UpGuard logo
UpGuard

We're on a mission to protect the world's data.

InfoSec Governance Risk and Compliance Lead

ComplianceComplianceFull TimeRemoteSeniorTeam 51-200Since 2012H1B No SponsorCompany SiteLinkedIn

Location

Australia

Posted

2 days ago

Salary

0

Seniority

Senior

Bachelor Degree4 yrs expEnglishCloudCyber SecuritySwift

Job Description

InfoSec Governance Risk and Compliance Lead

UpGuard

• Drive the development, maturity, and execution of UpGuard’s InfoSec Governance, Risk, and Compliance function, with primary ownership over technology and cybersecurity risk. • Partner closely with procurement, legal, and business stakeholders to embed security reviews into the purchasing lifecycle. Lead Third-Party Risk Management (TPRM) evaluations for new and existing vendors. • Review security exhibits, Data Processing Agreements, and security questionnaires during procurement negotiations to safeguard UpGuard and its customers. • Partner with the CISO to contribute expert analysis on broader enterprise and operational risk matters, ensuring a unified approach to risk management. • Architect and run the technology and security components of the Risk Management process. You will maintain, continually improve, and deliver executive-ready reporting on trends, vulnerabilities, and strategic insights. • Formally own the technology and security control components of UpGuard’s annual SOC 2 Type II audit cycle. Design, manage, and coordinate remediations and improvements stemming from prior cycles, incident post-mortems, and internal assessments. • Work cross-functionally with the Product team to develop public-facing trust documentation, while identifying security control gaps and improvement opportunities within the Product Development Life Cycle (PDLC). • Draft, implement, and maintain a robust framework of InfoSec policies, standards, processes, and guidelines tailored to an evolving threat landscape. • Design and implement comprehensive, company-wide security awareness and compliance training programs utilizing the MindTickle platform.

Job Requirements

  • 4+ years of dedicated experience in Information Security, IT Audit, or GRC within a technical, cloud-based landscape.
  • Deep familiarity and hands-on experience with modern technology risk management frameworks, GRC platforms, and Third-Party Risk Management (TPRM) tools.
  • Experience partnering with procurement, legal, and privacy teams across diverse geographic areas (e.g., GDPR/CCPA, anti-corruption) to review vendor contracts, technical agreements, and security exhibits.
  • A clear, collaborative communicator capable of translating complex technical risks into clear business impacts for stakeholders, customers, and vendors.
  • The ability to work independently, take swift initiative, and manage the fine details while never losing sight of long-term strategic goals.
  • A skillful issue-spotter and adaptive learner who can confidently navigate ambiguity and evaluate legal/business risk trade-offs.
  • High ethical standards, meticulous attention to detail, a team-first attitude, and a dual passion for teaching and learning.

Benefits

  • Monthly Lifestyle subsidy: Use this for financial, physical, and mental well-being
  • WFH set-up allowance: To ensure you have the right environment to work in, we will help you get set up within your first 3 months at UpGuard
  • $1500 USD annual Learning & Development allowance: To support your career development, all team members will be able to expense development opportunities against this allowance
  • Annual leave: PTO plus two additional UpGuardian leave days to give you time to recharge your batteries.
  • 18 weeks paid Parental Leave: Irrespective of parenting role
  • Personal Leave Allowance: This includes sick & carer’s leave
  • Fully remote working environment: While we have physical offices in Sydney & Hobart, we do not mandate compulsory attendance
  • Top-spec hardware: All team members will be provided with top-spec laptops for their role
  • Generative AI subsidy: UpGuard provides paid subscriptions for all team members to access generative AI tools to support their work

Related Categories

Related Job Pages

More Compliance Jobs

Kitsch logo

Director of Regulatory – Tech Transfer

Kitsch

Woman-owned accessories, beauty, lifestyle brand committed to creating high-quality products that are effortless...

Compliance2 days ago
Full TimeRemoteTeam 51-200Since 2010H1B No Sponsor

• Produce a complete supply risk map of every active SKU in Haircare, Body, and Fragrance within your first 90 days • Serve as the internal final approval authority on all artwork going to suppliers • Own all tech transfers across Haircare, Body, and Fragrance end to end • Conduct a full SKU documentation audit within your first 30 days • Build and maintain an approved formula library • Catch quality concerns at the development stage before production starts • Own regulatory and quality compliance across Target, Ulta, Walmart, and TikTok Shop • Conduct regular GMP, ISO, and REACH audits of manufacturers and testing facilities • Author and maintain the SOPs that keep the regulatory and tech transfer function running • Serve as the primary point of contact for all adverse event investigations in the Consumables portfolio • Use AI tools to accelerate regulatory research, SOP drafting, gap analysis, and documentation review.

United States
Arrow Electronics logo

Trade Compliance Engineer and Analyst

Arrow Electronics

Arrow Electronics is a Fortune 500 company that delivers a variety of products, services, and solutions to commercial and industrial users of enterprise computi

Compliance2 days ago

Ensure compliance with U.S. export and import control laws, review product documentation for classification, and process government license applications while collaborating with internal teams and external partners to resolve compliance issues.

Colorado

Role Description We are seeking a Compliance & Corporate Governance Advisor to support the Drilling Services division in Salt Lake City, UT. This role supports core compliance workflows, including: - Hotline intake - Investigations support - Policy management - Training tracking - Monitoring - Third-party due diligence The position reports directly to the General Counsel – Drilling Services and works closely with regional management, HR, Finance, and operations. The role is well suited for a detail-oriented compliance, legal, or risk professional who can: - Spot issues - Follow through on key workflows - Manage documentation carefully - Contribute across a lean legal team ESG/ESH responsibilities are separately managed but require coordinated interaction. Qualifications - Bachelor’s degree required - Advanced degree in business, law, or a related field preferred - Professional certifications such as CCEP, CCEP-I, CRCM, or similar are a plus Requirements - Minimum 5 years of experience in compliance, risk management, legal support, legal operations, corporate governance, or related operational roles - Experience in industrial services, energy, mining, manufacturing, or similarly complex environments is preferred - Working knowledge of compliance program elements, including ABC frameworks, hotline processes, investigations support, and third-party risk management - Experience in, or strong interest in, working in a corporate legal department, including governance support such as entity management, filings, board materials, or related work; public company experience is a plus - Excellent written and verbal English communication skills - Proactive, solutions-oriented mindset with sound judgment and an ability to spot issues and help resolve them - Excellent organizational skills, strong attention to detail, and ability to manage multiple projects, filings, and deadlines - Ability to work independently, learn new subject matter quickly, and contribute flexibly across a lean legal team Benefits - A strong compensation plan - Medical, vision, and dental program - Retirement program - Employee recognition rewards program (BRAVO) - Employee assistance program

United States
Full TimeRemoteTeam 1,001-5,000Since 1933H1B No Sponsor

Role Description Support all aspects of the Grievance and Appeals (G&A) compliance program for Medicare and Medicaid lines of business. Assume the primary role of interfacing with the Compliance department, Auditors, Vendors, and G&A staff for purposes of monitoring and ensuring compliant operations. Interface with the Compliance Department and Fraud, Waste and Abuse teams to evaluate and address fraudulent activities impacting the G&A Department. Conduct internal audits, support external audits, develop policies and procedures, and ensure departmental compliance. - In partnership with Compliance staff and G&A leadership, develop auditing and monitoring plans to assess compliance with all State, Federal, and internal business rules and regulations. - Serve as an inter-departmental liaison for compliance and FWA activities. - Inform all business operations and workflow decisions to ensure that programs are compliant with State, Federal, and internal business rules and regulations. - Be fully informed and ensure compliant processes are in place on all G&A business operations, including but not limited to: - Appeals and Grievance processing - OIG status - FWA programs - Helpdesk operations including call monitoring - Communication strategies - Website publications - Claims adjudication - All vendor managed programs - Maintain a current working knowledge of all applicable Medicare and Medicaid rules and regulations including assessment, impact report, and training on any new rules or regulations to all impacted departments. - Conduct frequent monitoring activities of all G&A business operations, publish results, and report out to G&A Leadership, Compliance Department, quality committees, and other PacificSource leadership teams as applicable. - Respond to all compliance-related inquiries from internal Compliance Department Staff and external Auditors in a timely, professional, and accurate manner to ensure minimal organizational and operational impact. - Work collaboratively with G&A leadership to produce and monitor department policies and procedures as applicable and ensure their regular maintenance to reflect new practices and guidance. - Provide interpretation, training, and implementation of Medicare and Medicaid regulations and communicate them appropriately with respective departments and teams. - Attend weekly meetings; review and approve external communications; and monitor operational performance reports. - Support ongoing communication efforts, maintaining compliant member, G&A, and provider communications. Keeping letters and other member communications up to date with compliance guidance and best practices. Qualifications - Minimum of two years of Grievance and Appeals related health insurance experience required. - Strong preference for experience in auditing or compliance related role. - High school diploma or equivalent required; Bachelor’s degree preferred. Requirements - Strong computer skills. - Excellent verbal and business writing skills. - Excellent public relations skills. - Good understanding of Medical Terminology required. - Ability to define and prioritize problems and manage workload without direct supervision. Benefits - Base Range: $44,982.98 - $71,972.77 - Compensation Disclaimer: The wage range provided reflects the full range for this position. The maximum amount listed represents the highest possible salary for the role and should not be interpreted as a typical starting wage. Actual compensation will be determined based on factors such as qualifications, experience, education, and internal equity. Company Description PacificSource is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to status as a protected veteran or a qualified individual with a disability, or other protected status, such as race, religion, color, sex, sexual orientation, gender identity, national origin, genetic information, or age. - PacificSource values the diversity of our community, including those we hire and serve. - We are committed to creating and fostering a work environment in which individual differences and diversity are appreciated, respected, and responded to in ways that fully develop and utilize each person’s talents and strengths.

United States
$45.0K - $72.0K / year