Security Governance, Risk, and Compliance (GRC) Engineer

Saicon Consultants Inc

San Jose, CA

JOB DETAILS
SKILLS
Analysis Skills, Artificial Intelligence (AI), Artificial Intelligence (AI) Agents, Automation, Best Practices, CISSP - Certified Information Systems Security Professional, Communication Skills, Communications Security (COMSEC), Computer Security, Cross-Functional, Detail Oriented, Establish Priorities, ISO (International Organization for Standardization), Industry Standards, Information/Data Security (InfoSec), Interpersonal Skills, Leadership, Metrics, Operations Management, Order Delivery, Organizational Skills, Outsourcing, Performance Metrics, Policy Development, Process Development, Process Improvement, Program Planning, Project/Program Management, Regulatory Compliance, Risk, Risk Analysis, Risk Management, Sarbanes-Oxley Act (SOX), Security Analysis, Security Attacks, Security Monitoring, Service Level Agreement (SLA), Software Agents, Standards Development, Standards Organizations, Team Building, Team Lead/Manager, Treatment Plan
LOCATION
San Jose, CA
POSTED
1 day ago

Job Descriotion:
Reporting to the Director Information Security, Governance, Risk, and Compliance, the GRC Engineer will contribute to the development and operational execution of the program. This role will focus activities in Data Governance, AI Governance, and Security Risk Management.

MUST HAVE SKILLS:

  • Data Governance, AI development and Governance, Security Risk Management

Responsibilities

  • Support the GRC operating model and the service-oriented customer engagement model.
  • Provide Information Security Data Governance program expertise and drive the operational delivery of the program.
  • Provide AI Governance and development expertise to business units and key stakeholders.
  • Utilize current tools to design, build, and enhance team processes using AI agents and intelligent workflows.
  • Maintain AI roadmaps and related communications to security leadership.
  • Provide Information Security Risk Management support and assist with the operational delivery of the program.
  • Develop and present regular operational and executive level metrics and reporting.
  • Perform risk assessments to address security threats, changes to systems and/or applications, process improvement initiatives, supplier assessments (including downstream outsourcers) and other requests from the business.
  • Collaborate with various operational and business teams to complete assessments, develop treatment plans, and drive remediation items to closure. Maintain accurate reporting of remediation activities to bring appropriate visibility to stakeholders and leadership.
  • Monitor the security risk profiles and events of our suppliers to objectively determine high risk suppliers that require additional review and treatment plans.
  • Act as security governance and risk management “ambassador” to internal customers.

Accountable for

  • Aligning governance and operational activities to industry best practices and current standards, as defined by internal policies and international standards bodies
  • Develop processes to utilize AI functionality to improve and enhance efficiencies, without sacrificing quality and accuracy.
  • Build new AI-driven internal processes to assist with prioritizing and risk-scoring activities.
  • The use of defined risk methodologies and best practices to perform Security assessments. Responsible for the planning, scoping, tracking, and execution of these assessments.
  • Driving remediation activities from identification, treatment plan, remediation, and closure. Hold owners accountable to delivery of remediation solution within the agreed upon/reasonable SLA.
  • Operationalization of a metrics and reporting function to continually report on meaningful security, risk and compliance metrics for operational and executive management. Support the automation of KRIs and KPI reporting that align with operational/business risk areas and corporate risk.

Qualifications

  • Competent industry certifications, and extra points for AI-related certifications.
  • Candidate must have at least 7 years professional experience in governance, risk and compliance and/or information security and risk management.
  • Functional knowledge of the CISSP security domains and information security industry standard and best practices.
  • Functional knowledge of applicable security regulatory and compliance requirements (EU AI Act, SOX, GDPR). Functional knowledge of ISMS governance models and analysis of certification reports (i.e. ISO 42001 & 27001, SOC, CAIQ), information security roles, security controls.
  • Ability to communicate information security methodologies and concepts to business units and IT teams.
  • Ability to independently drive program areas and cross-functional teams to deliver high quality results according to well-defined planning.
  • Strong interpersonal skills and ability to work effectively with diverse and globally distributed teams.
  • Strong attention to detail, project management and organizational skills.
  • Self-starter with the ability to effectively manage independent workloads asynchronously with stakeholders across multiple time zones.
  • Define and communicate program and activity plans and roadmaps, and collaborate effectively with all business and IT groups to achieve goals.

About the Company

S

Saicon Consultants Inc