דלג לתוכן הראשי

GRC Specialist

Torqתל אביב-יפו, מחוז תל אביב, ישראללא צויןFull-timeדרגה: לא צוין

פורסם לפני 25 ימים · 124 מועמדים

שכר לא צוין במשרה זו

שמירה, הגשה או בדיקת התאמה — כמה שניות להקמת חשבון חינם.

תובנת Willbi

התפקיד במילים פשוטות

התפקיד כולל בעלות על תוכניות אבטחת מידע ותאימות, כולל SOC 2, ISO 27001, C5 BSI ו-ISO 42001, והובלת הטמעת מסגרות תאימות חדשות. כמו כן, תעצב ותפעיל תוכניות ניטור תאימות רציפות תוך שימוש בבינה מלאכותית ואוטומציה, ותנהל את תוכנית ניהול הסיכונים של צד שלישי. בנוסף, תפתח ותתחזק מדיניות אבטחה ותוביל הדרכות מודעות לאבטחה ברחבי הארגון.

חובה
  • A self-starter mindset: comfortable with ambiguity, able to set priorities without heavy direction, and capable of building structure where none exists.
  • Demonstrated ability to build compliance and security programs from scratch, not just maintain inherited ones.
  • 2+ years of hands-on experience in information security and GRC
  • Deep familiarity with major frameworks and regulations - SOC 2, ISO 27001, NIST, CIS, DORA, GDPR, and related standards.
  • Practical experience with security and IT tooling across cloud environments (AWS, Azure, or GCP), application security, and infrastructure security.
יתרון

    חולץ מתיאור המשרה · מתעדכן אוטומטית

    למי זה מתאים

    התפקיד מתאים למועמדים בעלי ניסיון של שנתיים לפחות באבטחת מידע ו-GRC, עם יכולת מוכחת לבנות תוכניות תאימות ואבטחה מאפס. נדרשת היכרות מעמיקה עם מסגרות ותקנות מרכזיות כמו SOC 2, ISO 27001, NIST, CIS, DORA ו-GDPR, וכן אוריינטציה חזקה לבינה מלאכותית. התפקיד פחות מתאים למי שמחפש תפקיד תחזוקה בלבד או למי שאינו בעל סקרנות וידע עבודה בכלי AI.

    תיאור המשרה המלא

    המשרה המקורית · נשמר לעיון

    Skeletons, lasers, tattoo buses — the Torq brand grabs attention like nothing else in cybersecurity. And we're growing like crazy, backed by Series D funding, 200% employee growth, and 300% revenue growth. Fueling Torq's momentum is our game-changing AI SOC platform, backed by a team and culture that makes Torq one of Forbes' Best Startup Employers in America, and a Business Insider 'startup to bet your career on'.

    Life at Torq is all gas, no brakes. We're a team of relentless, collaborative go-getters pushing the boundaries of what's possible for security automation. Every role is an essential driver of Torq's success as the AI-native autonomous SecOps platform of choice for security teams across the Fortune 500.

    We’re looking for a driven, motivated, and ambitious GRC Specialist to join our growing Security team at Torq. Here, we’re redefining how security teams operate - not by buying more tools, but by building smarter, AI-driven programs from the ground up. As our GRC Specialist, you'll own the compliance programs that underpin trust with our customers and partners, while actively shaping how we use AI and automation to make compliance faster, more rigorous, and less manual. This isn't a checkbox role. It's a builder role for someone who sees compliance as a competitive advantage and AI as the engine to get there.

    Responsibilities

    Compliance Program Ownership

    • Own and lead Torq's security compliance programs across SOC 2, ISO 27001, C5 BSI, and ISO 42001, ensuring continuous readiness and alignment with evolving requirements.

    • Lead the scoping, planning, and implementation of new compliance frameworks as the business scales into new markets and regulatory environments.

    • Act as the primary point of contact for audits — managing evidence collection, auditor relationships, and remediation tracking end-to-end.

    AI-Driven Compliance Operations

    • Design and operate continuous compliance monitoring programs leveraging AI and automation — replacing point-in-time snapshots with real-time assurance.

    • Build internal AI-powered tooling and workflows (in partnership with the AI Transformation Lead) to automate evidence gathering, control validation, and risk signal aggregation.

    • Evaluate and adopt emerging AI compliance methodologies, including AI-specific frameworks like ISO 42001, and translate them into actionable internal programs.

    Risk & Vendor Management

    • Manage the third-party risk program (TPRM), including vendor assessments, security questionnaires, and ongoing monitoring of the vendor landscape.

    • Maintain and actively drive the risk register in close collaboration with the CISO, ensuring risks are tracked, owned, and remediated on time.

    Policy & Culture

    • Develop and maintain security policies, standards, and procedures that are practical, current, and aligned with both compliance requirements and business objectives.

    • Drive security awareness training across the organization and champion secure development practices in collaboration with engineering and product teams.

    Cross-functional Collaboration

    • Serve as a trusted partner to the CISO, Information Security Manager, HR, Legal, and AI Transformation Lead on matters of risk, compliance, and security governance.

    Requirements

    • A self-starter mindset: comfortable with ambiguity, able to set priorities without heavy direction, and capable of building structure where none exists.

    • Demonstrated ability to build compliance and security programs from scratch, not just maintain inherited ones.

    • 2+ years of hands-on experience in information security and GRC, ideally in a fast-moving SaaS or tech environment.

    • Deep familiarity with major frameworks and regulations - SOC 2, ISO 27001, NIST, CIS, DORA, GDPR, and related standards.

    • Practical experience with security and IT tooling across cloud environments (AWS, Azure, or GCP), application security, and infrastructure security.

    • Exposure to SOC (cybersecurity operations center) environments and cybersecurity incident response.

    • Strong written and verbal communication skills - able to translate technical risk into clear language for executives, auditors, and non-technical stakeholders.

    • Hands-on experience with IT and Security tools

    AI Orientation (Non-Negotiable)-

    • Genuine curiosity and working knowledge of AI tools, LLMs, and automation - you've used them, not just read about them.

    • Experience building or operating AI-assisted workflows for compliance, risk, or security operations is a strong plus.

    • Ability to think critically about AI risk, including how to govern and assess AI systems under frameworks like ISO 42001.

    • Visionary outlook: you see the 2-year horizon where AI has transformed how GRC functions and you want to be the person who builds that future at Torq.

    As an equal-opportunity employer, we are committed to a team defined and empowered by diversity. We consider qualified applicants without regard to race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

    We are waiting for you!

    We build AI for a living, and we encourage candidates to use it to prep, research, and sharpen their best work. But we're hiring humans, not chatbots. We want the real you. Use AI to tighten your resume, prep for interviews, research Torq, and outline ideas for written responses. Show up as yourself for live interviews, final assessments (the voice, logic, and reasoning need to be yours), and anywhere we're evaluating how you think — not how you prompt.

    Excited about our vision and ready to make an impact as we grow? We'd love to see what you can bring to the team.

    אודות Torq
    פרופיל החברה · בקרוב

    ביקורות עובדים · בקרובעוד משרות ב-Torq

    שאלות על המשרה

    • המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
    Torq
    פורסם לפני 25 ימים · 124 מועמדים
    בדקו את ההתאמה