Job Description
Manager - Governance Risk and Compliance
About CBIZ
CBIZ, Inc. (NYSE: CBZ) is a leading professional services advisor to middle-market businesses nationwide. With industry knowledge and expertise in accounting, tax, advisory, benefits, insurance, and technology, CBIZ delivers actionable insights to help clients anticipate what is next and discover new ways to accelerate growth. CBIZ has more than 9,500 team members across 23 major markets coast to coast.
CBIZ strives to be our team members employer of choice by creating an environment where team members are appreciated, recognized for their contributions, and provided with opportunities to grow, both personally and professionally, throughout their careers.
Together, CBIZ and CBIZ CPAs are ranked as one of the top providers of accounting services in the United States. CBIZ CPAs is an independent CPA firm that provides audit, review and attest services, while CBIZ provides business consulting, tax and financial services. In certain jurisdictions, CBIZ CPAs operates under its previous name, Mayer Hoffman McCann P.C.
Role Purpose
The GRC Specialist is responsible for assessing, managing, and mitigating risks associated with third-party vendors and service providers. Implement security best practices, policies, and controls through a repeatable process. This role involves conducting thorough security evaluations of potential and existing vendors, conducting regular security awareness trainings, and phishing campaigns, design and implementation of KPI s, KRI s, enhancing our internal policies and procedures.
Roles & Responsibilities
- Enhance existing security policies, controls and procedures and conduct annual certifications.
- Assist to operationalize the GRC tool and identify areas of improvement.
- Develop and maintain a vendor risk management framework and supporting documentation.
- Conduct detailed risk assessments, identify potential security risks associated with third-party vendors by reviewing and analyzing security policies, controls, and procedures.
- Get to know the business side, meet with owners and vendors, while identifying opportunities to improve ease of vendor management.
- Collaborate with legal, and other departments to ensure that security requirements are included in contracts and service level agreements (SLAs).
- Collaborate and coordinate with other Security groups, IT Operations, and other teams on audits, assessments and GRC control recommendations.
- Monitor and evaluate changes in vendor services or operations that may impact the organizations security posture.
- Provide guidance and recommendations to internal stakeholders regarding security risks and controls.
- Publish and collaborate outside vulnerability and threats. Stay current with industry best practices, regulatory requirements, and emerging threats related to third-party engagements.
- Maintain Security Awareness, Compliance programs, Risk register.
- Generate KPI s and KRI s for the security team.
Skills & Qualifications
- Minimum of 10 years of experience in information security, with a focus on third-party/vendor risk management.
- Strong understanding of information security principles, frameworks (e.g., NIST, ISO 27001, SOC 2 Type 2), and regulations (e.g., GDPR, HIPAA).
- Experience with risk assessment methodologies and tools.
- Excellent analytical and critical thinking skills, with the ability to manage complex projects.
- Proficient communication skills, both written and verbal, with the ability to explain technical concepts to non-technical stakeholders.
- Detail-oriented with strong organizational skills.
- Ability to work independently as well as collaboratively within a team environment.
- Bachelor s degree in information technology, Cybersecurity, or a related field; or equivalent work experience.
- Relevant professional certifications, such as CISM, CRISC, or CISA are preferred.
Perks & Benefits
- Competitive remuneration and benefits package:
- Insurance Benefits - Health Insurance cover for family includes 2 parents, OPD & Term life Insurance
- Paid time off - Parental leaves (Maternity & Paternity leaves), Paid Leaves
- Work life Harmony - Hybrid work model
- Mobility Benefits - Relocation benefits and door-to-door transportation
- Retiral Benefits - Employee PF Contribution, Gratuity, Leave Encashment
- Once in a lifetime opportunity to set up offshore business for one of the 10th largest Financial Services and CPA firms in the US.
- Chance to work with a team of talented and passionate individuals who are committed to delivering high-quality work to our clients.
- The opportunity to thrive in a high-performance environment while contributing to the foundation of a new division.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.