This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Here at Virtru you’ll help build a cutting edge security compliance program aligned with FedRAMP, SOC 2, PCI, HIPAA, GDPR, and just about any other security/privacy framework you can think of, whilst getting your hands on some of today’s most important tools and tech like Kubernetes, GCP, AWS, Terraform. We put a high value on input from everyone on our team. Your voice will have a significant impact. With a constantly growing customer base, there is no shortage of challenging and exciting scaling/optimization work to ensure that we can provide the most secure and performant service. As a GRC Analyst at Virtru, you will be the primary point of contact for compliance-related inquiries. You will lead and manage the organization's efforts to achieve and maintain CMMC compliance, by conducting gap analyses and developing a roadmap to address compliance requirements. You will also play a vital role in supporting our existing FedRAMP, SOC2, and PCI DSS compliance.
Job Responsibility:
Manage and implement complex controls frameworks for large systems, consisting of Cloud infrastructure and Software as a Service (SaaS) services (GCP, AWS, GitHub, Okta, etc)
Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services
Conduct risk assessments across business units and processes. Identify risk findings and recommend remediation and risk mitigation strategies
Assist or implement automated controls to support risk mitigation efforts across various business units with stakeholders
Incorporate CMMC certification into Virtru’s slate of compliance assessments and ongoing monitoring activities (FedRAMP, SOC 2, PCI)
Facilitate the third-party vendor on-boarding and annual review process by evaluating the security of current and prospective partners
Participate in incident response (IR) activities, providing risk analysis and remediation support as needed
Enhance the team with your individualism, spirit, and love of learning
Requirements:
Minimum of 5+ years of information security, IT audit and/or IT Risk Management, or GRC Analyst/Engineer experience
Deep understanding of at least few of the following: CMMC, NIST 800-53 & 800-171, FedRAMP, SOC 2, PCI, and/or other global privacy compliance frameworks
Technical acumen. Strong understanding of modern cloud technologies (AWS, GCP, Azure, etc.) and familiarity with GRC tools (Hyperproof, Vanta, Drata, etc) and SIEM tools (Datadog, Splunk)
You’re a relationship builder and have worked with both business and technical risk and understand how to translate risk to various levels of the organization
Have experience training and coaching teams to become better security and privacy practitioners
Like working on an autonomous agile team
Ability to resolve conflicts and drive issues to completion
Work independently with little or no supervision while maintaining a high level of efficiency
Hands on experience deploying and managing vulnerability scanning/cloud security posture management tools (Wiz, Prismacloud, etc.) to meet security compliance requirements
Real-world IR experience participating on security On-Call teams
Basic knowledge of scripting languages like Bash, Python, or Javascript to automate manual tasks
Familiarity with GitOps and Infrastructure-as-Code concepts
Nice to have:
Thinking outside of the box to respectfully challenge your teammates and managers in the pursuit of excellence
Strong sense of urgency with an action-oriented mindset
Able to collaborate and adapt to shifting priorities as business needs evolve
Comfortable with asynchronous communication including slack, email, zoom, etc.
What we offer:
A Flexible PTO policy
A $1,500 annual Learning & Development Stipend
Frequent company-sponsored team celebrations
Access to an Employee Assistance Program
Access to Headspace, a mental health app
A flat 3% contribution to your retirement account
A high degree of flexibility
Competitive compensation
Generous parental, medical, and bereavement policies
Welcome to CrawlJobs.com – Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.
We use cookies to enhance your experience, analyze traffic, and serve personalized content. By clicking “Accept”, you agree to the use of cookies.