SHEIN

SHEIN

GRC Risk Manager

Los Angeles

Sponsorship not specified$108k-$180kDetected 61 days ago
ExpressCybersecurityComplianceCommunicationProblem SolvingOrganizational SkillsCISSP

About the role

  • SHEIN Global Security & Risk Management is a global security organization that oversees security infrastructure, risk management, data privacy, governance and regulatory compliance across SHEIN's global footprint.
  • It is composed of a team of security professionals, innovators and thought leaders that have had decades of global security experience, led large scale transformations, and served in Fortune 500 executive roles.
  • Here, innovation isn't simply about protecting and defending our company.

Responsibilities

  • Develop, implement, mature, and champion risk management processes and concepts.
  • Manage the risk register and define and report key risk metrics to management on a regular basis.
  • Work closely with technology and legal partners and business units to ensure appropriate security and data protection requirements are incorporated into third-party engagements.
  • Maintain a current and comprehensive understanding of relevant industry standards to incorporate into the risk management strategy, framework, and program.
  • Support integration and maturation of policy, compliance, and risk frameworks.
  • Relevant security certifications, such as CISSP, CISM, CISA, ISO 27001 Lead Auditor are highly desired.

Requirements

  • A minimum of 7 years of experience in information security risk management, including business impact analysis, risk assessment and treatment, risk metrics and trend analysis.
  • Possess a bachelor's degree or higher in the field of information security, engineering, computer science or equivalent advance technology field of study.
  • Strong knowledge of security and data privacy standards and regulations such as ISO 27k, NIST, CIS, GDPR, CCPA, PCI DSS.
  • Experience with deploying GRC tools is desirable.
  • Strong written and verbal communication skills, with the ability to translate complex and technical issues to all levels of personnel.

Skills

  • Deploy the risk management framework, processes, and tools to conduct risk assessments effectively and consistently.
  • Practical knowledge and experience working with threat modeling frameworks such as STRIDE, MITRE ATT&CK, OCTAVE is desirable.
  • Strong analytical and problem-solving skills.

Compensation

  • $108k-$180k

This listing is sourced directly from SHEIN's careers page and normalized into a canonical job model.