Sr. Security Governance, Risk & Compliance Specialist

Clario

$110K — $130K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Systems, IT, Cybersecurity, or related field; Associate's degree may be accepted with relevant experience.
  • 5+ years in IT, Information Security, Governance, Risk, or Compliance.
  • Proven experience in building or enhancing Security Governance, Risk, and Compliance programs.
  • Strong knowledge of risk management and compliance methodologies.
  • Familiarity with frameworks like ISO/IEC 27001, NIST, COBIT, and ITIL.
  • Experience in coordinating security audits, assessments, and certifications.
  • Ability to influence and collaborate with diverse stakeholders.

Responsibilities

  • Support and mature the Security GRC program to ensure alignment with policies and best practices.
  • Coordinate external audits and certifications like SOC 1, SOC 2, and ISO 27001.
  • Evaluate compliance status of IT, Product, and Information Security controls and track remediation efforts.
  • Facilitate risk discussions and support risk assessments to evaluate inherent and residual risks.
  • Manage information security risks from third parties and external vendors.
  • Act as a primary contact for stakeholder interactions on security and compliance matters.
  • Identify opportunities for compliance process improvements using industry standards.

Benefits

  • Opportunity to influence security and compliance practices across the organization.
  • Work in a role that integrates with multiple departments including IT, QA, and legal.
  • Exposure to various external audits and certifications enhances professional credentials.
  • Engagement with both technical and non-technical teams fosters a dynamic work environment.
  • Possibility to contribute to the development and improvement of GRC tools and processes.
Full Job Description
The Senior Security GRC Specialist is a high-impact role focused on strengthening and maintaining information security governance, risk, and compliance across the organization. This position partners closely with QA, IT, Information Security, Legal, Product, and other internal stakeholders, as well as external clients, vendors, auditors, and assessment partners.

The role will help drive security and compliance initiatives, support risk management activities, coordinate audits and certifications, manage third-party security risk, and continuously improve security governance, policies, processes, and controls.

What You'll Be Doing
  • Security Governance, Risk & Compliance: Support and mature the organization's Security GRC program, helping ensure IT, Product, and Information Security controls align with applicable policies, standards, regulations, and best practices.
  • Audit & Assessment Coordination: Coordinate and support external client audits, certifications, and assessments, including SOC 1, SOC 2, ISO 27001/2700x, client audits, and other security assessments or accreditations.
  • Compliance Monitoring: Evaluate the compliance status of IT, Product, and Information Security controls. Partner with control owners to identify gaps, develop remediation plans, track progress, and drive issues through resolution.
  • Risk Management: Support the organization's risk management framework, including assessing inherent and residual risk, evaluating risk tolerance, facilitating risk discussions, and supporting periodic internal and third-party risk assessments.
  • Third-Party Risk Management: Execute established processes to assess, monitor, and manage information security risks associated with third parties, vendors, and other external partners.
  • Client Assurance & Regulatory Support: Serve as a key point of contact for QA, Regulatory, Customer, and other stakeholder interactions related to security and compliance. Support responses to audits, client questionnaires, RFPs, findings, and other assurance requests.
  • Policy & Standards Governance: Support the development, maintenance, and governance of the Information Security policies, standards, procedures, and related documentation.
  • Process Improvement: Identify opportunities to improve and mature IT and Information Security compliance processes. Use industry standards, emerging risks, regulations, and stakeholder feedback to recommend practical improvements.
  • Security Frameworks: Apply standards and best practices from frameworks such as ISO/IEC 27001, NIST, COBIT, and ITIL to support the organization's security and compliance objectives.
  • Reporting & Metrics: Develop compliance and risk reports, metrics, and management insights to communicate the status of key risks, controls, remediation activities, and compliance initiatives to stakeholders at various levels.
  • Security Awareness: Support security education and awareness initiatives by helping communicate new policies, procedures, and security practices to IT teams and the broader organization.
  • Cross-Functional Collaboration: Build strong relationships across technical and non-technical teams and influence stakeholders to support security, compliance, risk management, and governance objectives.
  • Program & Process Support: Contribute to the selection, implementation, improvement, and management of GRC tools, platforms, processes, and operational procedures.
  • Prioritization & Delivery: Effectively prioritize multiple initiatives and deliverables while maintaining a high level of quality and attention to detail.
  • Perform other related duties and projects as assigned.


What We Look For
  • Bachelor's degree in Information Systems, Information Technology, Cybersecurity, or a related field. An Associate's degree may be considered based on relevant experience and certifications.
  • 5+ years of experience in Information Technology, Information Security, Governance, Risk, and/or Compliance.
  • Strong experience building, maintaining, or maturing Security Governance, Risk, and Compliance programs.
  • Solid understanding of information security risk management and compliance methodologies.
  • Experience facilitating and leading risk discussions using both qualitative and quantitative information.
  • Knowledge of common information security and IT frameworks, including ISO/IEC 27001, NIST Cybersecurity Framework, NIST 800-53, COBIT, and ITIL.
  • Experience supporting or coordinating security audits, assessments, certifications, and client assurance activities.
  • Experience with third-party/vendor security risk management.
  • Understanding of solution lifecycle management and associated information security and compliance requirements.
  • Experience developing and implementing Standard Operating Procedures (SOPs), policies, and processes.
  • Strong ability to influence and collaborate with stakeholders at different levels, including situations where formal authority is not present.
  • Demonstrated ability to establish and leverage internal and external cross-functional relationships.
  • Strong business acumen and the ability to understand business needs and translate them into practical security and compliance solutions.
  • Excellent written and verbal communication skills, with the ability to communicate security risks, findings, recommendations, and requirements to both technical and non-technical audiences.
  • Experience working with globally distributed teams and stakeholders.
  • Strong learning agility and ability to adapt to evolving security risks, regulations, technologies, and business requirements.
  • Relevant security certifications are preferred, such as CISSP, CRISC, CISM, CISA, or FAIR.

Similar Jobs

More Jobs at Clario

More Information Technology Jobs

Find similar Sr. Security Governance, Risk & Compliance Specialist jobs: