What are the responsibilities and job description for the Head of GRC position at Bloomreach?
Become the Head of GRC for Bloomreach! You will lead our Governance, Risk, and Compliance team. Our company provides the best digital experience for the top international e-commerce companies. Your work will impact hundreds of millions of consumers in the online space. You will work in one of our US offices or from home on a full-time basis, and be part of the GIST (Global Information Security & Technology) group.
Responsibilities:
- Design, deploy and lead the operations of a multi-year roadmap for the GRC programs
- Own and scale our policy and control framework supporting various compliance frameworks including ISO 27001 and SOC 2
- Build trust with our customers, by responding to customer security, and compliance questionnaires, and represent GRC on customer calls
- Improve third-party risk management processes and develop a comprehensive third-party risk management program
- Develop and implement robust Business Continuity Planning (BCP) programs
- Coach, educate, and engage Bloomreach employees across all teams and help drive security and privacy awareness and a culture of trust and compliance
Requirements:
- 7 years of proven experience in the GRC, internal audits, security, or privacy space
- 3 years of experience hiring, building and managing a team
- Strong leadership skills
- Excellent collaboration, communication, interpersonal, and issue resolution abilities
- Experience with risk management and compliance frameworks, including related regulatory and IT compliance requirements (e.g., SOC 2, NIST 800-53, ISO 27001)
- Significant experience in performing, running and executing audits, certification programs, and control assessments
- Experience working with Cloud technologies (e.g., AWS, GCP)
- Experience in the areas of policy governance, third party or vendor risk management, incident response, and business continuity planning