Job Description
Responsibilities
- Lead GRC automation: Transform compliance requirements and policies into automated controls (Compliance as Code), reducing reliance on manual evidence collection.
- Implement AI in governance: Explore and apply AI solutions to optimize GRC processes, such as risk analysis, vulnerability mapping, and responses to security questionnaires.
- Develop and maintain technical controls: Work closely with Engineering teams to ensure frameworks such as ISO 27001, NIST, and SOC 2 are implemented via automation in the CI/CD pipeline.
- Manage risks with a data‑driven approach: Conduct security risk assessments using real data and telemetry, moving beyond subjective analysis.
- Build automated indicators: Create technical and operational security dashboards that reflect compliance in real time, using APIs and data tools.
- Technical interface with audit: Orchestrate internal and external audit deliverables through system...