Staff Security Privacy, Trust, and GRC Advisor
Job Description
Workrise is the network that powers the energy industry. By making it easier, faster, and safer to do business in energy, we are accelerating the pace of growth and innovation, and empowering the industry to do more - both for society and for the planet - than ever before.
Workrise is hiring a Staff Advisor, Security Privacy, Trust, and GRC that will be responsible for leading and driving the development and management of the data privacy, customer trust, and security governance, risk, and compliance functions. This role will need to build functions from scratch with limited oversight or direction to meet the objectives of the Security Organization. Our ideal candidate for this role will be someone who has multiple years of experience in the privacy, trust, or GRC space and wants to use that experience to build these functions for a promising and exciting startup. Additionally, this leader needs to be analytical, data driven, and forward thinking to ensure the privacy, trust, or GRC functions are built to scale the business. This role will be exempt and will report to the Director, Privacy & Trust.
Why join us? Our Security Privacy, Trust, and GRC team at Workrise is helping to build a modern and scalable platform for the future of the skilled labor workforce. You will be building and then owning security functions within the security organization. You will have the opportunity to engage with stakeholders and control owners across the organization as you work to build out all of the necessary pieces of privacy, trust, and GRC. You will provide real impact in moving the ball forward for privacy, trust, and GRC to allow Workrise to scale, grow, and win new business.
What you’ll be doing:- Manage the development, annual review, and off-cycle requests for security policy and standards.
- Manage the development and operation of cyber risk management programs, driving the documentation and management of risk treatment.
- Manage the execution of cyber risk assessments for business processes, technology, and products
- Provide guidance for the risk treatment/management process
- Build functions for the engagement of privacy, trust and GRC programs with customers, employees, and stakeholders to enable “Security-as-a-service” principles and goals
- Manage the GRC tooling and associated data
- Manage external audits by customers and certification bodies through the audit lifecycle
- Direct security IT audits to include evidence of lifecycle management, control walkthrough scheduling and execution, documentation of control CAPs, and management of corrective action plans
- Own and manage the development of security compliance programs for industry security frameworks (SOX ITGCs, AICPA TSC [SOC 2], ISO 27001, GDPR, CCPA, NIST CSF, etc)
- Make recommendations to management regarding programs, processes, etc.
- Provide support and mentors others on the team, sharing insights, knowledge, and experience
- Complete peer review for the team to ensure others understand data sources, improve
What you must have:
- Bachelor’s degree in computer science, Information Systems Management, Cybersecurity, Information Assurance or related field or equivalent relevant experience
- 8+ years of technical professional experience in IT audit, IT risk management, or security governance
- Extensive experience in assessing the effectiveness of information security controls (test of design, test of effectiveness, etc)
- Strong understanding experience with cyber risk management and mitigation
- Experience in access management, change management, security operations, etc
- Strong knowledge of multiple industry accepted information security frameworks (e.g. SOX ITGCs, AICPA TSC [SOC 2], ISO 27001, GDPR, CCPA, INST CSF, etc)
- Experience with public cloud solutions providers (AWS, Azure, and/or GCP)
- Experience bringing out GRC functions within third-party tooling platforms (Archer, Metricstream, ServiceNow, etc.)
- Strong working knowledge of Microsoft Office and Google Workspace.
- Exposure to working with 3rd parties on contract/engagement work (e.g. writing RFPs, getting quotes, writing business cases, reviewing SOWs, working with internal procurement teams, etc)
- Possess one or more industry accepted information security certification (CISA, CISSP, CRISC, CCSK, CIPPP, etc)
- Experience providing training and guidance to junior team members
- Strong communication and critical thinking skills, attention to detail, and experience collaborating cross-functionally with stakeholders.
Additional experience preferred, but not required:
- Experience in a startup environment
Essential Job Functions:
- Regular, on-time attendance
- Ability to travel <15% of the time
- Ability to communicate effectively
- Ability to use office equipment such as a computer, copier and telephone
- Ability to use office computer programs such as e-mail, Google Docs, Microsoft Word, PowerPoint and Excel
- Occasionally remain in a stationary position, often standing or sitting for prolonged periods
Workrise is uniquely positioned to make an impact on the energy transition, which is arguably the biggest challenge of our generation. Our clients are leading the charge. Through innovation and advancement in technology, we are creating solutions to help the industry do more today and meet the demands of this global challenge tomorrow. This is what we think about every day when we come to work.
We recognize that making an impact matters to you and we believe in providing an environment that fosters your growth. We use data to drive our decisions and improve the experience of the workers and clients we serve. With mutual respect for each other, we continually collaborate to find the best solution.
We support you with:Talented peers who can help bring out your best & the opportunity to significantly impact the lives of skilled laborers.
For eligible roles:
- Flexible paid time off for full-time employees
- Medical, dental, and vision insurance
- 401(k) with company matching contribution
- Flexible remote work support where applicable
- Professional development budget
- Wellness allowance
- Vacation stipend
- Learning opportunities through Udemy
- Financial planning support
- Parental leave
- Opportunity to earn bonus, commission, and/or equity
Workrise is committed to providing an environment where all people feel belonging, mutual respect, and the freedom to be their authentic selves. We welcome applicants of all gender identity and expression, sexual orientation, neurodiversity, educational background, religion, ethnicity, disability, age, veteran status, and citizenship. We’d love to learn what you can add to our team.
Who we are:
What began as a workforce management platform for Oil & Gas has since grown to serve the biggest companies in energy across both workforce and vendor management, absorbing much of the supply chain complexity these energy companies face and making it easier, faster, and safer to get work done. To date, Workrise has raised over $750M in funding from Founders Fund, Andreessen Horowitz, Bedrock Capital, Brookfield, and Baillie Gifford, along with others, and will continue to use these investments for strategic growth.
We’d love to share more through the interview process and look forward to learning more about your journey.
Date Posted
03/29/2023
Views
21
Similar Jobs
Senior Revenue Operations Analyst, Data Quality - Tripactions
Views in the last 30 days - 0
View DetailsSenior Manager, Customer Experience Technology - Tripactions
Views in the last 30 days - 0
View Details