Senior Manager, Security GRC ( Remote, USA)
Job Description
Team
Our Security Assurance department is in the business of trust, transparency, and advisory. We aim to prove to others and ourselves that we are trustworthy and do what we say. We deliver on this by aligning missions across four core programs: Supply Chain Risk Management, Privacy Operations, Security GRC, and Customer Trust & Security. In addition, we have a team of intelligent, dedicated, and highly collaborative SMEs responsible for building and maintaining well-defined solutions that help grow our business.
To support our growth and ambitious vision, we embrace agile principles and values, share openly, apply context-driven security mechanisms, default to action, and have an OSS-first mindset. We are a 100% remote company.
Role
The Senior Security GRC Manager will collaborate with teams across the company to understand, contextualize, design, implement, and report on our global security, risk, compliance, and technology requirements for security. Ideally, you would be familiar with operating in a cloud-native, remote product organization.
This is a people manager role reporting to the Director of Security Assurance.
Skills
A successful candidate in this role would be able to:
Develop, build, and roll out information, cyber, open source and cloud security governance frameworks.
Lead a security governance structure that drives effective decision-making across the Grafana leadership team.
Establish a cadence for security program reviews, support existing accreditations and identify strategic maturity opportunities for compliance.
Implement a mechanism for quantifiable risk-based security evaluation, prioritization and ownership.
Build partnerships with cross-functional stakeholders who are decision-makers for security initiatives.
Socialize and provide awareness of policies, standards, processes, and controls with relevant stakeholders.
Design a comprehensive Security Risk Management framework aligned with the business and security strategies.
Develop and manage Security GRC reporting metrics and dashboards.
Partner with engineering and operations teams on the business continuity and digital resilience program.
Identify, design, and implement process improvement initiatives to ensure scalability, allowing us to work smart and reduce repetitive tasks for customers and internal teams.
Knowledge
You should know a lot about:
Security governance, risk management and compliance engineering in cloud-native environments (GCP, AWS, Azure, Kubernetes, LogicGate, Secureframe, Jira, ServiceNow GRC).
Information security frameworks and standards (SOC 2, ISO 27001, ISO 27018, ISO 27017, ISO 22301, CISv8, CSA STAR and TISAX).
Securing the workforce of a remote-first organization.
Operationalizing Business Impact Assessments (BIAs) and Business Continuity Management Systems (BCMS).
Translating minimum viable policies into realistic and measurable controls. Read more here: https://grafana.com/blog/2021/12/20/the-values-behind-scaling-cloud-native-security-at-grafana-labs/
You should have some knowledge of the following:
Privacy regulations and frameworks (GDPR, CPRA/CCPA, CSA CoC for GDPR, Privacy Shield, SCCs, ISO 27701).
Corporate IT security operations, technology trends, and current cyber threat landscape.
Working with Solutions Engineers and GTM teams to provide adequate artifacts for customer requirements.
Aptitude
You should be able to demonstrate the following:
Passion for understanding our customers, open source community, products, culture, and business model.
A strong desire to learn in a rapidly growing and dynamic startup environment.
Ability to work closely with end users in a consulting or support capability.
Excellent written and verbal communication skills.
Good interpersonal skills and capabilities to build long-term business relationships.
Education
BS/MS degree in engineering, computer science, or information security, or equivalent experience.
CISSP, CISA, CISM and/or other cloud security solutions certifications are a plus
In the United States, the Base (OTE for commission positions) compensation range for this role is $168,000- $ 201,000. Actual compensation may vary based on level, experience, and skillset as assessed in the interview. Benefits include equity, bonus (if applicable) and other benefits listed here.
Date Posted
03/18/2023
Views
13
Similar Jobs
Software Engineering Manager - Cargill
Views in the last 30 days - 0
The Software Engineering Manager job involves setting goals for a team responsible for software project development and delivery ensuring quality stan...
View DetailsSales Development Representative - UK (Remote) - Dscout
Views in the last 30 days - 0
Dscout is a company that specializes in experience research solutions helping innovative companies like Salesforce Sonos Groupon and Best Buy to build...
View DetailsSenior Finance Business Partner (d/f/m) - Personio
Views in the last 30 days - 0
Personio an intelligent HR platform is seeking a Senior Manager for FPA to lead financial planning and analysis for key departments The ideal candidat...
View DetailsSenior Lead, Talent Acquisition - Sales (Relocation to Munich) (d/f/m) - Personio
Views in the last 30 days - 0
Personio a leading HR platform is seeking a Senior Lead Talent Acquisition professional to drive growth in the Revenue and Success functions across Eu...
View DetailsSenior Pricing Analyst - Cencora
Views in the last 30 days - 0
Cencora formerly known as AmerisourceBergen is a leading global pharmaceutical solutions organization They are currently experiencing rapid growth in ...
View DetailsSenior Product Analyst - FinCrime Platform - WISE
Views in the last 30 days - 0
Wise is seeking a Senior Product Analyst for its FinCrime Platform The role involves driving analytics efforts in the Financial Crime Platform product...
View Details