← Back to jobs
Makeawishamerica
Makeawishamerica

Lead Manager, Security Governance, Risk & Compliance

otherfull-timeRemote
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more

About the role

Position Summary

Work with a growing Information Technology Security team to support the organization's Governance, Risk, and Compliance (GRC) efforts. This role assists in maintaining policies, assessing risks, and ensuring compliance with regulatory requirements and internal standards. This position assists in the identification of control gaps, the development of remediation plans, and the monitoring of compliance activities. This position will contribute to activities such as audits, documentation, GRC application maintenance and the implementation of security controls, under the guidance of senior team members.

Knowledge and Abilities

  • Demonstrated successful problem-solving abilities.
  • Proficiency in project management, research, and data analysis.
  • Critical thinking and analytical skills to identify and diagnose threats.
  • Detail-oriented with strong organizational skills.
  • Possess strong written and verbal communication skills.
  • Engage effectively with professionals at all levels of the organization.
  • Organizational skills to create detail reports.
  • Multitasking skills to complete other tasks while monitoring data systems.
  • Organize work and prioritize to meet deadlines. Make timely decisions with sound judgment.

Duties & Responsibilities

  • Assist in the development, implementation, and maintenance of GRC frameworks and managing third-party risk.
  • Contribute to the assessment and mitigation of organizational risks.
  • Maintain internal policies, standards and security baselines, oriented toward compliance and regulatory standards - as well as, enforcement of secure practices.
  • Manage risk acceptance and policy exception processes, ingesting risks and creating tracking, reporting and accountability mechanisms.
  • Participate in audits of security controls and processes.
  • Assist with the creation and maintenance of documentation related to GRC activities, TPRM, Business Continuity Planning (BCP), Business Impact Analysis (BIA) and Disaster Recovery.
  • Assist in the identification of control gaps.
  • Contribute to the development of remediation plans.
  • Conduct due diligence on potential third-party vendors to evaluate their security posture, financial stability, and compliance with relevant regulations.
  • Assist in monitoring compliance activities.
  • Collaborate with various departments to integrate TPRM into vendor management processes.
  • Perform vendor and product risk assessments, to align vendors and products with applicable standards, policies and security baselines.
  • Create and maintain vendor questionnaire and Data Protection Agreements (DPA).
  • Vendor Responsibility Agreement, covering performance standards, security obligations, adherence to the Change Management process, training, communications, and documentation.
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $14.99/mo. Cancel anytime.
Join waitlist
Apply now
Lead Manager, Security Governance, Risk & Compliance at Makeawishamerica — Remote