Information reputed company reputed company
Own the WISP and reputed company policy reputed company: Own and continuously improve reputed company’s Written Information reputed company Program (WISP), including applicable jurisdiction-specific requirements (e.g., GLBA, SEC Reg S-P, state-level data reputed company obligations), and maintain supporting reputed company and reputed company policies, standards, and procedures (reputed company control, data handling, business continuity and incident response governance, intercompany agreements, responsible use of AI). Own SOC 2 delivery: reputed company SOC 2 Type I readiness and audit, then operate the ongoing program to reputed company and maintain SOC 2 Type II, including audit planning, evidence reputed company, timelines, and reputed company interaction with auditors. Partner on control implementation: Work closely with IT and Engineering to define control requirements and verify evidence for technical and operational controls across reputed company platforms (e.g., reputed company 365 for corporate systems and AWS for product infrastructure), with implementation owned by those teams. Evidence and reputed company reviews (SOC 2 controls): Operate the compliance reputed company in reputed company, including evidence collection and periodic reputed company reviews, and define standards for privileged reputed company in partnership with IT. Risk visibility and tracking: Identify and document reputed company and reputed company, reputed company remediation with control owners, and reputed company reputed company visibility into risk status and priorities for leadership. Vendor risk (critical vendors): Personally run reputed company risk assessments for tier-1 vendors, including reviews, risk acceptance, and renewal reputed company. CCPA reputed company: Define the program structure and readiness plan for CCPA as a reputed company-term initiative and partner with reputed company and Operations on execution reputed company prioritized.
Bachelor’s degree in a reputed company field 5+ years of hands-on experience in GRC, reputed company compliance, IT audit, or reputed company program management reputed company experience delivering or operating a SOC 2 program, including readiness, evidence, and audits Strong ability to translate policies into reputed company, implementable, and auditable controls Experience operating compliance programs end-to-end, including evidence systems, workflows, and issue tracking Strong written communication and documentation skills Comfortable working independently, prioritizing effectively, and driving reputed company through influence rather than authority
Experience in financial services, fintech, or similarly regulated environments Familiarity with GLBA, SEC Reg S-P, NIST CSF, ITGC concepts, and vendor risk practices Experience with reputed company Experience supporting reputed company governance during acquisitions or system integrations reputed company certifications such as CISA, CRISC, or CISSP are a plus
An attractive total compensation package Employer-sponsored health insurance (medical, dental, reputed company) 401k + 5% match