Ivalua

Ivalua

Sr Manager, InfoSec Governance Risk and Compliance (GRC)

Pittsburgh, Pennsylvania, United States · Senior

Sponsorship not specified$53k-$800kDetected 35 days ago
CybersecurityComplianceProject ManagementSupply ChainHIPAACommunicationCollaborationProblem Solving

About the role

  • Serve as the subject matter expert (SME) on security frameworks and standards including NIST SP 800-53 Rev 5, NIST 800-171, ITAR, FedRAMP, PCI DSS, SOC2, etc., providing guidance to internal stakeholders.
  • Review and negotiate information security exhibits and contractual terms in partnership with the legal team.
  • Oversee the Third Party Risk and Vendor Security Assessment program to mitigate supply chain risks.

Responsibilities

  • Lead and own the Governance, Risk, and Compliance (GRC) program globally, managing and developing a high-performing team.
  • Manage and drive compliance efforts and audits for certifications such as FedRAMP, IRAP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, and others.
  • Efficiently manage and respond to customer security audit and compliance requests in a timely manner.
  • Maintain continuous compliance and monitoring of security controls to ensure ongoing adherence to standards.
  • Lead the Security Awareness and Training program to promote a culture of security across the organization.
  • Track, manage, and drive remediation efforts for control deficiencies and gaps identified through internal and external audits.
  • Develop, maintain, and enforce InfoSec policies, standards, and plans.
  • Collaborate with like-minded individuals who are deeply passionate and highly motivated about their work.

Requirements

  • If you have the below experience and strengths this role could be for you:

Nice to have

  • At least 7+ years of proven experience leading GRC programs and managing compliance certifications and audits (FedRAMP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, IRAP, etc.).
  • At least 3+ years experience as a direct leader, managing a team.
  • Strong knowledge of security frameworks such as NIST SP 800-53, NIST 800-171, ITAR, PCI DSS, SOC2, and FedRAMP.
  • Excellent project management, analytical, and problem-solving skills with keen attention to detail.
  • Self-motivated with a high degree of initiative and ability to work independently.
  • Ability to handle multiple competing priorities and deadlines efficiently.
  • Bachelor's degree in related field preferred or equivalent experience with proven skills

Skills

  • Excellent interpersonal, communication, and organizational skills.
  • High degree of initiative, dependable, and able to work well with limited supervision.
  • Hybrid working model (3 days in the office per week)
  • We're a team dedicated to pushing the boundaries of product innovation and technology
  • Sustainable Growth, Privately Held
  • A stable and cash-flow positive Company since 10 years
  • Snacks and weekly lunches in the office
  • Feel empowered to pursue your goals with improved team collaboration and increased creativity/productivity
  • Unlock and unleash your full professional potential with our exceptional training and career development program
  • Regular social events, competitive outings, team running events, and musical activities,
  • Comparably recognized Ivalua for the following ( https://www.comparably.com/companies/ivalua ):

Compensation

  • The compensation range for this position reflects the cost of labor across our US locations and is based upon careful and continual market research.

Benefits

  • United by our values we embrace diversity and equity in the broadest possible sense to create an inclusive workplace.

Company info

  • We provide peace of mind and assurance of protection and safety to our customers.
  • Collaborate closely with Sales, Marketing, and Customer Success teams to effectively communicate Ivalua's security posture to prospects and customers.

This listing is sourced directly from Ivalua's careers page and normalized into a canonical job model.