Senior Cybersecurity GRC
You will architect and mature governance, risk, and compliance frameworks. You will lead SOC 2 Type II, ISO 27001, and ISO 22301 certification cycles, including evidence collection and auditor reviews. You will develop and maintain security policies, assess risks across SaaS, cloud, corporate IT, and digital-asset infrastructure, and manage third-party risk assessments and monitoring. You will support sales by responding to security questionnaires and client due-diligence requests, and you will run security-awareness, training, and phishing-simulation programs.
Responsibilities
- Lead end-to-end SOC 2 Type II, ISO 27001, and ISO 22301 certification cycles
- Develop, implement, and maintain security and compliance policies
- Perform continuous risk assessments across SaaS, cloud, corporate IT, and digital-asset infrastructure
- Lead third-party risk management from vendor assessments through ongoing monitoring
- Respond to information security questionnaires and client due-diligence requests
- Run security-awareness, training, and phishing-simulation programs
Requirements
- 5+ years of experience in IT compliance and GRC
- Hands-on ownership of at least one SOC 2 Type II and ISO 27001 cycle
- Experience working with GCP, GitHub, Jira, and Vanta
- Ability to translate technical and security requirements into audit-grade documentation and business language
- Ability to independently drive initiatives, manage priorities, and guide stakeholders
- Fluent English
- Familiarity with CCSS and cryptocurrency security standards
- Knowledge of cryptography, blockchain technology, or security-sensitive financial systems
- Experience with bank-grade security compliance standards and practices