- Company Name
- Vertex Elite LLC
- Job Title
- Sr. Security Governance, Risk, & Compliance
- Job Description
-
**Job Title**
Senior Security Governance, Risk & Compliance
**Role Summary**
Leads the organization’s security governance, risk management, and compliance program. Conducts security control assessments, oversees IT governance and contract management, and ensures adherence to industry frameworks and regulatory requirements across diverse technology environments.
**Expectations**
- 10+ years of information security experience with strong technical expertise.
- 5+ years performing security control assessments, IT governance, and contract management.
- Proven track record in audit and risk assessment environments.
- Ability to apply multiple security frameworks and standards to complex, multi‑disciplinary technology stacks.
**Key Responsibilities**
- Perform and document security control assessments against frameworks such as NIST‑CSF, NIST 800‑53/171, ISO 27001/27002, HIPAA, PCI‑DSS, NERC CIP, and CIS Controls.
- Develop, maintain, and enforce security governance policies, procedures, and risk management processes.
- Lead internal and third‑party audits, identify gaps, and drive remediation plans.
- Manage compliance reporting and regulatory liaison activities.
- Conduct risk assessments, threat modeling, and impact analyses for new and existing systems.
- Oversee contract security reviews, vendor risk assessments, and third‑party security posture evaluations.
- Provide guidance to engineering, operations, and business teams on secure design, implementation, and integration of technology solutions.
- Monitor emerging security regulations and standards; recommend updates to control frameworks.
**Required Skills**
- Deep knowledge of security frameworks: NIST‑CSF, NIST 800‑30/53/171, ISO 27001/27002/27005, HIPAA, PCI‑DSS, NERC CIP, CIS 20.
- Experience with risk assessment methodologies (e.g., FAIR, NIST SP‑800‑30).
- Proficiency in audit processes, control testing, and remediation tracking.
- Strong technical background in software development, systems engineering, and technology evaluation.
- Excellent analytical, written, and verbal communication skills; ability to influence senior stakeholders.
- Project management and contract management expertise.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, Information Technology, or related field (or equivalent experience).
- Preferred certifications: CISSP, CISM, CRISC, CISA, ISO 27001 Lead Implementer/Lead Auditor, or equivalent.