- Company Name
- RemoteHunter
- Job Title
- Security GRC Program Manager
- Job Description
-
**Job Title:**
Security GRC Program Manager
**Role Summary:**
Lead the design, execution, and continuous improvement of security governance, risk, and compliance (GRC) programs that protect sensitive estate‑planning data. Own customer trust initiatives, oversee SOC 2 Type II audits, manage DDQ/RFP responses, conduct vendor security assessments, and collaborate with sales, legal, and product teams to embed security into all customer engagements and product launches.
**Expectations:**
- Minimum 5 years technical or security experience with a customer‑facing focus;
- Minimum 3 years program management, trust, or DDQ/RFP leadership in a technology or regulated environment;
- Demonstrated success establishing and operating SOC 2, vendor risk, and contractual security controls;
- Ability to prioritize, meet tight deadlines, and communicate complex security concepts to diverse stakeholders.
**Key Responsibilities:**
- Own and streamline DDQ/RFP processes, coordinating cross‑functional responses.
- Lead SOC 2 Type II audit preparation, evidence collection, and remediation plans.
- Conduct third‑party vendor security assessments and integrate findings into risk management.
- Implement and manage tools that enhance DDQ, audit, and compliance workflows.
- Develop security narratives and reviews for new product features to support go‑to‑market.
- Negotiate and review security, privacy, and compliance clauses in customer contracts in partnership with Legal.
- Build and maintain Trust Center integrations and publicly available security documentation.
- Produce compliance artifacts (whitepapers, certifications) for customer distribution.
**Required Skills:**
- Advanced knowledge of information security frameworks, risk, threat management, and regulatory compliance (e.g., SOC 2, ISO 27001, GDPR, CCPA).
- Program management expertise: project planning, process design, KPI monitoring, and stakeholder communication.
- Strong analytical, negotiation, and documentation skills.
- Proficiency with GRC platforms, audit tools, and vendor risk frameworks.
- Ability to translate technical security requirements into business‑ready language.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent experience).
- Relevant security certifications (CISSP, CISM, CISA, CRISC, or equivalent) strongly preferred.