דלג לתוכן הראשי

Cyber GRC Lead

Alice (Formerly ActiveFence)רמת גן, מחוז תל אביב, ישראללא צויןFull-timeדרגה: לא צוין

פורסם אתמול · 50 מועמדים

שכר לא צוין במשרה זו

שמירה, הגשה או בדיקת התאמה. פתיחת חשבון חינם לוקחת כמה שניות.

תובנת Willbi
חובה
  • 4+ years of hands-on experience in Cyber GRC, IT audit, or security consulting within global, fast-paced technology companies
  • Proven track record of owning SOC 2 Type II and ISO 27001 compliance lifecycles
  • Experience partnering with Legal and Privacy teams on GDPR compliance and privacy risk assessments
  • Demonstrated track record handling customer DDQs, vendor security reviews (TPRM), and managing security awareness platforms
  • Strong technical proficiency in utilizing GRC automation platforms for automated control testing, evidence gathering, and vendor workflows
יתרון
  • Industry certifications: CISA, CRISC, CISM, CISSP, CIPP/E, or IAPP AIGP
  • Experience with automated TPRM and vendor intelligence solutions
  • Practical scripting capabilities to custom build or tie together GRC automation workflows

חולץ מתיאור המשרה · מתעדכן אוטומטית

תיאור המשרה המלא

המשרה המקורית · נשמר לעיון

We are seeking a skilled and experienced Cyber GRC Lead to join Alice (Formerly ActiveFence) CISO team. The ideal candidate will be responsible for driving the security initiatives.

Key Responsibilities:

• Third-Party Risk Management (TPRM) & Supply Chain Security:

• Lead the end to end Operational TPRM lifecycle, assessing and continuously monitoring the security postures of vendors, SaaS platforms, AI tool providers.

• Establish risk criteria for third party tools, ensuring third party AI integrations do not introduce data leakage, or intellectual property risks.

• Security Awareness & Culture & Behavioral Programs:

• Design and manage the enterprise wide security awareness and training program using modern platforms.

• Conduct targeted phishing simulations, role based security training and specialized training among others on GenAI risks (prompt injection, shadow AI, data exposure).

• Customer Due Diligence (DDQs) & Sales Enablement:

• Manage and streamline the end to end customer security assessment process (DDQs, RFPs, Security Questionnaires, customer audits).

• Build and maintain a centralized, automated knowledge base to expedite responses, directly removing friction from sales velocity and supporting enterprise revenue goals.

• Risk Management Frameworks & Risk Advisory:

• Lead ongoing security risk assessments, maintaining a dynamic Risk Register mapped to real world business impacts.

• Provide continuous risk advisory services across business units, establishing risk treatment and mitigation plans that balance operational agility with guardrails.

• GRC Automation & Continuous Compliance:

• Architect and leverage high-level GRC automation tools to move from point in time audits to continuous control monitoring.

• Drive process automation for evidence collection, vendor assessments, and policy management to reduce manual overhead across technical teams.

• Compliance, Frameworks & AI Governance:

• Maintain core information security certifications (ISO 27001, SOC 2 Type II, etc)

• Build, operationalize, scale the organization's AI Governance Framework, referencing established benchmarks (NIST AI RMF, ISO/IEC 42001).

• Lead internal and external audit readiness, acting as the primary liaison for independent auditors.

• Close Collaboration with Legal, Privacy & DPO:

• Partner directly with Legal and Privacy teams to operationalize global data protection standards (GDPR, CCPA, EU AI Act) align security controls with contractual commitments.

Professional Experience:

• 4+ years of hands on experience in Cyber GRC, IT audit, or security consulting within global, fast paced technology companies.

• Proven track record of owning SOC 2 Type II and ISO 27001 compliance lifecycles.

• Direct experience partnering with Legal and Privacy teams on GDPR compliance and privacy risk assessments.

• Demonstrated track record handling customer DDQs, vendor security reviews (TPRM), and managing security awareness platforms.

• Technical, Automation & AI Capabilities:

• Strong technical proficiency in utilizing GRC automation platforms to automate control testing, evidence gathering, and vendor workflows.

• Working knowledge of cloud security (AWS/GCP/Azure), AI/ML operational risks

• Deep familiarity with core frameworks: NIST CSF, ISO 27001, NIST AI RMF, ISO 42001.

• Leadership & Stakeholder Management:

• Exceptional communication and negotiation skills, capable of translating complex security and compliance demands into clear business terms

• A pragmatic, business first mindset focused on designing guardrails that empower teams rather than introducing operational roadblocks.

• Fluent in professional English (written and verbal).

Preferred Qualifications (Pluses):

• Industry certifications: CISA, CRISC, CISM, CISSP, CIPP/E, or IAPP AIGP.

• Experience with automated TPRM and vendor intelligence solutions

• Practical scripting capabilities to custom build or tie together GRC automation workflows.

Alice is a trust, safety, and security company built for the AI era. We safeguard the communicative technologies people use to create, collaborate, and interact—whether with each other or with machines.

In a world where AI has fundamentally changed the nature of risk, Alice provides end-to-end coverage across the entire AI lifecycle. We support frontier model labs, enterprises, and UGC platforms with a comprehensive suite of solutions: from model hardening evaluations and pre-deployment red-teaming to runtime guardrails and ongoing drift detection.

אודות Alice (Formerly ActiveFence)
פרופיל החברה · בקרוב

ביקורות עובדים · בקרובעוד משרות ב-Alice (Formerly ActiveFence)

שאלות על המשרה

  • המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
דומות וקשורות
Alice (Formerly ActiveFence)
פורסם אתמול · 50 מועמדים
בדקו את ההתאמה