- Company Name
- Hyundai Capital America
- Job Title
- Cybersecurity GRC Specialist
- Job Description
-
**Job Title**
Cybersecurity Governance, Risk & Compliance (GRC) Specialist
**Role Summary**
Functions as the second line of defense, establishing, enforcing, and monitoring cybersecurity policies, governance frameworks, and regulatory compliance across the organization’s IT and business systems.
**Expectations**
- Lead governance and risk management initiatives within a financial services environment.
- Align cybersecurity strategies with business objectives and security standards.
- Ensure adherence to industry regulations and internal controls.
**Key Responsibilities**
1. Develop, maintain, and enforce security policies, standards, and guidelines.
2. Create and manage a Cybersecurity Risk Register, including risk assessments, impact analyses, and remediation tracking.
3. Conduct Global Integrated Security Framework (GSIF) assessments to validate ISO 27001 compliance.
4. Collaborate with Cybersecurity Risk Management, Engineering Operations, and IT to embed best practices into projects and deployments.
5. Build metrics and dashboards; provide senior‑management reporting on risk status, compliance health, and performance indicators.
6. Automate governance tools to monitor the Risk Register and compliance status organization‑wide.
7. Communicate complex security concepts to business leaders and technical teams.
**Required Skills**
- 5–7 years of progressive experience in cybersecurity governance, risk management, or compliance in financial services.
- Deep knowledge of cybersecurity risk frameworks (ISO 27001/2, ISO 31000, NIST SPs 800‑12/30/37/39/53/150/161).
- Proficiency with IT general controls: asset classification, vulnerability & threat analysis, risk treatment, audit controls, vendor risk management.
- Understanding of regulatory requirements: CCPA, GLBA, NYDFS Cybersecurity Regulation, PCI‑DSS, FFIEC, SOX.
- Strong communication and stakeholder‑management skills.
**Required Education & Certifications**
- Bachelor’s degree in Cybersecurity, Information Security, Risk Management, or related field (Master’s a plus).
- Certifications strongly desired: CISSP, CISM, CRISC, CGEIT, CISA, ITIL.