Together, we create life-changing wishes for children with critical illnesses.
Lead Manager, Security Governance, Risk & Compliance
Location
United States
Posted
40 days ago
Salary
$76.3K - $92K / year
Seniority
Senior
Job Description
Lead Manager, Security Governance, Risk & Compliance
Make-A-Wish America
• Assist in the development, implementation, and maintenance of GRC frameworks and managing third-party risk. • Contribute to the assessment and mitigation of organizational risks. • Maintain internal policies, standards and security baselines, oriented toward compliance and regulatory standards - as well as, enforcement of secure practices. • Manage risk acceptance and policy exception processes, ingesting risks and creating tracking, reporting and accountability mechanisms. • Participate in audits of security controls and processes. • Assist with the creation and maintenance of documentation related to GRC activities, TPRM, Business Continuity Planning (BCP), Business Impact Analysis (BIA) and Disaster Recovery. • Assist in the identification of control gaps. • Contribute to the development of remediation plans. • Conduct due diligence on potential third-party vendors to evaluate their security posture, financial stability, and compliance with relevant regulations. • Assist in monitoring compliance activities. • Collaborate with various departments to integrate TPRM into vendor management processes. • Perform vendor and product risk assessments, to align vendors and products with applicable standards, policies and security baselines. • Create and maintain vendor questionnaire and Data Protection Agreements (DPA). • Vendor Responsibility Agreement, covering performance standards, security obligations, adherence to the Change Management process, training, communications, and documentation. • Assist Legal with vendor reviews and responses. • Conduct audits of third-party security controls, processes and vendor performance compliance and address and risks that arise. • Aid in the development of risk training and awareness programs. • Maintain GRC monitoring applications. • Performs other related job duties, as assigned.
Job Requirements
- Bachelor’s degree in Computer Science or related technology field or equivalent experience required.
- 5+ years of total experience with 2+ years of hands-on experience designing, building, and supporting enterprise GRC and TPRM solutions.
- Understanding of GRC concepts and frameworks (e.g., ISO 27001, NIST, Cybersecurity Framework (CSF), SOC, GDPR)
- Experience: IT Compliance, IT Audit, IT Security, Cloud Security, PCI, HITRUST, HIPPA, GRC, Risk management, Risk analysis
- Proficiency in Microsoft Office Suite (Word, Excel, PowerPoint).
- Relevant and Current Certifications Preferred: e.g., Certified in Governance, Risk and Compliance (CGRC), Certified in Risk and Information Systems Control (CRISC), Certified Information Systems Auditor (CISA), GRC Professional (GRCP), etc.
- Knowledge and experience with OneTrust Tools is preferred.
Benefits
- Comprehensive benefit package, effective day 1: Medical, Vision*, Dental*, Wellness
- Competitive compensation with annual incentive potential
- Health Savings Account and Flexible Spending Account Options
- Health Reimbursement Account fully funded by Make-A-Wish America
- Short Term Disability*, Long Term Disability* and Life Insurance
- Additional Insurance Plans: Accident, Critical Illness, Hospital Indemnity, Pet Insurance through Figo
- 401(k) Retirement Savings Plan with 5% match after one year of service
- Eligibility for student loan forgiveness through the Public Service Loan Forgiveness Program
- The organization will send a laptop, 24” monitor, and a docking station/adaptor to new hires
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Role Description The IT/ICT/Building Security Systems Designer will provide a wide range of consulting and design services related to information technologies, structured cabling, and building security. Projects primarily involve design of IT/ICT/Security systems and infrastructure for new buildings or major renovations to existing buildings. This role involves working on multiple concurrent projects, ensuring efficiency, accuracy, and top-quality work for our clients. This is a Work From Home position, and we are open to major markets beyond those listed. Responsibilities - Serve as a key contributor within a project design team, bringing a forward-thinking perspective on technology. - Design customized IT solutions, including: - Entrance Facilities - Telecomm Rooms - Pathways and other infrastructure - Wired/wireless and copper/fiber Structured Cabling Systems to support voice/data/video applications - Outside Plant - Distributed Antenna Systems - Data Center technologies - Other leading-edge IT solutions - Design customized Building Security solutions, including: - Video surveillance systems - Access control - Intrusion detection - Emergency telephones - Other innovative security technologies - Advise clients on Crime Prevention Through Environmental Design (CPTED). - Assist with business development activities as requested. - Develop and direct the documentation of high-quality infrastructure construction drawings, details, cost analysis, and specifications, often using AutoCAD, Revit, or PDF mark-ups with BlueBeam, and directing CAD staff to document the project in Revit. - Collaborate with MEP and architectural team members, guiding clients through the technology selection process. - Review submittals and shop drawings, coordinating with architects, contractors, engineers, and consultants. - Perform site walk-throughs to ensure adherence to standards and procedures. - Stay abreast of emerging technologies, products/services, guidelines, and standards, and their applicability to potential projects. - Ensure all work is completed on time, within budget, and consistently meets NV5’s high standards of quality. Qualifications - Minimum of five years of consulting experience in the design and specification of telecommunications systems, IT spaces, security systems, and cable plant projects for new buildings or major renovations to existing buildings. - In-depth knowledge of services, hardware, infrastructure, and systems architecture for IT. - CPTED experience is desired but not required. - Excellent attention to detail and outstanding communication skills, both oral and written. - Ability to meet deadlines and honor commitments. - Values that include integrity, accountability, and a desire to have fun while delivering Best-in-Class services to clients. - Works well as an individual contributor or as a collaborative team member. - Maintains a professional and positive attitude in a fast-paced and occasionally high-pressure environment. - High proficiency in BlueBeam and Microsoft Office. - General proficiency in AutoCAD and Revit. - BICSI Certification (active RCDD or test-ready; ITS Installer-1, or ITS Installer-2; additional certifications including OSP, WD); or ASIS certification is desired but not required. - Bachelor’s degree in a technical field is desired; equivalent industry experience will be considered. - Pluses: PE or additional industry certifications; experience with design of network electronic systems design; project experience within higher education or healthcare; strategic technology master planning; experience in business development for professional services. Requirements - All candidates must be driven to satisfy the needs of end users and have the ability to deliver high caliber results in a timely manner while operating without direct supervision. - Some overnight travel may be required. - On occasion, it may be necessary to participate in off-hours acoustic testing, as needed to support our design services. Benefits - NV5 offers a competitive compensation and benefits package including medical, dental, life insurance, PTO, 401(k) and professional development/advancement opportunities.
• Collaborate with a team of peers to research and propose solutions to a current business challenge • Work side-by-side with GDIT professionals delivering work for clients • Participate in a mentoring circle led by an early career champion • Interact with GDIT leaders and participate in professional development • Ensure the confidentiality, integrity, and availability of all data and systems across GDIT or client organizations • Work with analysts to understand business processes and promote data integrity
Security Engineer
Prime TherapeuticsEstablished in 1988, Prime Therapeutics helps people get the medicine they need to manage their health. This company manages pharmacy coverage for patients thro
• Supporting, implementing, and operating privileged access management (PAM) controls • Managing CyberArk PAM technologies • Conducting root-cause analysis of PAM failures • Monitoring privileged access activity and alerts • Producing audit evidence, compliance artifacts, and activity reports
Principal Enterprise Security Architect
Fifth Third BankFifth Third Bank was founded in 1858 and has spent over 150 years providing customers with quality financial products and services. Headquartered in Cincinnati, Ohio, Fifth Third B
• Responsible for the design and governance of information systems that support the Bank’s enterprise architecture • Analyzes and understands client and user needs • Evaluates technology and associated operational processes and recommends designs that will enhance performance, efficiency, and reliability • Designs and develops IT technical infrastructure, such as hardware, software, network resources, security, and services • Provides detailed requirements of design and ensures security and policy compliance requirements • Collaborate with IT leadership on technical assignments, issues, and problems • Serve as a technology and information security subject matter expert on projects • Participate in conducting research on new technology, threats, and remediation techniques • Assist in conducting risk assessments to evaluate the effectiveness of existing controls and determine the impact of proposed changes to business processes




