About the job
About The Role
We are seeking a Senior Governance, Risk, and Compliance (GRC) Security Engineer to enhance our compliance and risk management initiatives across various frameworks, entities, and regions. The successful candidate will have substantial hands-on expertise with SOC 2, ISO 27001, and PCI DSS, alongside proficiency in modern compliance automation tools like Sprinto. This role requires the ability to design and manage a hybrid unified GRC framework that caters to multiple geographical operations.
Responsibilities
- Oversee the design, execution, and ongoing enhancement of the organization's Governance, Risk, and Compliance program.
- Manage compliance initiatives across critical frameworks including SOC 2, ISO 27001, and PCI DSS.
- Establish and sustain a hybrid unified GRC framework to implement a consistent control structure across various entities and regions.
- Align global baseline controls with local regulatory, legal, privacy, and operational mandates.
- Conduct risk assessments, compliance gap analyses, control reviews, and track remediation efforts.
- Develop, maintain, and enhance policies, standards, procedures, and control documentation.
- Lead audit readiness activities, including evidence collection, control walkthroughs, and auditor coordination.
- Facilitate cross-framework control mapping to minimize redundancy and enhance audit efficiency.
- Collaborate with Engineering, IT, Security, Legal, Privacy, HR, and business teams to integrate compliance into daily operations.
- Oversee third-party risk assessments, vendor due diligence, and continuous compliance evaluations for critical suppliers.
- Define and monitor Governance, Risk, and Compliance metrics, including compliance status reports and executive dashboards.
- Promote security awareness, policy governance, and continuous program improvements.
- Monitor changes in regulations and frameworks, assessing their implications across all relevant entities and regions.
