
Search by job, company or skills
Who are we
Checkmarx is the leader in application security and ensures that enterprises worldwide can secure their application development from code to cloud. Our consolidated platform and services address the needs of enterprises by improving security and reducing TCO, while simultaneously building trust between AppSec, developers, and CISOs. At Checkmarx, we believe it's not just about finding risk but remediating it across the entire application footprint and software supply chain with one seamless process for all relevant stakeholders.
We are honored to serve more than 1,800 customers, including 40 percent of all Fortune 100 companies, including Siemens, Airbus, Salesforce, Stellantis, Adidas, Walmart, and Sanofi.
What are we looking for
We are seeking a proactive and detail-oriented GRC Analyst to join our Information Security team. In this role, you will support and enhance the organization's Governance, Risk, and Compliance programs by conducting Vendor Risk Management (VRM) assessments, performing risk evaluations, and supporting internal and external audits, including SOC 2 Type 2 and ISO 27001. You will ensure alignment with industry standards such as NIST and ISO, enhance our security posture, and promote a culture of compliance and risk awareness across Checkmarx.
How will you make an impact
What is needed to succeed
Job ID: 126890913
Skills:
Gdpr, Iso 27001, Gcp, Hipaa, Azure, AWS, nist, GRC tools, SOC 2, PCI-DSS
Skills:
Pci Dss, Hipaa, Iso 27001, Csf, Cisa, DORA, NIST RMF, CRISC, SOC 2
Skills:
, Gdpr, Saas, Grc, Cloud Computing, AI Governance, Compliance Audits, ISO IEC 27001, Risk Management, CIS Controls, SOC 2, ISO 27701, CCPA, Security Policies, NIST CSF, It Audit, CSA CCM, Third-Party Risk Management, ISO IEC 42001, NIST AI RMF, NIST SP 800-53, CPRA
Skills:
Gdpr, Saas, Information Security, Cloud Computing, Grc, It Audit, CPRA, CCSK, NIST CSF, CIS Controls, AI RMF, SOC 2, CCPA, Risk Management, NIST SP 800-53, NIST AI Risk Management Framework, EU AI Act, CSA CCM, ISO IEC 27001, ISO IEC 42001, CRISC, ISO 27701, ISO IEC 23894
Skills:
Iso 27001, It Operations, third-party risk assessments, Zscaler for Endpoint, DLP Policies, security control evaluations, KRI development, CIS Controls, gap analyses, SOC 2, cybersecurity awareness training, NIST CSF, cybersecurity best practices, cybersecurity policies, vendor security evaluations, cybersecurity reporting and metrics, risk assessments
We don’t charge any money for job offers