FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in managing GRC programs and cyber risk frameworks, including ISO 27001, SOC 2, and NIST, while driving compliance and risk remediation initiatives. Proficient in building risk registers and control frameworks, with a strong focus on security policy management and process automation.
Highest-signal resume keywords
GRC Program ManagementISO 27001 FrameworkSOC 2 FrameworkNIST FrameworkRisk Remediation
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Cyber Risk AssessmentCompliance ManagementRisk Register DevelopmentControl Framework ImplementationEvidence Collection and Validation
Soft Skills
Proactive LearningEffective CommunicationProblem Solving
Tools & Technologies
Modern GRC PlatformsAI Tooling
Industry Keywords
SaaSCloudCritical InfrastructurePublic SectorRegulatory Compliance
Tech Stack
Tools & technologiesCloudCyber Security
About the role
Key responsibilities & impact- Identify, assess, and track enterprise, cyber, product, and third-party risks
- Expand the cybersecurity risk universe
- Maintain risk scoring, treatment plans, and evidence aligned with ISO 27001, SOC 2, and NIST
- Drive risk remediation and manage risk acceptance workflows
- Operate GRC programs across ISO 27001, SOC 2, and NIST
- Map controls to eliminate duplication and improve efficiency
- Collect and validate evidence for internal assessments
- Manage security policy and standard lifecycles
- Research and implement compliance process improvements
- Build audit playbooks and practical controls
- Support external audits and coordinate evidence submission
- Respond to customer security questionnaires, RFPs, and due-diligence requests
- Partner with Engineering, Cloud Ops, IT, and Product to embed risk considerations
- Act as a risk gatekeeper for product releases and major delivery milestones
- Drive security awareness training and risk communications
- Champion security best practices and build company-wide security culture
- Participate in cross-functional risk forums and working groups
- Own key GRC components such as third-party risk or policy governance
- Drive process automation and program maturity using AI tooling
- Support executive reporting and strategic initiatives with the GRC Manager
Requirements
What you’ll need- Experience in GRC, cyber risk, compliance, or information security, ideally within SaaS, cloud, or critical-infrastructure environments
- Deep, practical working knowledge of at least three major frameworks, including ISO 27001, SOC 2, NIST, FedRAMP, FAIR, or COSO
- Proficiency with modern GRC platforms
- Hands-on ability to build and operate risk registers and control frameworks
- Exposure to public-sector or highly regulated customers, including federal, state, municipal, or transportation agencies
- Ability to use AI tooling effectively while identifying inaccurate outputs
- Proactive ability to independently learn frameworks, tools, or systems
- Strong ability to explain control gaps and drive remediation without friction
Benefits
Comp & perks- Comprehensive health benefits
- 24/7 virtual healthcare access
- Dedicated wellness programs
- RRSP/401K Matching Plan
- Variable Incentive Plan
- Mio-Days
- Flexible vacation policy
- Flexible work options
- Internet subsidy
- Remote work allowance
- Enhanced leave for new parents
- Equity
- Discretionary bonus
