Search by job, company or skills

Velsera

Senior InfoSec GRC Specialist

8-10 Years
new job description bg glownew job description bg glownew job description bg svg
  • Posted 27 days ago
  • Be among the first 10 applicants
Early Applicant

Job Description

Senior InfoSec GRC Specialist


Descriptio

nWhat will you do

Compliance & Governanc

  • eDevelop, implement, and maintain comprehensive information security policies, standards, and procedures aligned with the ISO 27001 framewor
  • kLead, manage, and mature the organization's Information Security Management System including risk treatment, internal audits, and readiness for external certification audits
  • .Serve as the subject matter expert (SME) for Security and Privacy Rules, ensuring compliance for all systems, processes, and applications handling PII and Protected Health Information (PHI)
  • .Conduct continuous monitoring and evidence collection to demonstrate compliance with relevant frameworks
  • .Plan, conduct and manage internal and supplier audit
  • sPlan GRC activities, prioritise and implement them in timebound manner
  • .Perform detailed security risk assessments and gap analyses on new and existing systems, with a focus on cloud infrastructur
  • eCollaborate with Product, Technology, IT and Security teams to implement security controls into cloud / infra / environments, ensuring compliance. Provide technical guidance to them on implementing controls and best practices, specifically related to cloud security architecture and configurations
  • .Review risk mitigations periodically and track remediation efforts to closure
  • .Conduct third-party vendor risk assessments, focusing on their adherence to required compliance standards
  • .Develop and deliver targeted security awareness and training programs focused on HIPAA and ISO 27001 requirements for all staff, including technical teams
  • .Evaluate and recommend new security technologies and processes to enhance the compliance and risk posture
  • .Stay current on emerging cloud security threats, regulatory changes, and updates to the ISO 27001 family of standards and HIPAA

.
Requiremen

tsWhat do you bring to the tabl

eExperienc

  • e:Minimum of 8+ years of progressive experience in Information Security GRC, with a focus on risk management, compliance, and governanc
  • e.Proven, hands-on experience driving and maintaining ISO 27001 certification program
  • s.Deep practical knowledge and experience of implementing security controls ensuring compliance in a technical, cloud-centric environmen
  • t.Strong technical competency in Cloud Security (AWS, Azure, or GCP) and related cloud-native security service
  • s.Education: Bachelor's degree in IT, Computer Science or related fiel
  • d.Certifications (One or more highly preferred
  • ):CISSP (Certified Information Systems Security Professiona
  • l)CISA (Certified Information Systems Audito
  • r)ISO 27001 Lead Implementer/Audit
  • orCCSK (Certificate of Cloud Security Knowledge) or equivalent Cloud-specific security certification (e.g., AWS Certified Security, Azure Security Engineer

).
Soft Ski

  • llsProficiency in written and verbal communication skills with the ability to translate complex security and compliance requirements / controls into clear actiona
  • bleStrong project management and organizational skills to handle multiple, simultaneous audit and compliance initiativ
  • es.A collaborative and proactive mindset, with the ability to influence and lead cross-functional teams without direct authori

ty.
Bene

  • fitsFlexible Work & Time Off - Embrace hybrid work models and enjoy the freedom of unlimited paid time off to support work-life bala
  • nce.Health & Well-being - Access comprehensive group medical and life insurance coverage, along with a 24/7 Employee Assistance Program (EAP) for mental health and wellness supp
  • ort.Growth & Learning - Fuel your professional journey with continuous learning and development programs designed to help you upskill and g
  • row.Recognition & Rewards - Get recognized for your contributions through structured reward programs and campai
  • gns.Engaging & Fun Work Culture - Experience a vibrant workplace with team events, celebrations, and engaging activities that make every workday enjoya
  • ble.& Many Mor

e...

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 133300749

Similar Jobs