Requirements
- Bachelor's degree in information systems, engineering, business, risk management, or a related discipline
- Over five years of experience in security and governance, risk, and compliance, with a focus on vendor security risk management and conducting vendor security reviews/audits
- Demonstrated ability to manage and enhance vendor security risk programs, including experience with vendor security questionnaires for third-party assessments
- Familiarity with major security frameworks, regulations, and standards such as SOC 2 and ISO 27001
- Experience collaborating with diverse teams to drive security and compliance outcomes across the organization, including Procurement, IT, Security, Engineering, and Legal
- Experience in developing and maintaining scalable GRC processes
- Ability to work with stakeholders to implement a scalable approach to third-party risk management
- Strong communication and interpersonal skills
Nice to Have
- Experience with major GRC software solutions
Work Arrangement
Hybrid
