ABOUT THE ROLE:
The role oversees the business’ security requirements and obligations mandated by standards and regulations such as the GrammLeach-Bliley Act (GLBA), Sarbanes-Oxley Act (SOX), General Data Protection Regulation (GDPR), Health Information Portability and Accountability Act (HIPAA) and Payment Card Industry Data Security Standard (PCI DSS).
The position is responsible for supporting the security direction of the business and elevating the company’s security posture. The GRC Program Specialist is expected to support the security strategy of the business with new and existing information system capabilities. Consequently, the position requires both an understanding of legacy systems, as well as innovative technologies and requirements. The GRC role is also responsible for the planning and design of policies and maintenance.
RESPONSIBILITIES:
- Assist in periodic re-validation of our Top Risks and drive improvements for risk reduction.
- Assist with the implementation and operation of Governance Risk and Compliance (GRC) tooling to further improve and automate our GRC processes and policies.
- Maintain oversight in a GRC-related platform.
- Identify strengths and weaknesses in the security program as they relate to privacy, security, business resiliency and compliance frameworks.
- Document, formulate and enforce areas of security improvement that balance risk with business operations and do not diminish efficiencies or innovation.
- Maintain strong oversight of third parties, vendors, and business partners to safeguard against undue risk presented by external entities. Escalating to security management and business unit leads when points of weakness are discovered.
- Analyze findings, and document, recommend and report program gaps to security leadership.
- Monitor current and proposed security changes impacting regulatory, privacy and security industry best practice guidance. Apply GRC expertise across key lines of business, including products, practices, and procedures.
- Define qualitative and quantitative metrics to assess the success of the security program and provide regular reports to security and business leadership.
- Ensure security and technology teams maintain up-to-date configuration documentation for systems and processes. Maintain rigorous oversight of security systems and security configuration administration to reduce risk to enterprise systems and accounts.
- Function as a key participant in incident response to track occurrence and resolution, with strict documentation and reporting.
- Help support various parts of the company to adopt a common risk and control framework.
- Assist with all ongoing compliance activities related to the implementation, maintenance, monitoring, and continuous improvement of the Information Security Management System (ISMS).
- Evaluate the effectiveness of information security controls and performance by developing, monitoring, gathering, and analyzing information security and compliance metrics for management.
- Advise and collaborate with SMEs, including Audit & Compliance teams, to ensure adequate security controls are in place to manage risk and are aligned with leading best practices.
- Perform security policy and standard gap analysis, propose and draft documents and changes.
REQUIREMENTS:
- Bachelor's degree in Information Technology, Computer Science/Engineering or its equivalent.
- 5+ years of relevant industry experience working with Agile methodology, JIRA, and GRC tools.
- Familiar with security compliance frameworks and requirements, e.g., SOC 1/2, PCI, ISO27001, NIST CSF, and others.
- Experience working with, Cloud technologies/environments, AWS or other related cloud experience is required.
- Strong knowledge of and experience in security risk management lifecycle.
- Experience in third party risk assessment and third-party risk continuous monitoring.
- Strong security and compliance domain knowledge.
- Effective communication, interpersonal and leadership skills to work with both engineering and other non-technical stakeholders.
- Amenable working in US Time zone (PST).
Pay: Php250,000.00 - Php300,000.00 per month
Benefits:
- Additional leave
- Company Christmas gift
- Company events
- Opportunities for promotion
- Pay raise
- Work from home
Application Question(s):
- What GRC Tools have you used? Kindly enumerate.
- What Security Compliance Frameworks do you have experience with?
- What Cloud Technologies have you used?
- Which of the following regulations have you worked with: GrammarLeach-Billy Act (GLBA), Sarbanes-Oxley Act (SOX), General Data Protection Regulation (GDPR), Health Information-Portability And Accountability Act (HIPAA) and Payment Card Industry Data Security Standard (PCI DSS)? Kindly enumerate.
- Are you amenable working un US Time zone (PST)?
- How soon can you start?
Experience:
- Agile Methodologies: 5 years (Preferred)
- Jira: 5 years (Preferred)
- GRC Tools: 4 years (Preferred)
- Security Compliance Frameworks: 5 years (Preferred)
- Cloud Technologies: 5 years (Preferred)
Work Location: Remote