Get more replies from employers
Send a job-specific resume in minutes.
Xceedance is seeking a seasoned GRC Coordinator to serve as the single point of contact for client security questionnaires, manage bi-annual cycles, and coordinate with Security Compliance and business SMEs to complete responses.
You will maintain documentation, ensure consistency with prior submissions, support SOX audits, lead data-pull requests, and foster cross-functional collaboration with IT, Legal, HR, and vendors.
nt· Serve as the single point of coordination for client-issued IT security/compliance questionnaires — cyclic and bi-annual in natur
e.· Log incoming requests from the shared distribution mailbox, loop in the account manager, and set/manage the standard ~60-day turnaround commitment to client
s.· Route each questionnaire to the corporate Security Compliance team, who own roughly 90% of standard responses, and independently coordinate with business subject-matter experts to complete the remaining client- or business-specific question
s.· Maintain the Received / Working / Sent folder structure and the historical SharePoint response repository; reuse and adapt previously validated answers to maintain consistency and speed of turnaroun
d.· Cross-check current-cycle responses against prior submissions for the same client, flag inconsistencies or outdated answers, and escal
n.· Coordinate the semi-annual access recertification cycle (for H1 typically starting January/February and completing through June, aligned with SOX audit timing) covering in-scope applications and shared-data security object
s.· Confirm application inventory and scope with application owners; submit and track data-pull requests to the Security Administration team via the internal ticketing syste
m.· Consolidate and clean raw access-extract data (application ownership details, AD extracts, user profiles) into a standardized Excel workbook, using macros, formulas, and pivot tables to de-duplicate entries and merge rows where necessary (with multi-group access details
).· Load the consolidated dataset into SharePoint, distribute recertification requests to business and IT reviewers, and track review decisions through to completio
n.· Compile audit-ready evidence packages (timestamps, reviewer decisions, access-removal confirmations) to support internal IT audit and SOX audit requirement
s.· Coordinate with Legal, HR, or other business stakeholders as needed for non-standard questionnaire items and elevate unique/new/non-standard client audit requests to senior team member
es· Coordinate mandatory bi-annual security/privacy awareness training for employees and consultants with access to personal information — working with HR and the employee talent portal and managing SharePoint acknowledgment surveys or vendor points of contact for consultant population
s.· Support the annual BCP/DR test cycle: confirm test dates with application owners, ensure business tester availability, track communications, and document test outcomes and remediation ownershi
NS· Bachelor's degree in either Comp Science, Information Systems, Information Security, Privacy, Risk Management, IT/Information Systems Business Administration or a related fiel
d.· Overall 5+ years of experience with 3–5 years of experience in GRC coordination, compliance operations, IT audit/vendor-risk support, client assurance, and with project coordination roles; deep technical security background is not require
d.· Advanced Excel skills, including documentation, pivot tables, macros, formula-based reconciliation, and large-dataset consolidation/cleanu
p.· Strong working knowledge of MS Word, SharePoint, and shared-drive documentation management practice
s.· Excellent written and verbal English communication skills, with confidence handling client-facing as well as internal leadership correspondenc
e.· Demonstrated ability to coordinate across cross-functional stakeholders — IT, Security, Legal, HR, Business, and third-party vendors etc. and drive follow-ups to closur
e.· High attention to detail and consistency when validating recurring or comparative data set
s.· Ability to handle sensitive, PII-adjacent information responsibly and maintain confidentiality (the role does not require direct access to client applications or systems
) .· Availability to overlap with US Eastern Time hours (through at least 12:00 PM ET) for real-time collaboration with the client teams/stakeholder
ES· Familiarity with vendor/third-party risk concepts (e.g., SIG questionnaires) is an advantage; formal GRC or security certifications are good to have but not mandatory for this rol
e.· Prior experience supporting insurance, reinsurance, or financial services client
s.· Experience with GRC tools, security questionnaire platforms, audit evidence repositories, or workflow tracking tools is an advantag
e.· Good understanding of information security, privacy, risk, access management, business continuity, and compliance concepts; familiarity with ISO 27001, ISO 27701, SOC/SOC 2, NIST, GDPR, HIPAA etc. or client audit requirements is preferre
d.· Certifications such as ISO 27001 Foundation/Internal Auditor, ISO 27701, ISO/IEC 27001:2022 LI or LA, CISA, CRISC, or equivalent are good to hav
e.· Self-driven with strong ownership; comfortable ramping up through an apprenticeship/knowledge-transfer period alongside the client team before working semi-independentl
y.· Comfortable in a coordination-heavy role with cyclical rather than constant workload peaks, and able to flex into ad hoc requests as they aris