FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in Governance, Risk, and Compliance (GRC) leadership, with a strong focus on SOC 2 and HITRUST certification processes, AI governance frameworks, and risk assessment methodologies. Proven ability to mentor teams, negotiate compliance agreements, and enhance operational efficiency through effective policy implementation.
Highest-signal resume keywords
GRC LeadershipSOC 2/HITRUST CertificationAI Governance FrameworksRisk Assessment MethodologyCompliance Negotiation
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Risk AssessmentControl MaturityData Privacy ComplianceIncident/Breach AnalysisOperational Efficiency ImprovementSecurity Risk ManagementAudit Program ManagementThird Party Risk ManagementSecurity Training DevelopmentContinuous Control Monitoring
Soft Skills
Team LeadershipMentoringNegotiationCollaborationCommunication
Tools & Technologies
DrataJamfCrowdStrikeArctic WolfWizServalKnowbe4AWSOktaJIRA
Certifications & Qualifications
CISSPCISACISM
Industry Keywords
SOC 2HITRUSTHIPAAHITECHBAAISO/IEC 42001AI Risk RegisterData Handling RequirementsBusiness Continuity PlanningControl Effectiveness
Tech Stack
Tools & technologiesAWSJamfSDLC
About the role
Key responsibilities & impact- Lead and mentor a small GRC team, setting priorities, reviewing work, and growing the function
- Own and evolve the unified control library, maintaining mappings across SOC 2, SOC 1, and the latest HITRUST version
- Lead the audit program for control requirements and evidence production in partnership with Engineering, IT, People, and Finance
- Partner with Legal on data privacy programs, including HIPAA/HITECH, BAAs, privacy and protection impact assessments, incident/breach analysis, and data handling requirements
- Own and mature the AI governance program modeled after ISO/IEC 42001, including the AI risk register, Statement of Applicability, and AI risk assessments
- Respond to customer and partner AI governance questionnaires and maintain alignment with emerging requirements such as Colorado ADMTA
- Review and negotiate security, privacy, data protection, incident notification, audit rights, AI, and related language in customer and vendor agreements
- Monitor, measure, and report control effectiveness in Drata, maintaining continuous control monitoring and evidence collection
- Improve policies and procedures to increase operational efficiency, control maturity, security, and compliance
- Lead business continuity planning and testing, focusing on a BIA-informed program
- Revamp and execute the Third Party Risk Management program
- Own the security risk management program, including enterprise risk preparation, discussion, tracking, remediation, and annual risk assessments
- Develop and implement security and compliance training programs
- Own and maintain the customer assurance program, including security questionnaires, RFP responses, trust center content, and supporting tooling
Requirements
What you’ll need- 5-10 years of related work experience
- Maintains a certification relevant to the role (e.g, CISSP, CISA, CISM)
- Personally led SOC2 with HITRUST CSF certification in a high growth environment and understands how to mature controls consistent with organizational maturity and capacity
- Familiarity with AI governance frameworks (e.g., ISO/IEC 42001) and the risk considerations of AI systems that process sensitive data
- Experience leading or mentoring GRC analysts
- Deep understanding of risk assessment methodology, HIPAA, and HITECH, including the practical distinction between covered entity and business associate obligations
- Comfortable negotiating and redlining BAAs and conducting four-factor breach risk assessments alongside Privacy and legal
- Intermediate to advanced understanding of the Software Development Life Cycle and IT and security tooling (Jamf, CrowdStrike, Arctic Wolf, Wiz, Serval, Knowbe4, Drata, AWS, Okta, JIRA, GIT/GITHUB) as it relates to controls
- Ability to perform qualitative and quantitative risk assessment
- Experience with joint SOC 2/HITRUST attestations (extra credit)
- A blend of deep, technical and compliance knowledge and experience (extra credit)
Benefits
Comp & perks- Bonus
- Equity
- Equal Opportunity Employer with an inclusive culture where differences are celebrated
