IT Security - GRC Lead (Remote)

Chicago, IL


Apply Save

Type: Direct-Hire

Category: Information Technology

Salary: 140,000.00

Reference ID: 10022465

Shortcut: http://addisongroup.gosnaphop.com/V3f7hB


Title: Security - IT GRC Lead

Location: Remote USA

Salary: $125-135K + Bonus

No sponsorship offered


Our client is a public organization with locations all over the world. They have a 75 year track record of being a subscription/SaaS based organization.


Summary:

The IT Governance, Risk and Compliance (GRC) Lead position is an individual contributor role responsible for the implementation and operation of IT GRC activities for the Enterprise. The IT GRC Lead will help further and maintain IT GRC - leveraging the organization’s security standards and applicable compliance regulations and IT Compliance with applicable IT standards, laws, and regulations. This individual will have a strong understanding of the SSAE 18 AICPA reporting standards, and an understanding of compliance frameworks supported such as SOC1, SOC2 (Security, Availability, Confidentiality, Processing Integrity, and Privacy Trust Service Principles), NIST, HITRUST, HIPAA and GDPR. This position reports to the Director of GRC within the CISO organization.

 

Candidate should be able to “lead from the front”, have a strong sense of ownership and be able to work autonomously. Candidate should also demonstrate our CISO org behavior of: Engagement, Maintaining a Consultative Mindset, Accountability and Emotional Intelligence

Responsibilities:

Candidate will be directly responsible for leading and/or supporting GRC initiatives:

  • Annual IT audit programs including SSAE-18 SOC2, SOX 404, ISO 27001, NIST CSF, NIST 800-171, NIST 800- 218 certification(s) and HiTrust initiatives.
  • Integrate IT GRC requirements into broader technology governance processes (e.g., cybersecurity, operational readiness, SDLC, enterprise architecture, ITIL processes, client security, supply chain security), ensuring IT GRC and Compliance practices are operating across all facets of the enterprise.
  • Elevate Cyber risk-management function, including risk register and risk lifecycle processes (i.e., identification, assessment, remediation, exception/acceptance).
  • Support of Control Framework(s) including:
    • Designing, reviewing and testing effective IT/Security controls
    • Control Self-Assessment program (CSA/SCA) which is inclusive of testing key controls such as patch management, backup process, vulnerability management, cybersecurity and network related controls.
  • Interpret regulations affecting control standards and suggest methods of updating policies and practices that address any risk concerns so as to maintain IT and regulatory compliance.
  • Identify, define and update security standards and policies for servers, endpoints, network infrastructure, and cloud environments with supporting audit and reporting processes
  • Liaise with engineering, IT operations, IT Infrastructure, IT security, HR, Marketing and business teams to provide accurate and timely responses to internal and external audit requests and related activities.
  • Advocate for all business areas while accounting for and balancing risk
  • Produce and maintain appropriate, KPIs, Metrics and Reporting

Qualifications:

  • 8 or more years working in IT Governance, Risk and Compliance
  • 8 or more years of Information Technology related work experience.
  • 5 or more years’ experience in SOC/SOX related audits.
  • 5 or more years’ experience with Risk/Control Risk frameworks (NIST CSF, ISO, COBIT)
  • 5 or more years’ experience with Vulnerability Management
  • 3 years of experience with Cloud Governance, cloud applications and Infrastructure
  • Identity Governance and Administration (IGA) or Access Management experience
  • Experience leading projects and service delivery initiatives.
  • Internal/external customer facing experience

 

Ideal Expertise:

To excel in this role, the ideal candidate should possess the following expertise:

  • Subject matter expertise in IT Governance, Risk, and Compliance (GRC) discipline, with in-depth knowledge of IT Service Delivery, ITIL, and Project Management.
  • Strong understanding of current cybersecurity concepts, tools, and technology.
  • Proven experience in SSAE18 SOC, SOX, or HiTrust audits for medium to large enterprises.
  • Proficiency in risk frameworks and ISO27001, along with experience in Risk/Control Risk frameworks (NIST CSF, ISO, COBIT, COSO).
  • Technical proficiency in key IT areas, including UNIX, DNS, Windows Server, Internet routing, TCP/IP protocols, Network technologies, Active Directory, and foundational technology concepts.
  • Expertise in risk assessment procedures, policy formation, role-based authorization methodologies, authentication technologies, and knowledge of cyber-attack techniques.
  • Ability to relate business requirements and risks to technology implementation for security-related issues.
  • Strong cybersecurity acumen
  • Knowledgeable in IT Service Delivery, ITIL and Project Management.
  • Deep understanding of cybersecurity concepts including tools/technology
  • Working knowledge and experience with MS Office products including Word, Excel, PowerPoint & Visio and SharePoint 
  • Expert in writing/updating documentation to include standards, policies and procedures
  • Experience with industry tools (e.g., ServiceNow, Archer, Process Unity, Panorays, Omada)
  • O365 (Word, PowerPoint, SharePoint, OneDrive, Teams, Excel, PowerBI)
  • Continuous control monitoring and automation
  • Ability to be a trusted advisor relative to all things GRC related

