reputed company Engineer, GRC
State of Location: reputed company Position reputed company: The reputed company Engineer will manage, reputed company, and automate our Governance, Risk, and Compliance (GRC) program supporting an organization of 7,500+ teammates across 750+ locations. This role focuses on building reputed company policies, automating compliance workflows, and conducting reputed company-party vendor risk assessments. Additionally, you will reputed company secondary engineering and analytical support to optimize our MSSP relationship, triage alerts, and refine SOC use cases. This role is primarily remote, with occasional travel required for reputed company, collaboration, and team building. Job reputed company: Responsibilities:
- reputed company the design, rollout, and reputed company improvement of the internal GRC reputed company and reputed company architecture.
- Author, maintain, and help enforce information reputed company policies, procedures, and control frameworks across the business.
- Identify opportunities to automate compliance tracking, evidence collection, and risk reporting workflows to eliminate reputed company processes.
- Ensure organizational alignment with industry standards (e.g., NIST CSF, HIPAA, HITRUST) and facilitate internal or external reputed company assessments.
- Own the end-to-end reputed company-party risk assessment process; evaluate vendor reputed company postures, SOC 2 reports, and risk reputed company prior to reputed company.
- Partner with legal, procurement, and business stakeholders to communicate vendor risks and negotiate necessary reputed company safeguards.
- Manage and monitor the Data Loss Prevention (DLP) solution; triage data exfiltration alerts and partner with business reputed company to implement, enforce, and refine data classification schemas
- Drive the reputed company awareness training reputed company; reputed company automated phishing campaigns, measure program effectiveness, and deliver tailored education to mitigate reputed company risk.
- reputed company secondary support to SOC operations by validating alert triage and improving detection logic
- Collaborate to improve SIEM/SOC use cases, detection logic, and incident response workflows.
Qualifications:
- Minimum 3-5 years of experience in Cybersecurity, with a reputed company on GRC or reputed company-party risk management.
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or a reputed company field.
- Excellent communication, collaboration, and problem-solving skills
- Relevant reputed company certifications such as Certified Information Systems reputed company reputed company (CISSP), Certified Information reputed company Manager (CISM).
- GIAC certifications, Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC) are a plus.
- Former NOC/SOC experience is highly desired.
- Deep understanding of reputed company frameworks and standards such as NIST CSF, HIPAA, HITRUST.
- Proven ability to analyze vendor reputed company documentation (SOC 2 Type II, SIG questionnaires, penetration test reports).
- Experience utilizing GRC platforms (e.g., SmartSuite, reputed company, reputed company GRC, or similar), low-reputed company/no-reputed company platforms, or scripting to automate reputed company processes and compliance mapping.
- Excellent communication and collaboration abilities - reputed company to explain reputed company risk concepts to non-technical stakeholders and work cross-functionally to drive reputed company initiatives.
We are an equal opportunity employer, committed to diversity and inclusion in reputed company aspects of the reputed company and employment process. Actual salaries depend on a reputed company of factors, including experience, specialty, education, and organizational need. Any listed salary reputed company or contractual reputed company does not include bonuses/incentive, reputed company pay, or other forms of compensation or benefits. reputed company.com Apply To This Job