Senior Cyber Security & GRC Lead

Emergent Staffing, LLC

Hartford (CT)

Presencial

USD 130.000 - 180.000

Jornada completa

14 días+
Generador de candidaturas

Convierte este puesto en una entrevista — un currículum y una carta de presentación creados pensando en lo que quiere el empleador.

Supera los filtros ATS

Descripción de la vacante

Emergent Staffing, LLC is assisting a client in Hartford, CT to hire a Senior Cyber Security & GRC Engineer. The role leads an enterprise-wide security, governance, risk, and compliance program, owning the Vanta platform and driving NIST CSF 2.0, GDPR, and SOX ITGC compliance across multiple entities.

The ideal candidate combines strategic leadership with hands-on security operations, policy development, vendor risk management, and effective communication with executives and auditors.

Formación

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or equivalent experience.
  • 7+ years of information security, cybersecurity, or risk management experience with progression into senior program ownership responsibilities.
  • Hands-on experience administering a GRC platform, preferably Vanta.
  • Experience implementing, operating, or auditing against NIST CSF, SOX ITGC, and GDPR requirements.
  • Demonstrated success developing and implementing security policies, controls, and governance programs.
  • CISSP, CISM, CRISC, or CISA certification(s).
  • Strong technical knowledge of cloud security, IAM, endpoint security, vulnerability management, logging, and security operations.
  • Excellent communication skills with the ability to engage technical teams, business leaders, auditors, and executives.
  • Proven ability to work independently, manage multiple priorities, and drive accountability across stakeholders.

Responsabilidades

  • Own and mature the enterprise cybersecurity and risk management program across a multi-entity organization.
  • Design, implement, and maintain a harmonized control framework supporting NIST CSF 2.0, GDPR, and SOX ITGC requirements.
  • Lead enterprise governance activities, including risk reviews, KPI/KRI reporting, executive reporting, and steering committee meetings.
  • Serve as the primary liaison for auditors, assessors, clients, and internal stakeholders regarding security and compliance matters.
  • Administer and optimize Vanta as the enterprise GRC system of record.
  • Configure controls, integrations, tests, evidence collection, continuous monitoring, and audit workflows within Vanta.
  • Develop, maintain, and manage enterprise security policies, standards, procedures, exceptions, and policy lifecycle processes.
  • Lead SOX ITGC readiness and compliance efforts.
  • Operationalize GDPR requirements, including records of processing, DPIAs, data subject rights management, vendor oversight, and breach response.
  • Conduct NIST CSF 2.0 assessments, maturity reviews, gap analyses, and remediation planning.
  • Manage enterprise risk assessments, risk registers, third-party vendor risk programs, and remediation initiatives.
  • Oversee vulnerability management, patch coordination, access reviews, and technical security controls across cloud and on-premises environments.
  • Lead incident response activities, including preparation, detection, containment, recovery, and post-incident reviews.
  • Provide security architecture guidance for new systems, integrations, cloud solutions, and data platforms.
  • Build and manage security awareness, phishing simulation, and employee training programs.
  • Partner with business and project teams to ensure security and privacy requirements are incorporated into solution design.

Conocimientos

Information security
GRC program ownership
NIST CSF
GDPR compliance
SOX ITGC
Cloud security
Audit coordination
Communication with stakeholders

Educación

Bachelor's degree in Computer Science / Information Security / Cybersecurity

Herramientas

Vanta

Descripción del empleo

**This position is a direct hire for one of our clients. Our ideal candidates live in the Hartford, Connecticut metro area. East coast & TX candidates will be considered with expectations of occasional travel to Connecticut. Eligible candidates must currently reside in the US and authorized to work in the US without visa sponsorship.**

Our client is seeking an experienced Cyber Security & GRC Engineer to lead and mature an enterprise-wide cybersecurity, governance, risk, and compliance (GRC) program across multiple organizations. This is a senior-level, hands-on leadership role responsible for developing a unified security and compliance framework that supports NIST CSF 2.0, GDPR, and SOX IT General Controls requirements.

The ideal candidate combines strategic leadership with technical expertise, comfortably engaging executive stakeholders and auditors while also administering security tools, managing risks, implementing controls, and driving compliance initiatives. This role will serve as the owner of the enterprise GRC platform, Vanta, ensuring continuous monitoring, audit readiness, and program maturity across all entities.

Responsibilities
  • Own and mature the enterprise cybersecurity and risk management program across a multi-entity organization.

  • Design, implement, and maintain a harmonized control framework supporting NIST CSF 2.0, GDPR, and SOX ITGC requirements.

