Source description
About the role
A minimum of 5 years of related experience in GRC, security compliance, or risk management roles with a Bachelor’s degree; or 3 years and a Master’s degree; or equivalent work experience.
Complete knowledge and full understanding of relevant security frameworks and standards (e.g., NIST CSF, SOC 2, ISO 27001, ISO 42001) and data privacy regulations (GLBA, GDPR, CCPA).
Relevant industry certifications: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Artificial Intelligence Governance Professional (AIGP), or equivalent.
Sophisticated analytical and problem-solving skills, with the ability to assess diverse, unusual, and complex security issues and develop effective solutions independently.
Strong communication and interpersonal skills, with a proven ability to persuade differing audiences and advise senior stakeholders on difficult compliance matters.
Familiarity with GRC technologies (i.e., Vanta, Drata, OneTrust, etc.), risk assessment tools, and practices specific to maintaining data integrity and confidentiality in the financial services or appraisal management industry.
Detail-oriented focus on accuracy and thoroughness in documentation, reporting, and policy formulation.
Commitment to maintaining the highest standards of confidentiality, integrity, and professionalism.
Capacity to understand legacy and progressive technology and security controls along with respective risks. Working knowledge of technologies such as cloud computing, DevOps, and application security is required.
Advanced proficiency in utilizing spreadsheets for comprehensive data analysis, audit metric tracking, and complex compliance reporting.
More at Clear Capital
