Job Description
📋 Description Own and mature the security GRC program. Conduct enterprise and product risk assessments. Lead audits: SOC 2, ISO 27001, ISO 9001, TISAX. Drive Third Party Risk Management (TPRM) with vendor reviews. Build GRC infrastructure: tooling, reporting, governance. Partner with Legal, Engineering, IT, and Operations to embed compliance into processes. 🎯 Requirements 6+ years in security GRC, risk management, or compliance. Hands-on enterprise risk assessments; risk register ownership. Experience with NIST 800-53, CCF, and similar frameworks. Manage SOC 2, ISO 27001, and TISAX audits; scoping and evidence. Experience with Third Party Risk Management (vendor reviews). Interpret frameworks and drive cross-functional remediation. Strong communication to exec leadership and board. 🎁 Benefits Health, dental, vision, life and disability insurance. 401(k) with employer matching. Learning and wellness stipends. Paid time off and holiday leave.