and professional development: Your manager will partner with you on establishing quarterly goals that not only benefit our organization but aid in your overall career development and advancement. SevenRooms also provides financial support for continuing education, certifications, or participation in external training programs.
About SevenRooms

SevenRooms is a guest experience and retention platform that helps hospitality operators create exceptional experiences that drive revenue and repeat business. Trusted by thousands of hospitality operators around the world, SevenRooms powers tens of millions of guest experiences each month across both on- and off-premises. From neighborhood restaurants and bars to international, multi-concept hospitality groups, SevenRooms is transforming the industry by empowering operators to take back control of their businesses to build direct guest relationships, deliver exceptional experiences and drive more visits and orders, more often. The full suite of products includes reservation, waitlist and table management, online ordering, mobile order & pay, review aggregation, email marketing and marketing automation.

Founded in 2011 and venture-backed by Amazon, Comcast Ventures, PSG and Highgate, SevenRooms has dining, hotel F&B, nightlife, and entertainment clients in more than 1000 cities worldwide, including: Marriott International, Bloomin’ Brands, MGM Resorts International, Mandarin Oriental Hotel Group, Jumeirah Group, Hilton Hotels, The Cosmopolitan of Las Vegas, Harrods, Wolfgang Puck, Michael Mina, José Andrés Group, LDV Hospitality, Union Square Hospitality Group, Australian Venue Company, Altamarea Group, AELTC, The Wolseley Hospitality Group, Zuma, Live Nation and Topgolf.

SevenRooms has been recognized as a top employer for its people-first approach by publications including:

  • Inc. Best Workplaces (2023, 2022, 2020)
  • Inc. 5000 (2023, 2022)
  • Ragan’s Platinum HR Awards Finalist (2022)
  • Built in Best Places to Work NYC (2023, 2022, 2021, 2020) 
  • Built in Best Place to Work NYC - Midsize Companies (2023, 2022) 
  • VentureFizz Unique PTO (2022)
  • Forbes Best Startup Employers (2022) 

SevenRooms is an equal opportunity workplace and an affirmative action employer. We welcome all qualified applicants regardless of race, color, ancestry, religion, sex (including pregnancy and related conditions), national origin, sexual orientation, age, marital status, disability (physical or mental), gender identity, gender expression, genetic information, veteran status, citizenship, immigration status, or any other classification, category or characteristic protected by applicable federal, state or local laws.  We understand the importance of creating a more diverse and inclusive workplace and celebrate our employees for their differences.

View our Prospective Employee Privacy Notice by visiting https://bit.ly/2P6ey4M

#LI-Remote

#BI-Remote

Apply Now

Date Posted

09/23/2023

Views

11

Back to Job Listings Add To Job List Company Profile View Company Reviews
Neutral
Subjectivity Score: 0.5

Similar Jobs

Workplace Coordinator - Elastic

Views in the last 30 days - 0

View Details

Staff Editor, Current Events - Dotdash Meredith

Views in the last 30 days - 0

The Staff Editor role involves coordinating crossplatform content across multiple verticals managing daily and breaking news and writingediting storie...

View Details

Software Engineering Lead - Dotdash Meredith

Views in the last 30 days - 0

Dotdash Meredith is seeking a skilled Engineering Lead for a missioncritical role in designing and scaling their nextgeneration publishing platform Th...

View Details

Business Account Executive - Spectrum

Views in the last 30 days - 0

The Business Account Executive role involves selling primary and ancillary communications solutions to small and mediumsized businesses within a speci...

View Details