Clorox is seeking a highly skilled Cybersecurity Governance, Risk & Compliance (GRC) Lead to support and improve the company's cybersecurity program, focusing on driving improvements in cyber risk management related to sensitive data, systems, third-party vendors, and cloud environments.
Requirements
- 6 plus years of using risk assessment methods and procedures
- 6 plus years of tracking, monitoring, and reporting risk
- 6 plus years of governance risk & compliance experience
- Cybersecurity risk management function including third party cyber risk
- Cybersecurity controls management
- Controls testing and automation
- Governance risk and compliance management
- Experience with Cybersecurity Risk Frameworks (NIST CSF/RMF, ISO 27001/27002, SOC (1,2,3), and Global Privacy regulations (e.g., CCRP, GDPR etc)
- Experience with AI/ML risk management frameworks (e.g., NIST AI RMF, ISO/IEC 42001).
- Understanding of AI-specific threat vectors (model poisoning, prompt injection, data leakage via LLMs).
- Familiarity with evaluating AI vendors for responsible AI, privacy, and security posture.
- Experience in drafting security policies and standards
- Experience in using/supporting ServiceNow Integrated Risk Management module (or related GRC platform
- Cyber risk certifications (CISA, CISM, CRISC, CISSP) are a plus
Benefits
- Comprehensive, competitive benefits
- Robust health plans
- Market-leading 401(k) program with a company match
- Flexible time off benefits
- Inclusive fertility/adoption benefits
- Eligibility for participation in Clorox’s incentive plans