We're looking for a highly skilled Cybersecurity Governance, Risk, and Compliance Engineer to oversee the technical execution of GRC initiatives, collaborating with cross-functional teams to drive resilience, risk reduction, and audit readiness across the organization.
Requirements
- Collaborate with R&D and DevOps teams to integrate security into development and deployment processes.
- Perform technical risk assessments, vulnerability trend analysis, and threat modeling to ensure risk registers reflect the true security posture.
- Lead security awareness and social-engineering simulations, correlating campaign results with real technical findings (phishing, MFA bypass, insider threat trends).
- Initiate and coordinate offensive security activities including penetration testing, red teaming, and vulnerability assessments to proactively identify and mitigate risks.
- Support incident response readiness by integrating lessons learned into policy, control design, and awareness materials.
- Leverage AI to automate GRC reporting, surface risk insights, and maintain intelligent dashboards integrated with platforms like ServiceNow, Jira, and internal data sources.
- Partner with Security Engineering and IT teams to ensure consistent endpoint hardening, patch management, and configuration compliance.
- Coordinate DR exercises and tabletop simulations, track findings, and oversee remediation to strengthen resilience.
- Prepare for and support internal and external audits, including SOC 2, ISO 27001, NYDFS, and customer due-diligence requests.
Benefits
- Generous Paid Time Off
- 401k Matching
- Tuition Reimbursement