Director, Security Audit and GRC

2 weeks ago


San Francisco CA, United States TripActions Full time

Navan, the No. 1 Corporate Travel and Expense Management App, is looking for a Director of Security Audit and Governance, Risk, and Compliance (GRC) to join our dynamic team. This role is critical in ensuring that our innovative technology and world-class customer support are backed by the highest standards of security and compliance. Reporting to the Head of Security, this position will play a key role in safeguarding our company's information assets and ensuring adherence to regulatory requirements.What you’ll do:Strategic Leadership: Develop and execute a comprehensive security audit and GRC strategy that aligns with Navan's business goals.Security Audits: Manage and oversee all aspects of security audits, both internal and external, to ensure compliance with industry standards and regulatory requirements.Risk Management: Implement a robust risk management framework to identify, evaluate, and mitigate risks associated with IT, information security and third-party.Compliance Management: Ensure that Navan adheres to all relevant laws, regulations, and standards, such as SOC 1, SOC 2, PCI DSS, ISO 27001, NIST CSF, and GDPR.Policy Development: Craft and maintain security policies, standards, and procedures to protect company assets and data.Sales Support: Build and maintain a comprehensive program to support enterprise sales, succinctly communicating our operating model and security posture. Stakeholder Engagement: Serve as a trusted advisor to senior leadership on security and risk management issues and promote security awareness across the organization.Security Awareness: Actively promotes security awareness via training, phishing simulations, newsletters. Knowledge base and more. Security Governance: Develop metrics to track the effectiveness and maturity of the security program. Identify areas for improvement and implement changes for ongoing optimization.What we’re looking for:Experience: At least 10 years in information security with 5+ years in a leadership role managing security audit and GRC functions.Education: Bachelor’s degree in Information Technology, Cybersecurity, or related field; advanced degree preferred.Certifications: Professional certifications such as CISSP, CISM, CRISC, or equivalent are highly desirable.Skills: Exceptional leadership, communication, analytical, and technical skills, with a deep understanding of IT infrastructure and cloud security principles.The posted pay range represents the anticipated low and high end of the compensation for this position and is subject to change based on business need. To determine a successful candidate’s starting pay, we carefully consider a variety of factors, including primary work location, an evaluation of the candidate’s skills and experience, market demands, and internal parity.For roles with on-target-earnings (OTE), the pay range includes both base salary and target incentive compensation. Target incentive compensation for some roles may include a ramping draw period. Compensation is higher for those who exceed targets. Candidates may receive more information from the recruiter.Pay Range$187,500—$322,000 USD



  • San Jose, United States Amadeus Full time

    Manager, Information Security GRC page is loaded Manager, Information Security GRC Apply locations San Jose time type Full time posted on Posted Yesterday job requisition id R17312 Job Title Manager, Information Security GRC About the Business: The Hospitality CISO Office consists of three teams of security experts: SEC-HOS-GRC (Governance, Risk and...


  • San Jose, United States Amiseq Inc. Full time

    Senior Security Governance, Risk, Compliance (GRC) Analyst San Jose, CA - Hybrid role 6 Months Contract Reporting to the Director Information Security, Governance, Risk, and Compliance, the Senior GRC Analyst will contribute to the development and operational execution of the program, including risk management and compliance with standards and regulations...


  • San Diego, United States Amiseq Inc. Full time

    Senior Security Governance, Risk, Compliance (GRC) AnalystSan Jose, CA - Hybrid role6 Months Contract Is this the role you are looking for If so read on for more details, and make sure to apply today. Reporting to the Director Information Security, Governance, Risk, and Compliance, theSenior GRC Analyst will contribute to the development and operational...


  • San Jose, United States Amiseq Inc. Full time

    Senior Security Governance, Risk, Compliance (GRC) AnalystSan Jose, CA - Hybrid role6 Months Contract Reporting to the Director Information Security, Governance, Risk, and Compliance, theSenior GRC Analyst will contribute to the development and operational execution of theprogram, including risk management and compliance with standards and regulations suchas...


  • San Diego, United States Amiseq Inc. Full time

    Senior Security Governance, Risk, Compliance (GRC) Analyst San Jose, CA - Hybrid role 6 Months Contract Is this the role you are looking for If so read on for more details, and make sure to apply today. Reporting to the Director Information Security, Governance, Risk, and Compliance, the Senior GRC Analyst will contribute to the development and...


  • San Jose, United States AMISEQ Full time

    Senior Security Governance, Risk, Compliance (GRC) AnalystSan Jose, CA - Hybrid role6 Months Contract Reporting to the Director Information Security, Governance, Risk, and Compliance, theSenior GRC Analyst will contribute to the development and operational execution of theprogram, including risk management and compliance with standards and regulations suchas...


