The Senior Cybersecurity Specialist – Governance, Risk & Compliance (GRC) provides senior-level leadership and subject matter expertise in the development, governance, and oversight of the organization’s security risk and compliance program. This role owns and maintains the enterprise security governance framework, policy lifecycle, and risk management processes. The Senior Cybersecurity Specialist – GRC establishes control requirements, ensures traceability to regulatory and framework obligations, and advises business and technology stakeholders on security risk and compliance matters. Operating in an advisory and governance capacity, this role does not perform operational execution of controls. Business and technology owners retain responsibility for implementation and risk acceptance decisions. The Senior Cybersecurity Specialist – GRC: Owns and maintains the enterprise security risk register and policy lifecycle. Defines and governs security standards aligned to the enterprise security framework and applicable regulatory requirements. Facilitates risk assessments and communicates security risks in business terms. Coordinates audit and compliance activities and oversees remediation tracking. Establishes and governs third-party security risk management practices. Leads governance scoping activities for initiatives impacting the GRC domain. Develops and reports key performance indicators related to governance, risk, and compliance maturity. Escalates material risks through established governance channels and supports formal risk documentation processes.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior