תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןWe are seeking a skilled and experienced Cyber GRC Lead to join Alice (Formerly ActiveFence) CISO team. The ideal candidate will be responsible for driving the security initiatives. Key Responsibilities: • Third-Party Risk Management (TPRM) & Supply Chain Security: • Lead the end to end Operational TPRM lifecycle, assessing and continuously monitoring the security postures of vendors, SaaS platforms, AI tool providers. • Establish risk criteria for third party tools, ensuring third party AI integrations do not introduce data leakage, or intellectual property risks. • Security Awareness & Culture & Behavioral Programs: • Design and manage the enterprise wide security awareness and training program using modern platforms. • Conduct targeted phishing simulations, role based security training and specialized training among others on GenAI risks (prompt injection, shadow AI, data exposure). • Customer Due Diligence (DDQs) & Sales Enablement: • Manage and streamline the end to end customer security assessment process (DDQs, RFPs, Security Questionnaires, customer audits). • Build and maintain a centralized, automated knowledge base to expedite responses, directly removing friction from sales velocity and supporting enterprise revenue goals. • Risk Management Frameworks & Risk Advisory: • Lead ongoing security risk assessments, maintaining a dynamic Risk Register mapped to real world business impacts. • Provide continuous risk advisory services across business units, establishing risk treatment and mitigation plans that balance operational agility with guardrails. • GRC Automation & Continuous Compliance: • Architect and leverage high-level GRC automation tools to move from point in time audits to continuous control monitoring. • Drive process automation for evidence collection, vendor assessments, and policy management to reduce manual overhead across technical teams. • Compliance, Frameworks & AI Governance: • Maintain core information security certifications (ISO 27001, SOC 2 Type II, etc) • Build, operationalize, scale the organization's AI Governance Framework, referencing established benchmarks (NIST AI RMF, ISO/IEC 42001). • Lead internal and external audit readiness, acting as the primary liaison for independent auditors. • Close Collaboration with Legal, Privacy & DPO: • Partner directly with Legal and Privacy teams to operationalize global data protection standards (GDPR, CCPA, EU AI Act) align security controls with contractual commitments.
Requirements: Professional Experience: • 4+ years of hands on experience in Cyber GRC, IT audit, or security consulting within global, fast paced technology companies. • Proven track record of owning SOC 2 Type II and ISO 27001 compliance lifecycles. • Direct experience partnering with Legal and Privacy teams on GDPR compliance and privacy risk assessments. • Demonstrated track record handling customer DDQs, vendor security reviews (TPRM), and managing security awareness platforms. • Technical, Automation & AI Capabilities: • Strong technical proficiency in utilizing GRC automation platforms to automate control testing, evidence gathering, and vendor workflows. • Working knowledge of cloud security (AWS/GCP/Azure), AI/ML operational risks • Deep familiarity with core frameworks: NIST CSF, ISO 27001, NIST AI RMF, ISO 42001. • Leadership & Stakeholder Management: • Exceptional communication and negotiation skills, capable of translating complex security and compliance demands into clear business terms • A pragmatic, business first mindset focused on designing guardrails that empower teams rather than introducing operational roadblocks. • Fluent in professional English (written and verbal). Preferred Qualifications (Pluses): • Industry certifications: CISA, CRISC, CISM, CISSP, CIPP/E, or IAPP AIGP. • Experience with automated TPRM and vendor intelligence solutions • Practical scripting capabilities to custom build or tie together GRC automation workflows.
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- היברידי