Senior Security Engineer, GRC

🕒 il y a 1 mois

🌐 États-Unis, Canada – Distant

info

💵 $180 000 - $225 000 / an

⏰ Temps Plein

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of Temporal Technologies

Temporal Technologies

51 - 200 employés

Fondée en 2018

💼 Conseil

🏭 Fabrication

📣 Marketing

💰 €75 000 000 Series B en 2023-02

Consulting • Manufacturing • Marketing

Temporal Technologies est une entreprise qui fournit une plateforme pour l'exécution durable, aidant les développeurs à créer des applications résilientes en gérant les défaillances, les pannes de réseau et les processus de longue durée. Leur technologie abstrait la complexité de la construction de systèmes distribués évolutifs, permettant aux développeurs de se concentrer sur la livraison de systèmes fiables plus rapidement. Temporal simplifie le code en éliminant la logique de récupération, les rappels et les minuteries, rendant ainsi les logiciels plus durables et tolérants aux pannes. La plateforme prend en charge une large gamme d'applications, allant du traitement des transactions à l'IA appliquée, et est appréciée par les développeurs pour sa facilité d'utilisation et sa fiabilité. Temporal est open-source et propose des services cloud autogérés ainsi que gérés dans plusieurs régions, permettant le développement d'applications serverless et évolutives.

Description

• Own the intake, prioritization, and completion of all inbound customer security questionnaires, RFPs, and due diligence requests including SIG, CAIQ, and custom enterprise questionnaires with a commitment to accuracy, thoroughness, and turnaround time. • Serve as the primary customer-facing representative for security and compliance, leading calls and meetings with enterprise customers, prospects, and their security or procurement teams. • Build and maintain a comprehensive, evergreen response library for common security and compliance questions, reducing duplication of effort and ensuring consistency across all customer engagements. • Build and maintain automations to continuously validate the organization's compliance posture across key frameworks including SOC2 Type II, ISO 27001, and HIPAA, coordinating evidence collection, managing external auditor relationships, and driving readiness for annual assessments. • Build dashboards and reporting pipelines that provide leadership with real-time visibility into compliance posture, open risks, and program health. • Design and automate the third-party risk assessment process, including vendor tiering logic, questionnaire workflows, and continuous monitoring for critical vendors. • Perform ongoing risk assessments and maintain a risk register that reflects the current threat and compliance landscape, escalating material findings to leadership with clear remediation recommendations. • Conduct third-party vendor risk assessments, including use case-specific risk analysis, ongoing tiering and monitoring, and implementation recommendations. • Author, maintain, and operationalize security policies and procedures; track employee acknowledgments and manage exceptions through to resolution. • Coordinate and participate in customer security review meetings, including onsite or virtual sessions with enterprise security, legal, and procurement stakeholders. • Collaborate cross-functionally with Engineering, Legal, and Product to gather documentation, validate control descriptions, and resolve compliance gaps surfaced through customer inquiries.

🎯 Exigences

• 8+ years of experience in GRC, information security compliance, or a closely related field. • Deep, hands-on experience with at least two major compliance frameworks (SOC2, ISO 27001, HIPAA, PCI-DSS, or FedRAMP), including direct involvement in audits and assessments. • Proven track record managing high volumes of security questionnaires and enterprise due diligence requests, including SIG and CAIQ formats. • Strong understanding of the security program’s influence on company revenue and a partnership mindset with the Go To Market function. • Scripting and automation fluency (Python, Bash, or similar) and a track record of building tools, not just spreadsheets. • Strong customer-facing communication skills, you are equally comfortable presenting to a CISO, walking a procurement team through a control matrix, or discussing technical security controls with customer engineering leaders. • Solid understanding of risk management principles, with hands-on experience performing risk assessments and maintaining a risk register. • Ability to translate technical security controls into clear, business-appropriate language for non-technical audiences including customers, legal teams, and executives. • Strong organizational skills and the ability to manage multiple concurrent questionnaire engagements, each with distinct deadlines and stakeholder requirements. • Bachelor's degree in Information Security, Computer Science, Business, or a related field (or equivalent experience).

🏖️ Avantages

• Unlimited PTO, 12 Holidays + 2 Floating Holidays • 100% Premiums Coverage for Medical, Dental, and Vision • AD&D, LT & ST Disability, and Life Insurance (Standard & Supplemental Available) • Empower 401K Plan • Additional Perks for Learning & Development, Lifestyle Spending, In-Home Office Setup, Professional Memberships, WFH Meals, Internet Stipend and more!

Postuler Maintenant

Emplois Similaires

🕒 il y a 1 mois

Omniscius LLC

1 - 10

💼 Conseil

📦 Logistique

🏥 Santé

Information System Security Officer responsible for cybersecurity and compliance in Microsoft Azure cloud platform for federal client. Leading security activities and ensuring compliance with federal frameworks.

🇺🇸 États-Unis – Télétravail

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

Azure

Cloud

Cyber Security

🕒 il y a 1 mois

HubSpot

1001 - 5000

🤝 B2B

☁️ SaaS

📣 Marketing

Manager of Security GRC focused on compliance onboarding at HubSpot. Leading a team while executing as a hands-on individual contributor.

🇺🇸 États-Unis – Télétravail

💵 $131 500 - $210 400 / an

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Zona Facta

501 - 1000

💼 Conseil

🎖️ Défense

🔐 Sécurité

Armed Protective Agent providing security escort for ATM technicians during service operations in Cleveland, Ohio. Maintaining a professional presence and adhering to company policies for security operations.

🇺🇸 États-Unis – Télétravail

💵 $23 - $25 / heure

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Zona Facta

501 - 1000

💼 Conseil

🎖️ Défense

🔐 Sécurité

Armed Protective Agent responsible for providing security escorts for ATM service technicians. Maintaining vigilance and professionalism during service operations in Cleveland, Ohio area.

🇺🇸 États-Unis – Télétravail

💵 $23 - $25 / heure

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

DigitalOcean

1001 - 5000

☁️ SaaS

Senior Engineering Manager leading the Security Products engineering team at DigitalOcean. Driving technical roadmap and delivering scalable security solutions for global customers.

🗣️🇺🇸🇬🇧 Anglais requis