We are currently seeking a Senior Governance Risk and Compliance (GRC) Specialist to join our team.
The ideal candidate will have 10+ years' of experience and a deep understanding of widely accepted information security frameworks such as NIST Cybersecurity, HIPAA, PCI, HITRUST, ISO 27001 among others and will be responsible for identifying, assessing, monitoring, and prioritizing Infosec risks across multiple domains.
Key Responsibilities:
• Provide expert knowledge on information security principles and theory.
• Analyze, interpret, and apply information security policies and standards.
• Perform thorough and detailed risk assessments framework for proposed projects and system developments
• Evaluate the effectiveness of supplier/third-party managed cybersecurity requirements.
• Responsible for interpreting the security testing results.
• Identify potential vulnerabilities in systems and recommend solutions to mitigate risks.
• Make recommendations for enhancements in the areas of risk management, governance, and compliance.
• Work closely with department heads to ensure relevant compliance resources are adequately and timely delivered.
Qualifications:
• Deep understanding of widely accepted information security frameworks, like NIST Cybersecurity, HIPAA, PCI, Shared Assessments (SIG), etc.
• Demonstrated understanding of cloud security.
• Experience evaluating cloud hosting environment
• Valid security certifications such as CCSP, CCSK, CCSA, CISM, CRISC, CISA, CISSP are preferred.
• Experience identifying, assessing, monitoring, and prioritizing Infosec risks across multiple domains
The role is both strategic and technical, requiring a high level of expertise in information security, risk management, and compliance. The successful candidate will have a strong ability to communicate complex issues to stakeholders at all levels effectively.