  • San Jose, United States Amiseq Inc. Full time

    Senior Security Governance, Risk, Compliance (GRC) Analyst San Jose, CA - Hybrid role 6 Months Contract Reporting to the Director Information Security, Governance, Risk, and Compliance, the Senior GRC Analyst will contribute to the development and operational execution of the program, including risk management and compliance with standards and regulations...


  • San Jose, United States AMISEQ Full time

    Senior Security Governance, Risk, Compliance (GRC) AnalystSan Jose, CA - Hybrid role6 Months Contract Reporting to the Director Information Security, Governance, Risk, and Compliance, theSenior GRC Analyst will contribute to the development and operational execution of theprogram, including risk management and compliance with standards and regulations suchas...


  • San Antonio, United States H-E-B Full time

    Responsibilities H-E-B is a leading innovator in technology, and recently we've been investing in our customers' digital experience. Our Digital Technology Partners collaborate to design, construct, implement, and support technology solutions, using the best available technologies to deliver modern engagement, reliability, and scalability to meet customer...


  • San Antonio, United States H-E-B Full time

    Responsibilities H-E-B is a leading innovator in technology, and recently we've been investing in our customers' digital experience. Our Digital Technology Partners collaborate to design, construct, implement, and support technology solutions, using the best available technologies to deliver modern engagement, reliability, and scalability to meet customer...


  • San Antonio, United States H-E-B Full time

    Responsibilities: H-E-B is a leading innovator in technology, and recently weve been investing in our customers digital experience. Our Digital Technology Partners collaborate to design, construct, implement, and support technology solutions, using the best available technologies to deliver modern engagement, reliability, and scalability to meet customer...

  • Director of Audit

    4 weeks ago


    San Diego, United States RSI Security Full time

    Job DescriptionJob DescriptionThe starting salary range is based on your experience, education, and skills.RSI Security is a small organization where collaboration is not only encouraged, but expected. We value relationships within our team and are intentional to build and maintain a strong team camaraderie through virtual happy hours, daily morning meetings...

  • Director of Audit

    4 weeks ago


    San Diego, United States RSI Security Full time

    The starting salary range is based on your experience, education, and skills. RSI Security is a small organization where collaboration is not only encouraged, but expected. We value relationships within our team and are intentional to build and maintain a strong team camaraderie through virtual happy hours, daily morning meetings to help us start off on the...

  • Director of Audit

    3 days ago


    San Diego, United States RSI Security Full time

    Job DescriptionJob DescriptionThe starting salary range is based on your experience, education, and skills.RSI Security is a small organization where collaboration is not only encouraged, but expected. We value relationships within our team and are intentional to build and maintain a strong team camaraderie through virtual happy hours, daily morning meetings...


  • San Jose, United States eTeam Full time

    Skills & Experience: Establish/understand client control objectives Align design to industry standards of COSO/COBIT/SOX/GDPR/NIST/ISO27001 security frameworks Survey, assess and measure enterprise risk related to Oracle Cloud ERP transactions, operations Develop governance and control within the greater enterprise risk infrastructure Write Policies ...


  • San Francisco, CA, United States OpenAI Full time

    About the TeamGovernance, Risk, and Compliance (GRC) is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity.  The GRC team provides security assurances and builds compliance for OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work,...


  • San Francisco, United States Transportation Security Administration Full time

    Summary Securing Travel, Protecting People - At the Transportation Security Administration, we serve in a high-stakes environment to safeguard the American way of life. In cities across the country, we secure airports, seaports, railroads, highways, and public transit systems, thus protecting our transportation infrastructure and ensuring freedom of...

  • SAP Security Admin

    1 week ago


    San Jose, United States eTeam Full time

    Role: SAP Security Admin Location: san Jose, C (2-3 days a week in office) Description s an SAP Security Admin, you will research and design solutions to keep pace with an ever-expanding SAP landscape, often providing expertise to address more complicated requirements to meet S/4HANA rollout. Propose improvements, both process and technical, to...

  • SAP Security Admin

    3 days ago


    San Jose, United States eTeam Full time

    Role: SAP Security Admin Location: san Jose, C (2-3 days a week in office) Description s an SAP Security Admin, you will research and design solutions to keep pace with an ever-expanding SAP landscape, often providing expertise to address more complicated requirements to meet S/4HANA rollout. Propose improvements, both process and technical, to...


  • San Francisco, United States Diverse Lynx Full time

    Relevant Experience(in Yrs) 6-12 years Must Have Technical/Functional Skills • Minimum of 7+ years of experience implementing and delivering - ECC SAP Security Solutions. • Strong technical knowledge of SAP Security architecture and role-based authorization models. • Must have strong demonstrated expertise of SAP Security in SAP ECC, SRM, GRC,...