How Remoteville checks and expires listings

Security GRC Lead

Skills
Compliance ManagementData PrivacyDocumentationISO 27001Information SecurityNISTNIST 800-53
Role

What the job involves

The main requirements, responsibilities and hiring steps.

Requirements

  • Bachelor's degree in a technical/security field or a non-technical degree with governance, risk and compliance-related work experience
  • 5-7+ years experience in risk, compliance management or in Information Security environment
  • Knowledge of security controls frameworks like ISO 27001/27002 and NIST 800-53
  • Experience with GRC tool
  • Excellent interpersonal communication teamwork and project management skills
  • Strong written and verbal communication skills
  • Ability to work independently with minimal direction and follow-up
  • Process analysis and control documentation skills
  • Proven analytical and troubleshooting skills
  • Understanding of information security risk and controls
  • Personal integrity accountability ability to take ownership of tasks
  • Ability to foster collaborative working relationships globally and remotely

Nice to have

  • Experience with ISO 27001
  • Experience with NIST 800-53

Day to day

  • Manage and support audit engagements ensuring requests are fulfilled appropriately by stakeholder management
  • Coordinate and collate required evidence for audit support
  • Manage control and process libraries assisting the business in implementing internal controls
  • Prepare agendas document meeting minutes and track follow-up completion
  • Lead junior staff in completing critical tasks on time
  • Lead Internal/External Audits documenting or evidencing control management practices
  • Participate in Risk Assessments documenting risks within the risk register identifying and documenting risk treatment
  • Assist the business in documenting assessing and remediating issues raised during audits and risk assessments
  • Manage Sprinklr security standards and policies
  • Update and maintain the GRC Confluence and share drives
  • Manage risks controls and requests in GRC tool
  • Occasionally attend conference call meetings outside normal office hours