GRC (Governance, Risk, Compliance) Manager
Job Summary:
The GRC Manager will spearhead the organization's Governance, Risk, and
Compliance strategies, specifically focusing on Third Party Risk Management
(TPRM) and threat modeling. This role is pivotal in safeguarding the
organization against cyber security threats while ensuring adherence to
regulatory requirements and best practices, enhancing the overall risk
posture.
Key Responsibilities:
-
Lead the development and implementation of comprehensive TPRM policies and
processes to mitigate third-party risks.
-
Conduct thorough threat modeling exercises to identify vulnerabilities and
develop strategic risk management frameworks.
-
Collaborate with cross-functional teams to assess and improve cybersecurity
measures and compliance practices.
-
Monitor and report on risk metrics and compliance status to key
stakeholders, ensuring alignment with business objectives.
-
Facilitate risk assessments and audits to evaluate the effectiveness of
current GRC programs and controls.
-
Update and maintain documentation related to compliance frameworks and risk
management processes.
-
Provide training and support to teams on GRC initiatives, fostering a
culture of risk awareness within the organization.
Requirements:
-
Bachelor's degree in Cyber Security, Information Technology, Risk
Management, or related field.
-
Minimum of 6 years of experience in governance, risk, compliance, or
cybersecurity roles with a focus on TPRM.
-
Strong understanding of risk management frameworks, regulatory requirements,
and compliance standards (e.g., NIST, ISO, PCI-DSS).
-
Proficient in threat modeling methodologies and tools to analyze cyber
threats and vulnerabilities effectively.
- Excellent analytical, problem-solving, and decision-making skills.
-
Ability to communicate complex risk concepts to diverse audiences, including
senior management.
-
Strong project management skills with a proven track record of leading
initiatives to completion.
Preferred Qualifications:
-
Master's degree in a relevant discipline or relevant certifications (e.g.,
CISSP, CISM, CRISC).
- Experience with GRC software solutions and their implementation.
-
Proven ability to work effectively in a fast-paced, teamwork-oriented
environment.
-
Familiarity with emerging technologies and their impact on risk and
security.
Benefits:
- Competitive salary and performance-based bonuses.
-
Comprehensive health and wellness benefits, including medical, dental, and
vision coverage.
-
Flexible working hours and remote work options to promote work-life balance.
- Generous paid time off policy and company holidays.
-
Opportunities for professional development and continuing education
reimbursement.
-
Collaborative and inclusive workplace culture focused on employee
engagement.
- Retirement savings plan with company matching contributions.