Job Closed

This listing is no longer active.

Echo Global Logistics logo
Echo Global Logistics

Transportation Simplified

Cybersecurity GRC Program Lead

Security EngineerSecurity EngineerFull TimeRemoteLeadTeam 1,001-5,000Since 2005H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

23 days ago

Salary

$112.5K - $163.6K / year

Seniority

Lead

Job Description

Cybersecurity GRC Program Lead

Echo Global Logistics

Role Description Echo is seeking a Cybersecurity GRC Program Lead to build the operating system for security governance, risk, controls, evidence, and exceptions across the enterprise. This is a hands-on leadership role for someone who can select and drive adoption of a primary cybersecurity framework, build the control ownership model, build & improve evidence operations, accelerate questionnaire throughput, and create practical governance mechanisms that work with real engineering and business teams. This role is not limited to policy writing or audit coordination. It is intended to make security governance real and measurable across the enterprise by building practical operating mechanisms around risk, controls, evidence, exceptions, and stakeholder accountability. In the staffing plan, this role is explicitly intended to select and operationalize the primary framework, likely starting with NIST CSF 2.0 while mapping outward to ISO 27001 and other requirements for customer, audit, and international needs. What you will do - Lead selection, adoption, and operationalization of Echo’s primary cybersecurity framework and related standards structure, with NIST CSF 2.0 as the likely management layer. - Build and maintain a control ownership model across Technology, Engineering, Platform, Network, EUC, Asset, Data, Integrations, and Security. - Translate existing policies into measurable operating practices, control expectations, evidence requirements, review cadences, and exception workflows. - Partner with security architecture, engineering, and operations teams to ensure that governance expectations are practical, technically grounded, and enforceable. - Drive enterprise risk and control assessments, including facilitating discussions on control design, effectiveness, and remediation priorities. - Build an evidence library structure while defining repeatable collection, review, reuse, and freshness cadences. - Improve security questionnaire workflows through standardized responses, evidence reuse, service-level expectations, and clearer ownership. - Coordinate third-party security intake and help define tiering, minimum security requirements, documentation expectations, and escalation paths. - Partner with Internal Audit and business stakeholders on readiness efforts, compliance reviews, and operational audit support. - Track policy exceptions, control gaps, remediation commitments, and overdue actions through closure, including clear owners and time bounds. - Provide security governance input on supplier security requirements, contractual obligations, and ongoing review expectations. - Produce reporting for leadership on framework maturity, control ownership, policy currency, evidence readiness, exception status, and risk trends. - Lead the evolution to and support of continuous compliance capabilities to improve control visibility, evidence freshness, and audit readiness. - Manage and evolve the organization’s trust center, including published security documentation, customer-facing assurance materials, and the processes that keep content current and supportable. What success looks like In the first 60 to 90 days, this role is expected to produce a framework decision package, define the control ownership model, stand up an evidence library structure, improve questionnaire operations, and establish practical workflows for exceptions and third-party intake. Over 12 months, success means framework adoption becomes measurable, control ownership is visible, evidence is reusable, customer and audit due diligence become less reactive, and policy exceptions and control gaps are actively managed. Qualifications - 7+ years in cybersecurity GRC, security risk, audit readiness, compliance operations, or related functions, with clear experience building or maturing governance operating models. - Strong experience operationalizing NIST CSF and translating controls across frameworks such as ISO 27001, SOX, SOC 2, or similar frameworks. - Experience building or maturing security governance programs in complex enterprise environments with multiple technical stakeholders. - Experience with risk assessments, control design reviews, exception management, and remediation tracking. - Strong understanding of third-party risk, supplier security reviews, security questionnaires, and governance workflows that scale beyond one-off reviews. - Experience partnering with technical teams to influence architecture, engineering, and operations outcomes in a practical, technically credible way. - Ability to turn policy and framework language into concrete operating practices, ownership expectations, and measurable evidence. - Strong writing, stakeholder management, and executive communication skills. Preferred qualifications - Experience supporting SOC 2, ISO 27001, CTPAT, SOX or similar audit/readiness efforts. - Experience with evidence management, control testing, internal audit coordination, or related assurance processes. - Experience with continuous compliance platforms, including evidence automation, control monitoring, and audit readiness workflows. - Experience managing a trust center or similar customer assurance portal and keeping security documentation current and reusable. - Familiarity with enterprise technology environments spanning cloud, identity, endpoint, network, and application security domains. Benefits - For more information about our benefit offerings, please visit our careers page at https://www.echo.com/company/careers . Compensation $112,498.00-163,571.00 per year. This role is eligible for a bonus that is based on a combination of personal and business performance.

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 51-200H1B Sponsor

• Formulating and executing service delivery strategies aligned with quality standards. • Working with clients to understand requirements and planning technical activities. • Leading project’s technical team within the scope of the engagement. • Documenting and presenting product security risks in both technical and business language. • Conducting technical QA and presenting deliverables to technical and business audiences. • Building and developing relationships with cross-client teams and partners. • Ensuring client satisfaction and business growth by communicating lessons learned.

Greece
Glean logo

Cloud Security Engineer

Glean

Search across all your company's apps to find exactly what you need and discover the things you should know.

Full TimeRemoteTeam 11-50H1B Sponsor

• Collaborate with cross-functional teams to design and architect secure cloud infrastructure solutions on AWS and Azure • Identify potential security vulnerabilities and gaps in existing infrastructure and propose remediation plans • Implement cloud-native security technologies and best practices to address identified gaps • Analyze security logs and metrics to proactively detect and respond to security incidents • Develop and deploy security controls, such as identity and access management (IAM), network security policies, and encryption mechanisms • Leverage software engineering skills to create security-specific features, particularly in the areas of authentication, authorization, and rate limiting • Create documentation and train and guide team members and other stakeholders on security best practices

United States
$153K - $238K / year
Job Closed
Glean logo

Software Engineer, Platform Security

Glean

Search across all your company's apps to find exactly what you need and discover the things you should know.

Full TimeRemoteTeam 11-50H1B Sponsor

• Design, develop, and maintain secure software for core platform functionalities • Collaborate with cross-functional teams (engineering, product) to integrate security best practices throughout the development lifecycle • Stay up-to-date on the latest security threats, vulnerabilities, and mitigation strategies • Conduct security code reviews and identify potential security risks in existing codebases • Develop and implement automated security testing procedures • Respond to security incidents and participate in incident response procedures • Continuously improve the platform's security posture by identifying and implementing security enhancements • Document security processes, procedures, and best practices

United States
$153K - $238K / year
Job Closed
Zscaler logo

Security Architect

Zscaler

Zscaler helps leading organizations in 180+ countries securely transform their networks and applications for a mobile and cloud-first world. Founded in 2008, the company operates o

Full TimeRemoteTeam 8,697Since 2007

• Build secure agent runtimes, libraries, and reference implementations while implementing core agent patterns like planner/executor, tool routing, and RAG boundaries • Build and secure MCP servers, clients, tool registries, and connector patterns with robust authentication, authorization, and audit logging • Enforce secure-by-default controls including schema validation, tool allowlists, redaction, and policy checks • Threat model and test agent workflows for prompt injection and data exfiltration to build repeatable security evaluations

California
$182K - $260K / year