Negotiable
Undetermined
Remote
Remote
Summary: The GRC - Cyber Security Engineer role focuses on managing and implementing governance, risk, and compliance (GRC) frameworks within the cyber security domain. The position requires expertise in risk management, data privacy, and technology audit, along with strong analytical and communication skills. The role is remote, allowing for flexibility in work arrangements while addressing critical security challenges. Candidates must possess relevant certifications and experience in the field.
Key Responsibilities:
- Implement and manage enterprise GRC platforms.
- Develop and implement risk management frameworks and conduct Cyber Security Risk Assessments, Threat Modelling, and control testing.
- Design and implement data privacy programs and manage compliance with major regulations (GDPR, CCPA, etc.).
- Author and manage the lifecycle of information security policies, standards, and procedures.
- Develop and mature Third-Party Risk Management (TPRM) programs and platforms.
- Understand cloud security governance and compliance management principles.
- Communicate complex risk concepts to diverse audiences and influence senior leadership.
Key Skills:
- Experience in Cyber Security GRC, Information Security Risk Management, Data Privacy, and Technology Audit.
- Proven experience implementing or managing enterprise GRC platforms.
- Expertise in developing and implementing risk management frameworks.
- Strong knowledge of AI governance and security.
- Demonstrated experience in designing and implementing data privacy programs.
- Experience in developing and maturing Third-Party Risk Management (TPRM) programs.
- Understanding of cloud security governance and compliance management principles.
- Excellent analytical, strategic thinking, and problem-solving skills.
- Superior communication and presentation skills.
- Certifications: CMMC, (Mandatory) CCP, CCA, LCCA.
Salary (Rate): undetermined
City: undetermined
Country: undetermined
Working Arrangements: remote
IR35 Status: undetermined
Seniority Level: undetermined
Industry: IT
Job Role: GRC- Cyber Security Engineer
Location: Remote
Skills:
Experience in Cyber Security GRC, Information Security Risk Management, Data Privacy, and Technology Audit.
• Proven experience implementing or managing enterprise GRC platforms.
• Expertise in developing and implementing risk management frameworks and conducting Cyber Security Risk Assessments, Threat Modelling, and control testing.
• Strong knowledge of AI governance and security, including experience assessing risks in AI/ML models and data pipelines and familiarity with frameworks like the NIST AI Risk Management Framework and OWASP Top 10 for LLMs.
• Demonstrated experience in designing and implementing data privacy programs and managing compliance with major regulations (GDPR, CCPA, etc.).
• Authored and managed the lifecycle of information security policies, standards, and procedures.
• Experience in developing and maturing Third-Party Risk Management (TPRM) programs and platforms.
• Understanding of cloud security governance and compliance management principles (e.g., Cloud Security Posture Management - CSPM).
• Excellent analytical, strategic thinking, and problem-solving skills.
• Superior communication and presentation skills, with the ability to influence senior leadership and articulate complex risk concepts to diverse audiences.
• Certifications: CMMC, ( Mandatory)CCP, CCA, LCCA.