Senior Security Governance, Risk & Compliance Specialist
Posted 1hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior Security GRC Specialist strengthening Clario’s information security governance, risk, and compliance programs. Coordinating audits, assessments, third-party risk, controls, and security frameworks.
Responsibilities:
- Support and mature the organization’s Security GRC program
- Ensure IT, Product, and Information Security controls align with policies, standards, regulations, and best practices
- Coordinate and support external client audits, certifications, and assessments, including SOC 1, SOC 2, ISO 27001/2700x, client audits, and other assessments or accreditations
- Evaluate compliance status, identify control gaps, develop remediation plans, track progress, and drive issues through resolution
- Support the risk management framework, including inherent and residual risk assessments, risk tolerance evaluation, risk discussions, and internal and third-party risk assessments
- Assess, monitor, and manage information security risks associated with third parties, vendors, and external partners
- Support audit responses, client questionnaires, RFPs, findings, and assurance requests
- Develop, maintain, and govern Information Security policies, standards, procedures, and documentation
- Identify and recommend improvements to IT and Information Security compliance processes
- Apply ISO/IEC 27001, NIST, COBIT, and ITIL frameworks
- Develop compliance and risk reports, metrics, and management insights
- Support security education and awareness initiatives
- Collaborate with technical and non-technical teams and influence stakeholders
- Contribute to GRC tools, platforms, processes, and operational procedures
- Prioritize multiple initiatives and deliverables while maintaining quality and attention to detail
- Perform other related duties and projects as assigned
Requirements:
- Bachelor’s degree in Information Systems, Information Technology, Cybersecurity, or a related field; an Associate’s degree may be considered based on relevant experience and certifications
- 5+ years of experience in Information Technology, Information Security, Governance, Risk, and/or Compliance
- Strong experience building, maintaining, or maturing Security Governance, Risk, and Compliance programs
- Solid understanding of information security risk management and compliance methodologies
- Experience facilitating and leading risk discussions using qualitative and quantitative information
- Knowledge of ISO/IEC 27001, NIST Cybersecurity Framework, NIST 800-53, COBIT, and ITIL
- Experience supporting or coordinating security audits, assessments, certifications, and client assurance activities
- Experience with third-party/vendor security risk management
- Understanding of solution lifecycle management and related information security and compliance requirements
- Experience developing and implementing SOPs, policies, and processes
- Ability to influence and collaborate with stakeholders at different levels without formal authority
- Ability to establish and leverage internal and external cross-functional relationships
- Strong business acumen and ability to translate business needs into practical security and compliance solutions
- Excellent written and verbal communication skills for technical and non-technical audiences
- Experience working with globally distributed teams and stakeholders
- Ability to adapt to evolving security risks, regulations, technologies, and business requirements
- Relevant security certifications preferred, such as CISSP, CRISC, CISM, CISA, or FAIR



















