Information Security Engineer, GRC

KYOCERA AVX Greenville

Fountain Inn (SC)

On-site

USD 140,000 - 190,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

KYOCERA AVX Greenville is seeking an experienced GRC leader to design, implement, and govern the organization’s information security program in alignment with NIST, CIS, and ISO 27000 frameworks. You will drive risk assessments, third-party risk, audit readiness, and continuous compliance using a structured project management approach.

The role requires 10+ years in information security with strong communication skills and hands-on experience with GRC tooling such as Archer, ServiceNow GRC,

Qualifications

  • Bachelor's degree required with 10+ years in information security focusing on GRC or risk/compliance.
  • Experience with NIST CSF, NIST SP 800-53/171, CIS, ISO 27001 and related frameworks.
  • Hands-on risk assessments, control assessments, and audit responses experience.
  • Knowledge of regulatory requirements such as GDPR, CMMC, GDPR, IATF or related.
  • Strong written and verbal communication; ability to produce executive-level reporting.
  • Proficiency with GRC tooling (Archer, ServiceNow GRC, OneTrust, RSA) and security monitoring platforms.

Responsibilities

  • Governance, policy & control design: Maintain policies/standards; map obligations to frameworks; define testable controls and evidence.
  • Risk management & exceptions: Conduct risk assessments; maintain risk register; support remediation decisions.
  • Compliance & audit readiness: Test controls, document gaps, gather audit evidence, close findings.
  • Third-party risk: Assess vendor security; review artifacts; drive remediation with vendors.
  • Control implementation support & monitoring: Collaborate with IT/SecOps to implement and monitor controls; define evidence sources.
  • Metrics & stakeholder communication: Create dashboards and reports for risk, control health, and remediation aging.
  • Operational support & enablement: Provide GRC guidance during incidents and publish job aids to decrease exceptions.

Skills

GRC
NIST frameworks
Risk assessments
Audit readiness
Third-party risk
Policy design
Executive reporting
Stakeholder comms

Education

Bachelor's degree
Master’s degree or advanced certification
Certifications: CISSP, CISM, CRISC, CGEIT

Tools

Archer
ServiceNow GRC
OneTrust
RSA
Security monitoring platforms

Job description

Design, implement, audit, and maintain governance, risk management, and compliance (GRC) controls for the organization’s information security program aligned to the National Institute of Standards and Technology (NIST), the Center for Internet Security (CIS), and the International Organization for Standardization (ISO) 27000 family of frameworks. Drive policy, risk assessments, third party risk, audit readiness, and continuous compliance with regulatory and industry standards, using an organized and project managed approach.

  • Governance, policy & control design: Maintain policies/standards; map obligations to NIST CSF, NIST SP 800-53/800-171, CIS, and ISO 27001; define testable controls, procedures, and evidence requirements.
  • Risk management & exceptions: Conduct risk assessments; document scenarios and residual risk; maintain risk register, compensating controls, and remediation plans; support exception/acceptance decisions with rationale and evidence.
  • Compliance & audit readiness: Test controls (design/operating effectiveness), document gaps, assemble audit evidence, and track findings to validated closure.
  • Third-party risk: Assess vendor security (questionnaires, SOC/ISO artifacts, evidence review), document risk and required controls/terms, and drive remediation follow-ups.
  • Control implementation support & monitoring: Partner with IT/SecOps to implement and run controls (access, logging, vuln mgmt, encryption, backup/DR) and define monitoring, evidence sources, and test cadence.
  • Metrics & stakeholder communication: Produce dashboards and brief status reports on risk, control health, audit readiness, and remediation aging for technical and non-technical stakeholders.
  • Operational support & enablement: Provide GRC support for incidents/vulnerabilities and privacy obligations; publish practical guidance (standards, job aids, FAQs) to increase control adoption and reduce exceptions.
REQUIRED QUALIFICATIONS:
  • Bachelor's degree
  • 10+ years experience in information security, including GRC, or risk/compliance roles.
  • Demonstrated experience with NIST frameworks (NIST CSF, NIST SP 800-53, NIST RMF, NIST SP 800-171), CIS 8.1, and ISO 27001.
  • Hands-on experience conducting risk assessments, control assessments, and audit responses.
  • Experience with regulatory requirements relevant to the organization (e.g., CMMC, TISAX, CTPAT, GDPR, IATF).
  • Strong communication skills; experience producing executive-level reporting.
  • Experience with GRC tooling (e.g., Archer, ServiceNow GRC, OneTrust, RSA) and security monitoring platforms.
PREFERRED QUALIFICATIONS:
  • Master’s degree or relevant advanced certification.
  • Certifications: CISSP, CISM, CRISC, CGEIT, or equivalent.
  • Experience with cloud security (AWS/Azure/GCP) controls and cloud compliance frameworks.

Kyocera-AVX is an Equal Opportunity Employer: All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or status as a protected veteran.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Engineer, GRC
Information Security Engineer, GRC

KYOCERA AVX Components Corporation • Fountain Inn (SC)

On-site
USD 90,000 - 120,000
Information Security Engineer, GRC
Information Security Engineer, GRC

KYOCERA AVX Greenville LLC • Fountain Inn (SC)

On-site
USD 100,000 - 130,000
Information Security Engineer, GRC
Information Security Engineer, GRC

Compliance Officer Jobs • Fountain Inn (SC)

On-site
USD 110,000 - 170,000
IT Security GRC Analyst
IT Security GRC Analyst

The Phoenix Group • Charlotte (NC)

On-site
USD 85,000 - 120,000
Cyber GRC Specialist
Cyber GRC Specialist

Jobtailor • Washington

On-site
USD 90,000 - 130,000
Information Technology Security Analyst
Information Technology Security Analyst

The Phoenix Group • Charlotte (NC)

Hybrid
USD 54,000 - 90,000
Hybrid work model
Relocation assistance
Certifications support
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
GRC Analyst II
GRC Analyst II

Frontgrade Technologies • Colorado Springs (CO)

On-site
USD 70,000 - 90,000
Immediate Medical, Dental, and Vision
401K Match with 100% immediate vesting
Tuition Reimbursement/Student Loan Repayment
+2
GRC Specialist (Governance, Risk & Compliance)
GRC Specialist (Governance, Risk & Compliance)

360CyberX • United States

On-site
USD 70,000 - 90,000
Lead GRC Analyst (IT/Security)
Lead GRC Analyst (IT/Security)

Ultra Clean Technology • Manor (TX)

On-site
USD 90,000 - 120,000