GRC Risk Manager
About the Company
SHEIN Technology is a U.S. technology company and a leading global online retailer. Founded in 2012, SHEIN operates in Guangzhou, Los Angeles, Singapore, and other key markets, reaching consumers across more than 150 countries and regions. The company delivers over 6,000 new fashion, beauty, and lifestyle products daily, with more than 600,000 items available. SHEIN’s mission is to help people express their individuality through accessible and affordable trends.
About the Role
SHEIN Global Security & Risk Management is a global security organization overseeing security infrastructure, risk management, data privacy, governance, and regulatory compliance. The GRC Risk Manager will implement and maintain the risk management framework and program, working with technology, legal, and business partners to meet global risk management needs. This role requires collaboration with development, engineering, and operations teams to identify, articulate, prioritize, manage, and monitor security risks.
Responsibilities
- Develop, implement, mature, and champion risk management processes and concepts.
- Deploy the risk management framework, processes, and tools to conduct risk assessments effectively and consistently.
- Manage the risk register and define and report key risk metrics to management on a regular basis.
- Conduct risk assessments of business units, critical processes, and information assets.
- Conduct third-party risk assessments and security reviews of third-party agreements.
- Work closely with technology and legal partners and business units to ensure appropriate security and data protection requirements are incorporated into third-party engagements.
- Prepare risk assessment reports to inform risk treatment decisions.
- Track and monitor remediation and risk management activities.
- Maintain a current and comprehensive understanding of relevant industry standards to incorporate into the risk management strategy, framework, and program.
- Support integration and maturation of policy, compliance, and risk frameworks.
Requirements
- A minimum of 7 years of experience in information security risk management, including business impact analysis, risk assessment and treatment, risk metrics, and trend analysis.
- Bachelor’s degree or higher in information security, engineering, computer science, or an equivalent advanced technology field of study.
- Relevant security certifications, such as CISSP, CISM, CISA, or ISO 27001 Lead Auditor, are highly desired.
- Strong knowledge of security and data privacy standards and regulations such as ISO 27k, NIST, CIS, GDPR, CCPA, and PCI DSS.
- Team management experience, including setting and aligning team and individual goals, providing feedback, and fostering collaboration.
- Experience developing and deploying risk management frameworks and programs, preferably in an e-commerce or technology-related industry with international exposure.
- Experience with deploying GRC tools is desirable.
- Practical knowledge and experience working with threat modeling frameworks such as STRIDE, MITRE ATT&CK, or OCTAVE is desirable.
- Strong analytical and problem-solving skills.
- Strong written and verbal communication skills, with the ability to translate complex technical issues to all levels of personnel.
- Detail-oriented and highly organized, with the ability to thrive in a fast-paced environment and prioritize accordingly.
- High level of personal integrity, with the ability to handle confidential matters professionally and exude appropriate judgment and maturity.
Benefits
- Bonus and RSU eligibility.
- Healthcare (medical, dental, vision, prescription drugs).
- Health Savings Account with employer funding.
- Flexible Spending Accounts (Healthcare and Dependent Care).
- Company-paid basic life/AD&D insurance.
- Company-paid short-term and long-term disability.
- Voluntary benefit offerings (Voluntary Life/AD&D, Hospital Indemnity, Critical Illness, and Accident).
- Employee Assistance Program.
- Business Travel Accident Insurance.
- 401(k) Savings Plan with discretionary company match and access to a financial advisor.
- Paid vacation, holidays, floating holiday, and sick days.
- Employee discounts.
- Free weekly catered lunch.
- Dog-friendly office (select locations).
- Free gym access (select locations).
- Free swag giveaways.
- Annual holiday party and invitations to pop-ups and other company events.
- Complimentary daily office snacks and beverages.
Pay
$108,000 USD - $180,000 USD