  • Lead enterprise governance activities, including risk reviews, KPI/KRI reporting, executive reporting, and steering committee meetings.

  • Serve as the primary liaison for auditors, assessors, clients, and internal stakeholders regarding security and compliance matters.

  • Administer and optimize Vanta as the enterprise GRC system of record.

  • Configure controls, integrations, tests, evidence collection, continuous monitoring, and audit workflows within Vanta.

  • Develop, maintain, and manage enterprise security policies, standards, procedures, exceptions, and policy lifecycle processes.

  • Lead SOX ITGC readiness and compliance efforts.

  • Operationalize GDPR requirements, including records of processing, DPIAs, data subject rights management, vendor oversight, and breach response.

  • Conduct NIST CSF 2.0 assessments, maturity reviews, gap analyses, and remediation planning.

  • Manage enterprise risk assessments, risk registers, third-party vendor risk programs, and remediation initiatives.

  • Oversee vulnerability management, patch coordination, access reviews, and technical security controls across cloud and on-premises environments.

  • Lead incident response activities, including preparation, detection, containment, recovery, and post-incident reviews.

  • Provide security architecture guidance for new systems, integrations, cloud solutions, and data platforms.

  • Build and manage security awareness, phishing simulation, and employee training programs.

  • Partner with business and project teams to ensure security and privacy requirements are incorporated into solution design.

Required Qualifications
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or equivalent experience.

  • 7+ years of information security, cybersecurity, or risk management experience with progression into senior program ownership responsibilities.

  • Hands-on experience administering a GRC platform, preferably Vanta.

  • Experience implementing, operating, or auditing against NIST CSF, SOX ITGC, and GDPR requirements.

  • Demonstrated success developing and implementing security policies, controls, and governance programs.

  • One or more of the following certifications: CISSP, CISM, CRISC, or CISA.

  • Strong technical knowledge of cloud security, identity and access management, endpoint security, vulnerability management, logging, and security operations.

  • Excellent communication skills with the ability to engage technical teams, business leaders, auditors, and executives.

  • Proven ability to work independently, manage multiple priorities, and drive accountability across stakeholders.

Nice to Have Experience
  • Direct Vanta administration experience.

  • Experience supporting a publicly traded company and SOX Section 404 compliance requirements.

  • Experience leading security programs across multiple organizations or business entities.

  • ISO 27001 Lead Implementer or Lead Auditor certification.

  • SANS/GIAC certifications.

  • Construction, engineering, energy, power generation, or EPC industry experience.

  • Familiarity with AI/ML governance, data security, and secure AI deployment practices.

Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Senior Cyber Security & GRC Lead
Senior Cyber Security & GRC Lead

Emergent Software • Hartford (CT)

Presencial
USD 140.000 - 170.000
Enterprise Cybersecurity & GRC Leader (NIST/GDPR/SOX)
Enterprise Cybersecurity & GRC Leader (NIST/GDPR/SOX)

Emergent Software • Hartford (CT)

Presencial
USD 140.000 - 170.000
Senior Cybersecurity & GRC Leader: NIST, GDPR & SOX
Senior Cybersecurity & GRC Leader: NIST, GDPR & SOX

Emergent Staffing, LLC • Hartford (CT)

Presencial
USD 130.000 - 180.000
Governance, Risk & Compliance Analyst, Specialist
Governance, Risk & Compliance Analyst, Specialist

Vanguard • Dallas (TX)

Presencial
USD 90.000 - 125.000
Governance, Risk & Compliance Analyst, Specialist
Governance, Risk & Compliance Analyst, Specialist

Vanguard • Malvern

Presencial
USD 110.000 - 160.000
GRC Manager
GRC Manager

Glocomms • San Francisco (CA)

Presencial
USD 120.000 - 180.000
Full Health Benefits
Equity participation
Relocation Support
+1
Lead GRC Security Engineer
Lead GRC Security Engineer

Lorien • EE. UU.

Presencial
USD 165.000 - 240.000
GRC (Governance, Risk, and Compliance) Consultant
GRC (Governance, Risk, and Compliance) Consultant

Zoho • EE. UU.

A distancia
USD 120.000 - 180.000
Senior Security Engineer
Senior Security Engineer

Prestige Staffing • Georgia

Presencial
USD 140.000 - 200.000
Senior Cybersecurity GRC Analyst
Senior Cybersecurity GRC Analyst

Eliassen Group • King of Prussia (PA)

Presencial
USD 80.000 - 105.000