Un-siloed teams. Happier customers.™
Security GRC Lead
Location
Canada
Posted
2 days ago
Salary
0
Seniority
Senior
Job Description
Security GRC Lead
Sprinklr
• Manage audit engagements (e.g. SOX, ISO 27001, C5 PCI-DSS, SOC 2, HIPAA), the audit request lists and ensure requests are being fulfilled appropriately by stakeholder management • Coordinate and collate required evidence for external and internal audit support • Managing the control and process libraries, and assisting the business in implementing internal controls • Contribute to meetings by preparing agendas, document meeting minutes, and help track the completion of follow up • Lead junior staff to ensure critical tasks are completed on time and per requirements • Lead Internal/External Audits as it relates to documenting or evidencing control management practices • Lead/participate in Risk Assessments and documenting risks within the risk register, and identifying and documenting the risk treatment • Assist the business to document, assess, and remediate any issues raised during audit examinations and risk assessments • Assist in management of Sprinklr security standards and policies • Update and maintain the GRC Confluence and share drives • Assist with management of risks, controls and requests in the GRC tool • other duties or tasks as assigned by management
Job Requirements
- A Bachelor's degree in a technical/security field or a non-technical degree with combination of governance, risk and compliance-related work experience
- At least 5-7+ years of experience in risk, compliance management or in an Information Security environment
- Knowledge of security controls frameworks such as ISO 27001/27002 and NIST 800-53
- Generally adept at picking up new technologies and experience working with a GRC tool
- Excellent interpersonal communication, teamwork and project management skills
- Strong written and verbal communication skills
- Strong sense of accountability with the ability to work independently with minimal direction and follow-up
- Demonstrated ability to perform process analysis and experience in documenting controls
- Proven analytical and troubleshooting skills
- A broad understanding of information security risk and controls
- Personal integrity, accountability, and the ability to take ownership of specific tasks and activities
- Able to foster a collaborative working relationship with multiple areas and complex business lines, globally and remotely.
Benefits
- voluntary healthcare coverage
- paid time off
- open Mentoring Program
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Account Executive, Data Security – Majors
ZscalerZscaler helps leading organizations in 180+ countries securely transform their networks and applications for a mobile and cloud-first world. Founded in 2008, th
• Serve as the primary specialist for customers, partners, and internal teams to drive revenue growth across the data security product portfolio • Partner with domain-expert solution engineers to capture customer requirements and craft compelling value propositions that close complex business deals • Own the regional quota and territory achievement by building and implementing account-based strategies to land and expand data security solutions • Collaborate synergistically with primary sales teams and leadership to ensure a unified and effective Zscaler presence in the market • Engage stakeholders across the organization, selling effectively to both C-suite executives and technical practitioners
• Monitor and triage security alerts from SIEM, EDR, and other tools; escalate and respond as needed. • Investigate security incidents, determine root cause, document findings, and develop IOCs to prevent recurrence. • Support escalations from internal employees or customers with security-related concerns. • Assist with security reviews related to infrastructure and system changes. • Build, enhance, and maintain internal security tooling and scripting repositories. • Contribute to the development of detection content, alert tuning, and automation pipelines. • Drive annual security team goals and cross-functional initiatives. • Author and maintain clear, actionable documentation and knowledge bases. • Mentor junior team members and share expertise across the organization. • Participate in a rotating on-call schedule for security operations support.
• Design and implement security solutions to enable customers to securely deploy and govern Claude Enterprise • Assess existing security, identity, data, cloud and SaaS architectures and advise on best-in-class solutions for securing enterprise AI tooling across customers in a wide range of industries • Conduct comprehensive evaluations of AI tools (e.g. Claude, Claude Enterprise), platform configurations, data access patterns, connector usage, security controls, processes and personnel to deliver informed recommendations leveraging your expertise in security engineering and AI governance • Design and implement security controls for enterprise AI platforms, including SSO, SCIM, RBAC, MFA, conditional access, admin roles, user lifecycle management, retention policies, audit logging, workspace controls, DLP, and acceptable-use enforcement • Assess and govern AI platform features such as file uploads, custom assistants, projects, GPTs, connectors, browsing, code execution, data analysis, plugins, agents, API access, and external sharing • Review and secure AI integrations with enterprise repositories and collaboration platforms, including Google Drive, SharePoint, OneDrive, Slack, Teams, GitHub, GitLab, Jira, Confluence, Salesforce, Snowflake, Databricks, and BI platforms • Manage and lead end-to-end AI Security Implementation efforts as part of a project team; including activities such as identity integration, access control design, data protection controls, AI platform configurations, connector governance, monitoring / logging and incident response workflows
Developer Intern, Data Security
1PasswordProductive businesses use 1Password to secure employees at scale.
• Be partially responsible for the underlying cryptography across our products. • Help build cryptographic libraries and implement the latest algorithms directly into our client applications with security, performance and usability in mind. • Develop proof-of-concepts and implement new industry specifications into code. • Conduct code and design reviews to ensure good cryptographic hygiene and standards across our codebase.