Preferred Skills:

  • Demonstrated leader with team-oriented interpersonal skills; ability to effectively interface with a broad range of team members and roles.
  • Ability to work independently with or without direction and/or supervision.
  • Ability to prioritize workload and multitask. Flexibility and adaptability in work approach.
  • Ability to work directly with internal and external audit partners.
  • Calmness, clarity and due diligence process oriented and works well under pressure and has ability to maintain confidentially.
  • Strong written and verbal communication skills and maintains attention to detail


  • Chief Information Security Officer (CISO)

    Austin, TX

    Chief Information Security Officer (CISO) Reporting to the CIO, the Chief Information Security Officer (CISO) is a key role on the leadership team of the IT department. This position is responsible for the security of data and information assets. This ...

    Recommended

  • IT Security GRC Program Manager

    ,

    IT Security GRC Compliance Program Manager Alameda, CA Starting Base Salary Is: $120,000-$145,000 Visa Transfer for those that have 1 year or more on an active H1B Visa Individual compensation will vary based on factors such as qualifications, skill le...

    Recommended

  • SNOC Engineer II

    Pittsburgh, PA

    Job Title: SNOC Engineer II Office Location: Onsite Location: Pittsburgh, PA Salary: $85000 — $100000 Education/Experience · Bachelor’s degree from an accredited college or university in Computer Science, Information Systems, or related field. An equiv...

    Recommended

  • Sr. Network Security Engineer

    Alameda, CA

    Sr. Network Security Engineer Alameda, CA $200-215K Base Must be onsite 3X week Client will transfer a Visa with 1 year or more remaining. Job Description: The Sr. Network Security Engineer will be a member of the Information Security & Compliance team...

    Recommended

  • IT Systems Lead

    ,

    Position: IT Systems Lead Location: District of Columbia - Hybrid Are you looking for a growth opportunity for a reputable company with a positive work environment? Our client is looking for an IT Systems Lead to join their team. Please contact us toda...

    Recommended

  • Senior Azure Data Architect

    Frederick, MD

    Our client is looking for a Senior Data Architect to help design, build, and expand a leading technology platform in the financial services industry. As a Sr. Data Architect, you will be pivotal in shaping the organization's data strategy and infrastru...

    Recommended

  • Senior Cloud Security Engineer

    Alameda, CA

    Senior Cloud Security Engineer Alameda, CA $200K-$220K/year Visa Transfer for those that have 1 year or more remaining on an H1B Visa Job Description: The Senior Cloud Security Engineer will be a member of the Information Security & Compliance team. Th...

    Recommended

  • Cybersecurity Engineer

    Washington, DC

    Position: Cybersecurity Engineer Location: District of Columbia - Hybrid Are you looking for a growth opportunity for a reputable company with a positive work environment? Our client is looking for a Cybersecurity Engineer to join their team. Please co...

    Recommended

  • HSEQ Manager

    ,

    Job Description: BASIC FUNCTION This position is responsible for leadership of the Health, Safety, Environmental, and Quality functions. Responsibilities include the monitoring and reviewing of all quality control and quality assurance related activiti...

    Recommended

  • Costpoint SME (Business Systems Analyst)

    Arlington, VA

    Position: Costpoint SME (Business Systems Analyst) Location: Arlington, VA Are you looking for a growth opportunity for a reputable company with a positive work environment? Our client is looking for a Costpoint SME (Business Systems Analyst) to join t...

    Recommended

  • Data Governance Professional

    Oklahoma City, OK

    Data Governance Professional Direct Hire Oklahoma City, OK – remote a few days a week Pay: up to $115K DOE ** Must be authorized to work in the United States, now and in the future, without assistance! ** Our client is looking to add to their data gove...

    Recommended

  • Chief Enterprise Architect CEA

    Austin, TX

    Chief Enterprise Architect Direct Hire/Full Time Austin, TX $180K-$190K The Chief Enterprise Architect (CEA) is responsible for the organization's overall Enterprise Architecture. This role is typically engaged as the highest-level technology expert ac...

    Recommended

  •  Senior IT Auditor

    Bellevue, WA

    Job Name: Senior IT Auditor Location: Bellevue, WA (4 days in-office) Pay Rate: $120 - $130K/Year Job ID: 10021180 Company Overview: Our client is a stable Bellevue, WA public company with operations across the globe. We are recruiting for a skilled Se...

    Recommended

  • IT Site Manager - Roseville, CA

    ,

    IT Site Manager Roseville, CA (Sacramento, CA AREA) Onsite 5X weekly Annual Base Salary Range: $120,000 - $160,000 / year Visa Transfer for Visa's with 1 year or more left on them. We offer a competitive compensation package plus a benefits and equity ...

    Recommended

  • Solutions Architect

    Katy, TX

    Work Experiences: 10+ years’ of experience related to IT Management or other information technology solutions architecture role Experience in Data Integration patterns and tools Experience in designing solutions in cloud and hybrid cloud environments U...

    Recommended