Responsibilities
- Lead and participate in both internal and external audits for frameworks including ISO 27001/27701, PCI-DSS, NIST 800-171, NIST 800-53 (FedRamp), and IRAP
- Experience using or exploring AI/automation tools to enhance, streamline, or scale Governance, Risk, and Compliance (GRC) processes and workflows
- Manage and oversee risk, compliance, and governance initiatives across teams
- Coordinate with process owners, control owners, auditors, and consultants to ensure findings are tracked and addressed
- Conduct risk assessments, security audits, and third-party/vendor risk reviews
- Review contracts to ensure security and compliance requirements are met
- Identify process gaps and recommend improvements to enhance the organization’s security posture
- Communicate risks and compliance requirements clearly to both technical and non-technical stakeholders
- Perform regular user access reviews
- Develop and track remediation plans for identified risks and issues
- Maintain and update the risk register
- Oversee vendor security assurance processes
- Collaborate with stakeholders to design and implement effective internal controls aligned with regulatory standards
- Support risk and security discussions across cross-functional teams
- Build strong working relationships across departments
- Take on additional responsibilities as needed
Requirements
- 8+ years of experience in cybersecurity programs, audits, risk management, compliance, or remediation
- Experience working with cloud platforms such as AWS, Azure, or Google Cloud
- Proven ability to negotiate and prioritize risk remediation with internal stakeholders
- Bachelor’s degree in Information Systems, Computer Science, Information Security, or a related field
- Strong understanding of security controls, including cloud environments, firewalls, IDS/IPS, and vulnerability management
- Familiarity with NIST 800-171 and NIST Risk Management Framework (NIST 800-53)
- Experience auditing frameworks such as PCI-DSS, SOC 2, and ISO 27001/27701
- Strong communication skills with the ability to translate compliance requirements into technical actions
- High energy and adaptability in a fast-paced environment
- Strong collaboration and a knowledge-sharing mindset
- Excellent time management and organizational skills
- High attention to detail, integrity, and ethical standards
- Willingness to learn and take on new challenges
Nice to Have
- Relevant certifications (CISSP, CISA, PCI ISA, ISO, or similar)
Benefits
- A vibrant and dynamic work environment
- A multitude of benefits they can enjoy inside and outside of their work lives
Additional Information
- May involve some international travel
- This position requires overlap with U.S. Pacific Time (PST) working hours. Candidates should be available and flexible to work from 2:00 PM to 11:00 PM IST.
- Strong hands-on experience with PCI audits, ISO 27001, NIST 800-171, FedRamp, SOC 2, and potentially IRAP is required.