
Program Manager, Security GRC
Responsible for representing the Security team in audit engagements, maintaining audit evidence for standards like SOC 2, PCI DSS, and SOX, performing security risk and control assessments against frameworks (e.g., ISO 2700x, NIST, COBIT), and supporting GRC program initiatives such as policy writing, training, and third-party risk assessments. Requires 6+ years in Security GRC or technology compliance and experience with global regulatory requirements.