Home

Senior Compliance: GRC Engineer: NO at Remote, Remote, USA
Email: [email protected]
http://bit.ly/4ey8w48
https://jobs.nvoids.com/job_details.jsp?id=3655426&uid=f225fd072f444cd6b3f3d0b0809466cb

From:

Saurabh,

SDH Systems LLC

[email protected]

Reply to: [email protected]

Job Title: Senior Compliance / GRC Engineer
Location: Remote

Job Description

Requirements

We are seeking an experienced Senior Compliance / GRC Engineer to design, implement, and operationalize an enterprise-wide, risk-based information security compliance and controls framework.

The ideal candidate will have hands-on experience designing an internal company risk-based controls framework from scratch, using ISO/IEC 27001:2022 and NIST Cybersecurity Framework (CSF) 2.0 as foundational frameworks. The candidate should also have practical implementation experience with Optro InfoSec Risk Management and Cross Comply modules, including configuration, control mapping, risk assessments, evidence management, compliance monitoring, and reporting.

This role requires someone who understands both security/compliance frameworks and how to translate them into practical, measurable controls implemented across an organization.

Key Responsibilities

Design and establish an enterprise risk-based security controls framework from the ground up.

Develop and maintain a comprehensive control library aligned with:

ISO/IEC 27001:2022

NIST CSF 2.0

NIST SP 800-53 / 800-30 where applicable

SOC 2 and other applicable regulatory/customer requirements.

Perform control rationalization and cross-framework mapping to eliminate duplicate controls and establish a unified control framework.

Develop control objectives, control activities, control owners, testing procedures, evidence requirements, and effectiveness criteria.

Establish a risk-based approach to control prioritization, including inherent risk, residual risk, control maturity, risk acceptance, and remediation.

Design and implement enterprise Information Security Risk Management processes.

Configure and implement Optro InfoSec Risk Management capabilities, including:

Risk identification and assessment

Risk scoring and prioritization

Risk treatment plans

Risk acceptance

Risk registers

Risk monitoring and reporting

Implement and operationalize Optro Cross Comply, including:

Framework implementation

Control mapping

Compliance assessments

Evidence collection

Control testing

Findings/remediation tracking

Compliance dashboards and reporting.

Establish processes for continuous control monitoring and compliance validation.

Develop compliance metrics, KPIs, KRIs, and executive-level dashboards.

Work with Security, Infrastructure, Cloud, IT, Application Development, HR, Legal, and business teams to establish and validate control ownership.

Conduct internal control assessments and identify control gaps.

Develop remediation plans and track corrective actions through closure.

Support internal and external audits and provide evidence of control effectiveness.

Establish a repeatable GRC operating model that can scale across business units, applications, cloud environments, and third parties.

Continuously evaluate the effectiveness and maturity of the organization's control environment.
Required Experience

Must Have

7+ years of experience in Information Security, GRC, Compliance, Risk Management, or Cybersecurity.

Demonstrated experience building an enterprise security/compliance controls framework from scratch.

Strong hands-on experience with ISO/IEC 27001:2022.

Strong hands-on experience with NIST CSF 2.0.

Proven experience developing risk-based security controls, rather than simply implementing checklist-based compliance.

Hands-on experience implementing Optro InfoSec Risk Management.

Hands-on experience implementing Optro Cross Comply.

Experience creating and maintaining:

Enterprise control libraries

Risk registers

Control matrices

Risk/control mappings

Statements of Applicability

Control testing methodologies

Evidence requirements

Corrective action/remediation processes.

Experience conducting risk assessments and determining inherent vs. residual risk.

Experience translating security risks into measurable and auditable controls.

Experience working with control owners across IT, Cloud, Infrastructure, Security, Applications, and business functions.
Preferred Experience

ISO 27001 Lead Implementer or Lead Auditor certification.

CISA, CISM, CRISC, CISSP, or equivalent.

Experience with SOC 2, PCI DSS, HIPAA, GDPR, or other regulatory frameworks.

Experience with cloud security compliance across Azure, AWS, or GCP.

Experience developing third-party/vendor risk management programs.

Experience with business continuity and disaster recovery controls.

Experience with security architecture and technical control validation.

Experience integrating GRC platforms with security and IT management tools.

Experience developing executive-level risk and compliance dashboards.
Key Competencies

The candidate should be able to:

Start with a blank sheet of paper and design a controls framework.

Translate business and technology risks into specific security controls.

Map one control across multiple frameworks without creating unnecessary duplicate controls.

Determine whether a control is actually effectivenot merely whether documentation exists.

Establish risk-based priorities instead of treating every compliance requirement equally.

Configure and operationalize GRC technology rather than simply being a GRC platform user.

Communicate technical risk effectively to both engineers and executives.

Keywords: information technology
Senior Compliance: GRC Engineer: NO
[email protected]
http://bit.ly/4ey8w48
https://jobs.nvoids.com/job_details.jsp?id=3655426&uid=f225fd072f444cd6b3f3d0b0809466cb
[email protected]
View All
10:39 PM 02-Sep-26


To remove this job post send "job_kill 3655426" as subject from [email protected] to [email protected]. Do not write anything extra in the subject line as this is a automatic system which will not work otherwise.

Pages not loading, taking too much time to load, server timeout or unavailable, or any other issues please contact admin at [email protected]


Time Taken: 0

Location: ,