Security GRC Specialist

2 months ago


Jersey City, United States MDMS Recruiting LLC Full time
Job DescriptionJob Description

***MUST HAVE EXPERIENCE WITH DFS500***

The Security GRC Specialist - Regulatory and Audit Lead is an experienced professional in Information Security Governance, Risk management and Compliance functions. The role involves performing security risk assessments and assessing compliance against cybersecurity related external (laws and regulations), internal (company policies) requirements and industry frameworks (NIST CSF, ISO 27001, FFIEC CAT) as well as working with other IT and security teams to implement security solutions, test the effectiveness of security controls, and document the compliance levels. It is a key role to develop, deploy, and manage the security GRC framework.


ESSENTIAL JOB FUNCTIONS

Cybersecurity Regulatory Lead

  • Manage the regional cyber regulatory compliance program including: assessing requirements, communicating and working with internal stakeholders to ensure required controls are in place and supporting documentation is maintained. Review controls implemented for appropriateness, effectiveness, and completeness. Assist, follow-up and report on any necessary remediation actions.
  • Act as a subject matter expert for all DFS500-related matters and ensure the bank maintains and enhances its level of compliance with DFS500 requirements
  • Assist during cyber regulatory examinations by preparing presentations, responses and associated artifacts
  • Act as the subject matter expert to develop and maintain an effective FFIEC CAT framework for the bank
  • Manage the FFIEC CAT inherent and maturity assessments
  • Develop related reports and metrics

Security GRC Framework Specialist

  • Maintain an in-depth understanding of the broad regulatory landscape impacting business and IT areas
  • Understand the impact of laws and regulations on company systems and technology
  • Map external and internal requirements against security controls in place
  • Develop and implement the components of the security GRC Framework for mapping threats, vulnerabilities, risks, assets, stakeholders, assessments, standards, policies, controls into a holistic lifecycle to achieve Assess and Test Once, Report Multiple Times
  • Actively manage the security GRC framework by:
  • Performing various security risk assessments to identify residual risks and control gaps
  • Ensuring clients, regulatory, and internal requirements are being met consistently and effectively
  • Ensuring the required and expected controls are in place and working as they should
  • Reviewing, and maintaining security policies, standards and procedures as needed
  • Recommending tooling and process improvements of the Security GRC function, including automation
  • Providing multi-level reporting to stakeholders in the company
  • Build partnerships across the organization: Audit, Legal, Compliance, Information Technology, business operations, Risk management, etc. to ensure the security GRC program is aligned with business objectives and requirements

Documentation, Reporting & Analytics

Contribute to the reporting framework that will provide regular metrics about our business and IT environment; analyze trends in security events, activities, etc. to better understand risks, and current gaps.

KNOWLEDGE AND EXPERIENCE

  • 8-10 years’ demonstrable experience in security GRC, security project management, and other security practices
  • Working knowledge of relevant cybersecurity and data privacy regulations
  • Knowledge of common security frameworks (NIST CSF, ISO 27001, COBIT, FFIEC CAT, etc.)
  • Proficient with MS Office, project management processes, and at least one GRC tool (highly preferred to have experience with RSA Archer)
  • Solid understanding of common security topics (e.g., application security, infrastructure security, vulnerability management, Identity and Access Management, data protection, cyber incident response, cloud security, etc.)
  • Requires strong analytical skills, oral and written communication skills including documentation of requirements, problem solving skills, and project/program management skills and presentation skills
  • Experience in managing risk and compliance (IT audit, IT or cyber risk management, regulatory compliance)

EDUCATION/CERTIFICATIONS

  • Degree in IT, Computer Science, Cybersecurity, or related subject required
  • Certified training in security management, risk and compliance solutions and practices
  • Ability to work towards or has achieved at least one Information Security or Risk Management Certification (Security+, CISSP, CCSP, CCSK, CISA, CISM, GSEC, CRISC, etc.)




  • Jersey City, New Jersey, United States Société Générale Full time

    Job SummaryWe are seeking an experienced Security GRC Specialist to join our team at Societe Generale. As a key member of our security team, you will be responsible for managing our regional cyber regulatory compliance program, including assessing requirements, communicating with internal stakeholders, and ensuring required controls are in place.Key...


  • Jersey City, United States MDMS Recruiting LLC Full time

    ***MUST HAVE EXPERIENCE WITH DFS500***The Security GRC Specialist Regulatory and Audit Lead is an experienced professional in Information Security Governance Risk management and Compliance functions. The role involves performing security risk assessments and assessing compliance against cybersecurity related external (laws and regulations) internal (company...


  • Jersey City, New Jersey, United States Société Générale Full time

    Job SummaryWe are seeking an experienced Security GRC Specialist - Regulatory Lead to join our team at Societe Generale. The successful candidate will be responsible for managing the regional cyber regulatory compliance program, including assessing requirements, communicating with internal stakeholders, and ensuring required controls are in place.Key...

  • GRC Specialist

    5 days ago


    Jersey City, New Jersey, United States Hamlyn Williams Full time

    About the RoleWe are seeking a highly skilled GRC Specialist to join our team at Hamlyn Williams. As a key member of our organization, you will play a critical role in ensuring the effective management of our cybersecurity governance, risk management, and compliance programs.Key ResponsibilitiesManage Cybersecurity Regulatory Compliance Program: Assess...

  • VP- GRC Specialist

    4 weeks ago


    Jersey City, United States Hamlyn Williams Full time

    GRC Specialist/ Regulatory Lead is an SME in Information Security Governance, Risk Management, and Compliance. This role focuses on conducting security risk assessments, ensuring compliance with cybersecurity laws, regulations, internal policies, and industry frameworks. You collaborate with IT and security teams to implement, test, and document security...


