Remote job
GRC Specialist
Job details
About this role
Role overview
Support a cybersecurity governance, risk, and compliance program spanning enterprise systems, cloud platforms, products, and third parties. The specialist will maintain risk and control processes, help teams prepare for audits, and make security requirements practical across product delivery and operations.
Responsibilities
- Identify and assess enterprise, cyber, product, and third-party risks; maintain scoring, treatment plans, evidence, and risk acceptance approvals. - Run day-to-day compliance activities across ISO 27001, SOC 2, and NIST, mapping controls to reduce duplication. - Maintain security policies and standards, validate evidence, and improve compliance processes. - Prepare audit playbooks and coordinate with control owners to provide accurate evidence for external assessments. - Draft responses to customer security questionnaires, proposals, and due diligence requests. - Work with engineering, cloud operations, IT, and product teams to incorporate security into delivery, vendor onboarding, and release decisions; support awareness and risk communications.
Requirements
The available listing describes the responsibilities and frameworks in detail, but does not provide a complete, reliable set of required qualifications. It indicates a need to work across technical and nontechnical teams, manage audit evidence and risk workflows, and communicate security requirements clearly.
Nice to have
Experience with public-sector or highly regulated customers is identified as valuable. The listing also references AI-assisted hiring administration, while stating that final hiring decisions remain with people.
Benefits and work setup
Benefits described include health coverage, virtual healthcare, wellness support, retirement savings matching, incentive compensation, flexible vacation, and flexible work options. Internet and remote-work allowances and enhanced parental leave are also listed.