GRC Risk Principal
LevelBlue · United States · 3 wk ago
RemoteRemoteEducationFull-time
About the role
The LevelBlue Office of Security and Trust team is expanding to include an experienced and motivated professional to lead and manage the Governance, Risk, and Compliance (GRC) program. This role will be responsible for navigating the opportunities and complexities of an international business experiencing organic and inorganic growth.
Responsibilities
- Provide expert leadership in all matters pertaining to governance, risk management, and compliance, ensuring risk programs are successfully executed to strengthen and sustain trust with LevelBlue customers, staff, and partners.
- Design and drive the integrated risk management strategy, framework, tools, and processes.
- Oversee, manage, and communicate risks.
- Govern, optimize, and monitor policies and policy performance.
- Strengthen cross-functional security governance model and effectively run various governance committees to ensure stakeholders align on the risk acceptance level, and priorities to manage risks.
- Manage, assess, and communicate risks with a variety of audiences to strengthen the secure by design culture.
- Set the direction and mature the security awareness and training program.
- Establish an ongoing awareness and training program to strengthen security culture.
- Enhance GRC dashboard and reporting.
- Continuously analyze risk control effectiveness of the organization, overall security resilience, risk posture improvement, and maturity growth.
- Work closely with business unit leaders and external entities as needed to support Enterprise Risk Management.
Qualifications
- A minimum of 6 years of security experience, with a combined background of technology and compliance.
- A minimum of 3 years in GRC leadership positions, with experience managing any Security Governance, Risks, and Compliance functions or Internal Audit function.
- Extensive experience in risk management, vendor and client security management.
- Familiarity with cyber security and risk management frameworks, with experience in implementing and applying frameworks into actionable tasks.
- Experience managing, and working with, global teams.
- Experience in mergers, acquisitions, and divestitures.
- Experienced in management and operations, with a proven record of streamlining processes to boost agility, efficiency, and growth while ensuring security.
- Excellent communication and presentation abilities, enabling clear explanation of complex risk matters to executive management, as well as effective interaction with technology, development, and business partners.
- Demonstrated expertise in relationship management, team development, and facilitation.
- Experience in a complex matrix organization supporting both operational and transformational initiatives for business units, while focusing on Security & Trust goals.
- Demonstrated capability for strategic thinking, combined with a strong sense of urgency and meticulous attention to detail.
- Strong team player that collaborates well with others to solve problems and actively incorporates input from various sources.
- Independent and creative thinker with the willingness to "step outside the box" and take reasonable, calculated risks.
Skills
- Teamwork, collaboration, and communication: Expressing ideas effectively through speaking, writing, visuals, and non-verbal cues, and listening to understand others.
- Problem solving framework: Simplifying the complex, high quantity, and sometimes contradictory information to effectively drive stronger business outcomes.
- Own the outcomes: Empowered as a leader at LevelBlue, identify key milestones and navigate the pathways for achievement.
Qualifications
- Minimum of 6 years of security experience, with a combined background of technology and compliance.
- Minimum of 3 years in GRC leadership positions, with experience managing any Security Governance, Risks, and Compliance functions or Internal Audit function.
- Extensive experience in risk management, vendor and client security management.
- Familiarity with cyber security and risk management frameworks, with experience in implementing and applying frameworks into actionable tasks.
- Experience managing, and working with, global teams.
- Experience in mergers, acquisitions, and divestitures.
- Experienced in management and operations, with a proven record of streamlining processes to boost agility, efficiency, and growth while ensuring security.
- Excellent communication and presentation abilities, enabling clear explanation of complex risk matters to executive management, as well as effective interaction with technology, development, and business partners.
- Demonstrated expertise in relationship management, team development, and facilitation.
- Experience in a complex matrix organization supporting both operational and transformational initiatives for business units, while focusing on Security & Trust goals.
- Demonstrated capability for strategic thinking, combined with a strong sense of urgency and meticulous attention to detail.
- Strong team player that collaborates well with others to solve problems and actively incorporates input from various sources.
- Independent and creative thinker with the willingness to "step outside the box" and take reasonable, calculated risks.