We are looking for Security Governance, Risk, and Compliance (GRC) Engineer for our client in San Jose CA.
Job Title: Security Governance, Risk, and Compliance (GRC) Engineer
Job Location: San Jose CA
Job Type: Contract
Job Overview:
Pay Range: $90hr - $120hr
Requirement/Must Have:
- 7+ years professional experience in governance, risk and compliance and/or information security and risk management.
- Competent industry certifications, with extra points for AI-related certifications.
- Functional knowledge of the CISSP security domains and information security industry standards and best practices.
- Functional knowledge of applicable security regulatory and compliance requirements (EU AI Act, SOX, GDPR).
- Functional knowledge of ISMS governance models and analysis of certification reports (i.e. ISO 42001 & 27001, SOC, CAIQ), information security roles, security controls.
- Strong verbal and written communication skills.
- Ability to independently drive program areas and cross-functional teams to deliver high quality results according to well-defined planning.
- Strong interpersonal skills and ability to work effectively with diverse and globally distributed teams.
- Strong attention to detail, project management and organizational skills.
- Self-starter with the ability to effectively manage independent workloads asynchronously with stakeholders across multiple time zones.
Responsibilities:
- Support the GRC operating model and the service-oriented customer engagement model.
- Provide Information Security Data Governance program expertise and drive the operational delivery of the program.
- Provide AI Governance and development expertise to business units and key stakeholders.
- Utilize current tools to design, build, and enhance team processes using AI agents and intelligent workflows.
- Maintain AI roadmaps and related communications to security leadership.
- Provide Information Security Risk Management support and assist with the operational delivery of the program.
- Develop and present regular operational and executive level metrics and reporting.
- Perform risk assessments to address security threats, changes to systems and/or applications, process improvement initiatives, supplier assessments and other requests from the business.
- Collaborate with various operational and business teams to complete assessments, develop treatment plans, and drive remediation items to closure.
- Monitor the security risk profiles and events of suppliers to determine high risk suppliers that require additional review and treatment plans.
- Act as security governance and risk management ambassador to internal customers.
- Align governance and operational activities to industry best practices and current standards, as defined by internal policies and international standards bodies.
- Develop processes to utilize AI functionality to improve and enhance efficiencies, without sacrificing quality and accuracy.
- Build new AI-driven internal processes to assist with prioritizing and risk-scoring activities.
- Use defined risk methodologies and best practices to perform Security assessments.
- Drive remediation activities from identification, treatment plan, remediation, and closure.
- Operationalize a metrics and reporting function to continually report on meaningful security, risk and compliance metrics for operational and executive management.
=
Benefits
Our Benefits Include:
- Medical, Dental, and Vision Insurance
- 401(k) Retirement Plan
- Health Savings Account (HSA)
- Disability Insurance (Short-Term and Long-Term)
- Life and AD&D Insurance
- Paid Sick Leave (where required by applicable state or local law)
- Supplemental Insurance Plans
- Identity Theft Protection
- Pet Insurance
- Employee Wellness Programs
- Employee Assistance Program (EAP)
- Career Growth and Professional Development Opportunities
Disclaimer: Benefits eligibility, accrual rates, and usage limits may vary based on employment status, length of service, and work location. Paid Sick Leave is provided in strict accordance with applicable state and municipal mandates. Cynet Systems Inc. reserves the right to modify, amend, or terminate any benefit plans at any time in accordance with applicable laws.
About Cynet Systems
Founded in 2010 and headquartered in the Washington, DC metro area, Cynet Systems Inc. is a leading technology staffing and workforce solutions company serving Fortune 500 companies, government agencies, and enterprise organizations across the United States and Canada. We deliver agile, scalable talent solutions across IT, engineering, life sciences, clinical, and professional staffing, powered by a high-performing recruitment engine operating across North America and Asia.
As a nationally and locally certified Minority Business Enterprise (MBE), Cynet Systems is committed to helping organizations build high-performing teams while empowering professionals to grow rewarding careers. Our organization is certified to ISO 9001, ISO 14001, ISO 27001, and SOC 2 Type II standards, reflecting our commitment to quality, security, operational excellence, and customer success.