SHEIN
GRC Risk Manager
Los Angeles
Sponsorship not specified$108k-$180kDetected 61 days ago
ExpressCybersecurityComplianceCommunicationProblem SolvingOrganizational SkillsCISSP
About the role
- SHEIN Global Security & Risk Management is a global security organization that oversees security infrastructure, risk management, data privacy, governance and regulatory compliance across SHEIN's global footprint.
- It is composed of a team of security professionals, innovators and thought leaders that have had decades of global security experience, led large scale transformations, and served in Fortune 500 executive roles.
- Here, innovation isn't simply about protecting and defending our company.
Responsibilities
- Develop, implement, mature, and champion risk management processes and concepts.
- Manage the risk register and define and report key risk metrics to management on a regular basis.
- Work closely with technology and legal partners and business units to ensure appropriate security and data protection requirements are incorporated into third-party engagements.
- Maintain a current and comprehensive understanding of relevant industry standards to incorporate into the risk management strategy, framework, and program.
- Support integration and maturation of policy, compliance, and risk frameworks.
- Relevant security certifications, such as CISSP, CISM, CISA, ISO 27001 Lead Auditor are highly desired.
Requirements
- A minimum of 7 years of experience in information security risk management, including business impact analysis, risk assessment and treatment, risk metrics and trend analysis.
- Possess a bachelor's degree or higher in the field of information security, engineering, computer science or equivalent advance technology field of study.
- Strong knowledge of security and data privacy standards and regulations such as ISO 27k, NIST, CIS, GDPR, CCPA, PCI DSS.
- Experience with deploying GRC tools is desirable.
- Strong written and verbal communication skills, with the ability to translate complex and technical issues to all levels of personnel.
Skills
- Deploy the risk management framework, processes, and tools to conduct risk assessments effectively and consistently.
- Practical knowledge and experience working with threat modeling frameworks such as STRIDE, MITRE ATT&CK, OCTAVE is desirable.
- Strong analytical and problem-solving skills.
Compensation
- $108k-$180k
This listing is sourced directly from SHEIN's careers page and normalized into a canonical job model.