What are the responsibilities and job description for the GRC Manager position at Guideline, Inc.?
Guideline is looking for a highly-motivated, experienced and collaborative individual able to serve as the GRC Manager.
What will you be working on?
You will serve as a leader and subject matter expert for Risk Management, Vendor Security Assessments, Data governance, and SOC amongst others. You'll have the opportunity to expand and mature the Risk Management process across the organization, successfully embedding Risk Management into culture itself. Besides uncovering and reducing hidden risks, you'll also be proactively leading table top exercises to strengthen existing processes and IR/BRC/DR.
The successful candidate will make a huge mark as the company continues to rapidly grow. The candidate will have direct influence on the future of Guideline’s security initiatives and objectives.
Responsibilities
- Lead Security tabletop exercises and work with stakeholders to strengthen IR/BCR/DR.
- Mature and manage the data risk program level including risk registers, risk identification, tracking, prioritization and driving resolution of project/program level issues
- Perform application and vendor security assessments, both initial and annual, effectively communicating the risks to internal stakeholders.
- Help maintain and mature internal corporate Information Security Policies.
- Lead the annual SOC auditing effort.
- Collaborate with various key stakeholders to gain a common understanding of issues related to the control breakdowns/missing controls to define a specific commitment to strengthen or implement controls.
Qualifications
- 10 years of experience in data management and/or risk and compliance programs
- 5 years experience leading projects and initiatives
- Familiarity with data related regulations including privacy, cybersecurity, data localization. Familiarity with retirement regulations a plus
- Understanding of risk management methodologies, frameworks, and principles (e.g. SOX, COBIT, NIST, CSA, ITIL, PCI, GDPR, CCPA etc.)
- Excellent verbal and written communication skills, the ability to communicate up, down, and across, while tailoring the message accordingly
- Highly motivated individual with the ability to self-start, prioritize, multi-task, and has a "can-do" attitude
More about Guideline
Employee Benefits
- Flexible Vacation Policy
- 401(k) Matching
- 100% coverage of Health / Vision / Dental
- Generous parental leave policy
Guideline provides equal employment opportunities to all employees and applicants for employment without regard to race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.