





Niche GRC skillset but metro location and mid-seniority increase applicant density slightly.
Role requires domain-specific compliance, audits, and frameworks, making cross-industry transferability low.
Explicit 6+ years and mandatory GRC frameworks and audit experience create moderate filter strictness.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Own and manage the compliance program covering Security, Privacy, and IT controls aligned to frameworks like ISO 27001, ISO 9001, SOC 2 Type II, PCI DSS, HIPAA, and GDPR.
Lead internal and external audit activities including control testing, evidence collection, remediation tracking, and certification assessments.
Develop and maintain compliance policies, conduct risk assessments, manage compliance exceptions, support vendor risk reviews, and produce compliance reporting for leadership.
6+ years of experience in IT Compliance, Information Security Governance, GRC, Audit, or Risk Management.
Demonstrated experience managing compliance programs and regulatory audits.
Knowledge and experience with ISO 27001, ISO 9001, SOC 2 Type II, PCI DSS, HIPAA, and GDPR compliance frameworks.
Bachelor's degree in Computer Science, Information Security, Information Systems, or related field.
Experienced in collaborating with cross-functional teams including Security, IT, Engineering, HR, and Legal in fast-paced environments.
Practical expertise in audit management, risk assessments, policy management, and governance processes.
Familiarity with cloud and SaaS environments and relevant certifications like CISSP, CISA, or ISO Lead Auditor preferred but not mandatory.