  • Jersey City, New Jersey, United States Diverse Lynx Full time

    Position OverviewWe are seeking a knowledgeable SAP Security Specialist to join our team at Diverse Lynx. This role is crucial for ensuring the integrity and security of our SAP systems. The ideal candidate will possess a robust background in SAP security and governance, risk, and compliance (GRC).Key ResponsibilitiesManage SAP User Provisioning...


  • Jersey City, New Jersey, United States Diverse Lynx Full time

    Diverse Lynx LLC is seeking a highly skilled SAP Security consultant to join our team. As an SAP Security consultant, you will be responsible for designing and implementing SAP Security solutions, including SAP GRC automation and SAP Role design. You will work closely with our SAP Functional and Rise teams to ensure seamless integration and coordination. The...


  • new york city, United States Tata Consultancy Services Full time

    Job Title : Architect for SAP Security Function with experience in GRC in New York, NY or Mount Laurel, NJRelevant Experience(in Yrs) 12+Technical/Functional Skills 1. Design and configure activity groups, manual profiles/authorizations and users within the systems and clients.2. Design roles for each business functionality3. Work with the business users to...


  • New York City, United States Tata Consultancy Services Full time

    Job Title :Architect for SAP Security Function with experience in GRC in New York, NY or Mount Laurel, NJRelevant Experience(in Yrs) 12+Technical/Functional Skills 1.Design and configure activity groups, manual profiles/authorizations and users within the systems and clients.2.Design roles for each business functionality3.Work with the business users to...


  • Jersey City, New Jersey, United States Arrow Security Full time

    Mobile Security Specialist - Jersey City, NJCompensation: $17.00 per hourShifts: All shifts available. Flexibility required as assignments will vary across multiple locations.Are you dedicated to maintaining safety and delivering outstanding customer service? Join our team at Arrow Security as a Mobile Security Specialist, where you will play a crucial role...


  • Jersey City, New Jersey, United States Arrow Security Full time

    Safety and Security SpecialistLocation: Jersey City, NJCompensation: $16.00 per hourSchedule: Monday-Friday, 8:00 AM - 4:00 PMQualifications: Prior Military Experience RequiredAre you dedicated to ensuring safety and delivering outstanding customer service? Join our team at Arrow Security as a Safety and Security Specialist, where you will play a crucial...


  • Jersey City, New Jersey, United States Hamlyn Williams Full time

    About the Role:The VP - Governance, Risk, and Compliance Specialist will play a critical role in developing and managing the security Governance, Risk, and Compliance (GRC) framework for Hamlyn Williams. This role focuses on conducting security risk assessments, ensuring compliance with cybersecurity laws, regulations, internal policies, and industry...


  • Salt Lake City, United States SoFi Full time

    Employee Applicant Privacy NoticeWho we are: Shape a brighter financial future with us. Together with our members, we're changing the way people think about and interact with personal finance. We're a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The...


  • Jersey City, New Jersey, United States Johnson Security Bureau, Inc. Full time

    Location: Jersey CityEmployment Type: Full TimeCompensation: $20.00 per hourExperience: Minimum of 2 years in security rolesAvailable Shifts:Shift Options: All Days 6:00 am - 2:00 pmShift Options: All Days 9:00 am - 5:00 pmShift Options: All Days 2:00 pm - 10:00 pmKey Responsibilities:As a Building Security Specialist, your duties will encompass but are not...


  • Foster City, California, United States A Society Group, Inc. Full time

    About the RoleWe are seeking a highly skilled Information Security Governance Compliance Specialist to join our team at A Society Group, Inc., a leading organization in the automotive industry. The successful candidate will be responsible for ensuring the organization's adherence to established information security governance, risk management, and compliance...


  • Jersey City, New Jersey, United States HCL Technologies Full time

    Job Overview: Position: Cybersecurity Operations Manager with Expertise in Managed Security Services Company: HCL Technologies Experience Required: 10-12 years Role Summary: The Cybersecurity Operations Manager will spearhead the delivery of Cybersecurity and Governance, Risk, and Compliance (GRC) services, utilizing our extensive global delivery...


  • Culver City, California, United States Security Industry Specialists Full time

    Position Title: Security Intelligence Specialist Division: Special Operations Security Industry Specialists, Inc. (SIS) is dedicated to delivering comprehensive security solutions to prominent corporations, international gatherings, and esteemed individuals. Our mission is to redefine the conventional perceptions of security. The SIS Security Intelligence...


  • Panama City Beach, Florida, United States Pryme Security Full time

    Pryme Security is actively seeking a dedicated Security Operations Specialist to enhance our team. The primary role of the Security Operations Specialist is to safeguard the client and designated properties from any unlawful activities or unauthorized access. The ideal candidate will possess exceptional written and verbal communication skills, outstanding...


  • Mason City, Iowa, United States Transportation Security Administration Full time

    Overview Aviation Security Specialists play a crucial role in ensuring the safety and security of passengers across various transportation platforms. They are tasked with safeguarding travelers and maintaining a secure environment in a professional and courteous manner. Their responsibilities may also encompass the protection of significant events, notable...


  • Studio City, California, United States Securitech Security Services Full time

    Join Our Team as a Retail Security SpecialistSecuritech Security Services, Inc., a prominent provider in the security sector, is currently seeking dedicated individuals for the role of Retail Security Specialist. If you possess a valid CA guard card and are looking for a reputable security firm that values its workforce, you are in the right place.Available...