We are seeking an experienced Information Security Governance Specialist to support and strengthen enterprise information security governance, risk, and compliance activities. This role will work closely with Information Security, Technology, Risk, Compliance, Audit, and business stakeholders to ensure security controls, policies, standards, and risk management practices are effectively implemented and maintained.
The ideal candidate will have strong experience in information security governance, GRC, risk and controls, security frameworks, audit support, and stakeholder management within a large enterprise environment.
Key Responsibilities
- Support the development, implementation, and maintenance of information security policies, standards, procedures, and governance processes.
- Manage and maintain security risk and control documentation, including Risk & Control Matrices, control inventories, and risk registers.
- Coordinate periodic control assessments, certifications, testing, and evidence collection with control owners.
- Identify control gaps, document risks, track remediation activities, and elevate overdue or high-risk issues.
- Perform information security and technology risk assessments across applications, infrastructure, cloud environments, vendors, and business processes.
- Support internal and external audits, regulatory examinations, compliance assessments, and security reviews.
- Map security controls to applicable frameworks and regulatory requirements, including NIST, ISO 27001, COBIT, SOC 2, and SOX where applicable.
- Review audit findings, security assessments, and third-party reports to identify control deficiencies and required remediation.
- Maintain governance metrics, dashboards, risk reporting, and executive-level presentations.
- Partner with technology and business stakeholders to ensure security requirements are understood and incorporated into business and technology initiatives.
- Support security exception and risk acceptance processes, including documentation, approvals, compensating controls, and expiration tracking.
- Coordinate security governance meetings and forums and track decisions, actions, and remediation commitments.
- Identify opportunities to improve security governance processes, control effectiveness, documentation, and reporting.
- Support the implementation and ongoing administration of Governance, Risk, and Compliance (GRC) platforms.
Required Qualifications
- 5+ years of experience in information security, cybersecurity governance, technology risk, GRC, IT audit, security compliance, or a related field.
- Hands-on experience with information security controls, risk assessments, governance processes, and compliance activities.
- Strong understanding of security frameworks such as NIST, ISO 27001, COBIT, CIS Controls, or similar frameworks.
- Experience developing or maintaining Risk & Control Matrices (RCMs/RACMs), control inventories, risk registers, and governance documentation.
- Experience supporting internal/external audits and remediation of security or technology control findings.
- Experience with GRC platforms such as Archer, ServiceNow GRC, MetricStream, or similar tools.
- Strong understanding of enterprise security concepts including IAM, cloud security, vulnerability management, application security, encryption, network security, data protection, and third-party risk.
- Excellent written and verbal communication skills with the ability to communicate security risks to both technical and non-technical stakeholders.
- Strong analytical, organizational, documentation, and problem-solving skills.
Preferred Qualifications
- Experience in financial services, banking, investment management, brokerage, asset management, wealth management, retirement services, or another highly regulated industry.
- Experience with SOX 404, SOC 1/SOC 2, PCI DSS, GDPR, or other regulatory/compliance requirements.
- Experience with Information Security Management Systems (ISMS).
- Experience with cloud security governance across AWS and/or Azure.
- Experience with third-party/vendor security assessments.
- Experience supporting regulatory examinations and enterprise-level audits.
- Certifications such as CISA, CISM, CRISC, CISSP, CGEIT, or ISO 27001 Lead Auditor/Implementer are preferred.
- Experience developing security governance metrics, dashboards, and executive reporting.