| Senior Compliance: GRC Engineer: NO at Remote, Remote, USA |
| Email: [email protected] |
|
http://bit.ly/4ey8w48 https://jobs.nvoids.com/job_details.jsp?id=3655426&uid=f225fd072f444cd6b3f3d0b0809466cb From: Saurabh, SDH Systems LLC [email protected] Reply to: [email protected] Job Title: Senior Compliance / GRC Engineer Location: Remote Job Description Requirements We are seeking an experienced Senior Compliance / GRC Engineer to design, implement, and operationalize an enterprise-wide, risk-based information security compliance and controls framework. The ideal candidate will have hands-on experience designing an internal company risk-based controls framework from scratch, using ISO/IEC 27001:2022 and NIST Cybersecurity Framework (CSF) 2.0 as foundational frameworks. The candidate should also have practical implementation experience with Optro InfoSec Risk Management and Cross Comply modules, including configuration, control mapping, risk assessments, evidence management, compliance monitoring, and reporting. This role requires someone who understands both security/compliance frameworks and how to translate them into practical, measurable controls implemented across an organization. Key Responsibilities Design and establish an enterprise risk-based security controls framework from the ground up. Develop and maintain a comprehensive control library aligned with: ISO/IEC 27001:2022 NIST CSF 2.0 NIST SP 800-53 / 800-30 where applicable SOC 2 and other applicable regulatory/customer requirements. Perform control rationalization and cross-framework mapping to eliminate duplicate controls and establish a unified control framework. Develop control objectives, control activities, control owners, testing procedures, evidence requirements, and effectiveness criteria. Establish a risk-based approach to control prioritization, including inherent risk, residual risk, control maturity, risk acceptance, and remediation. Design and implement enterprise Information Security Risk Management processes. Configure and implement Optro InfoSec Risk Management capabilities, including: Risk identification and assessment Risk scoring and prioritization Risk treatment plans Risk acceptance Risk registers Risk monitoring and reporting Implement and operationalize Optro Cross Comply, including: Framework implementation Control mapping Compliance assessments Evidence collection Control testing Findings/remediation tracking Compliance dashboards and reporting. Establish processes for continuous control monitoring and compliance validation. Develop compliance metrics, KPIs, KRIs, and executive-level dashboards. Work with Security, Infrastructure, Cloud, IT, Application Development, HR, Legal, and business teams to establish and validate control ownership. Conduct internal control assessments and identify control gaps. Develop remediation plans and track corrective actions through closure. Support internal and external audits and provide evidence of control effectiveness. Establish a repeatable GRC operating model that can scale across business units, applications, cloud environments, and third parties. Continuously evaluate the effectiveness and maturity of the organization's control environment. Required Experience Must Have 7+ years of experience in Information Security, GRC, Compliance, Risk Management, or Cybersecurity. Demonstrated experience building an enterprise security/compliance controls framework from scratch. Strong hands-on experience with ISO/IEC 27001:2022. Strong hands-on experience with NIST CSF 2.0. Proven experience developing risk-based security controls, rather than simply implementing checklist-based compliance. Hands-on experience implementing Optro InfoSec Risk Management. Hands-on experience implementing Optro Cross Comply. Experience creating and maintaining: Enterprise control libraries Risk registers Control matrices Risk/control mappings Statements of Applicability Control testing methodologies Evidence requirements Corrective action/remediation processes. Experience conducting risk assessments and determining inherent vs. residual risk. Experience translating security risks into measurable and auditable controls. Experience working with control owners across IT, Cloud, Infrastructure, Security, Applications, and business functions. Preferred Experience ISO 27001 Lead Implementer or Lead Auditor certification. CISA, CISM, CRISC, CISSP, or equivalent. Experience with SOC 2, PCI DSS, HIPAA, GDPR, or other regulatory frameworks. Experience with cloud security compliance across Azure, AWS, or GCP. Experience developing third-party/vendor risk management programs. Experience with business continuity and disaster recovery controls. Experience with security architecture and technical control validation. Experience integrating GRC platforms with security and IT management tools. Experience developing executive-level risk and compliance dashboards. Key Competencies The candidate should be able to: Start with a blank sheet of paper and design a controls framework. Translate business and technology risks into specific security controls. Map one control across multiple frameworks without creating unnecessary duplicate controls. Determine whether a control is actually effectivenot merely whether documentation exists. Establish risk-based priorities instead of treating every compliance requirement equally. Configure and operationalize GRC technology rather than simply being a GRC platform user. Communicate technical risk effectively to both engineers and executives. Keywords: information technology Senior Compliance: GRC Engineer: NO [email protected] http://bit.ly/4ey8w48 https://jobs.nvoids.com/job_details.jsp?id=3655426&uid=f225fd072f444cd6b3f3d0b0809466cb |
| [email protected] View All |
| 10:39 PM 02-Sep-26 |