IT Governance, Risk, & Compliance Specialist

iboss
Massachusetts
Full-time

Description

Company Overview iboss is a cloud security company that enables the modern workforce to connect securely and directly to all applications from wherever they work.

Built on a containerized cloud architecture, iboss delivers security capabilities such as SWG, malware defense, RBI, CASB and data loss prevention to all connections via the cloud, instantaneously and at scale.

This eliminates the need for traditional network security appliances, such as VPNs, firewalls and web gateway proxies, which are ineffective at protecting a cloud-first and mobile world.

Leveraging a purpose-built cloud architecture backed by 230+ issued and pending patents and more than 100 points of presence globally, iboss processes over 150 billion transactions daily, blocking 4 billion threats per day.

More than 4,000 global enterprises trust the iboss Cloud Platform to support their modern workforces, including a large number of Fortune 50 companies.

To learn more, visit / At iboss, we believe that exceptional employees are the key to our success. Our teams are hands on, diverse, nimble, and highly empowered to drive excellence.

Be a part of the team that will transform the way cybersecurity is delivered! Job Description The IT Governance, Risk, and Compliance Specialist will play a key role on the iboss team by aligning security initiatives with enterprise programs and business objectives.

In this role, you will be a part of the team responsible for information security assessments of cloud environments, information systems, risk management and security tool configurations to ensure adherence to applicable frameworks, laws, and regulations.

The IT GRC Specialist will make an impact on iboss’ security program and services through experience with various areas including data governance, risk management, metrics, audit, policy, and standards development. Responsibilities

  • Develop and oversee IT compliance and IT Risk strategies, ensuring alignment with regulatory requirements and industry standards
  • Lead the implementation and maintenance of IT governance frameworks, risk, policies, and procedures
  • Design and enforce IT controls to mitigate risks and ensure data security and regulatory compliance
  • Facilitate and support the gathering, reviewing, assembling, and maintaining of internal and external audit evidence and related documentation
  • Conduct thorough risk assessments and provide strategic recommendations for risk management
  • Act as liaison / main of contract with internal and external auditors for regulatory inquiries and compliance related matters.
  • Collaborate with cross-functional teams to integrate compliance requirements
  • Monitor and review regulatory updates and issues relative to pertinent security regulatory requirements.
  • Drive continuous improvement efforts to enhance IT compliance and governance practices.

Skills / Qualifications

  • Bachelor's degree in Computer Science, Information Security, or related field
  • 5+ years of experience in IT compliance, governance, or related roles
  • Working experience with Business continuity plans (BCPs)
  • Expert knowledge on industry specific regulatory requirements and compliance frameworks for cloud providers (FedRAMP / DoD, SOC, ISO, HIPAA, PCI-DSS)
  • Deep understanding of IT governance frameworks and risk management methodologies
  • Prior experience with cloud providers and / or data centers a plus
  • CISA required and other industry certifications such as CISSP, CISM, or equivalent a plus
  • High level of verbal and written communication skills

Benefits :

  • Health, Vision, Dental - open to domestic partners
  • 401K with company match
  • Paid Time Off (PTO)
  • Company paid holidays
  • 30+ days ago
Related jobs
Promoted
Lantheus
Bedford, Massachusetts

Operationalize GRC capability areas including policy and exception management, security awareness and training, third-party risk management, security reviews and audits, enterprise security risk management, compliance management, business continuity, disaster recovery. The Director of Cybersecurity ...

SGA
Boston, Massachusetts

This includes assisting business lines completing security control self-assessments, preparing System Security Plan documentation, conducting analysis of security control deficiencies, and monitoring risk management activities. Assisting peers within the Information Security function with ad hoc ris...

Crowe
Boston, Massachusetts

Crowe uses its deep industry expertise to provide audit services to public and private entities while also helping clients reach their goals with tax, advisory, risk and performance services. Crowe LLP provides equal employment opportunities to all employees and applicants for employment and prohibi...

Ignyte AI
Canton, Massachusetts

Maintain the risk repository to continually identity, prioritize, and mitigate cyber and information security related risk issues. IT, cyber/information security, risk, audit, compliance, with increasing responsibility. Requires the ability to identify risk within complex, interrelated programs; abi...

The Hanover Insurance Group
Worcester, Massachusetts
Remote

The GRC team is responsible for providing oversight and governance of information security risk related activities and to ensure management awareness through transparent reporting of our security risk and compliance posture. Take end to end ownership of information security owned programs and relate...

firstPRO, Inc
Boston, Massachusetts

Collaborating with technology/architect and internal audit team in implementing IT compliance governance/controls where applicable. Leading IT compliance areas such as ITIL (implementation reviews, project assurance etc), privileged user access deficiencies, data sharing, malware protection, monitor...

Liberty Mutual Insurance
Boston, Massachusetts

Our Cybersecurity Governance, Risk, and Compliance (cGRC) organization manages IT compliance and cybersecurity risk supported by an integrated set of products and services that support the lifecycle of our assessment functions. Knowledge and experience working with; cybersecurity controls, IT auditi...

Vitamin T
Boston, Massachusetts
Remote

This allows us to gain efficiencies of scale, create enabling synergies across GRC teams, and be able to more effectively support our core XFN and the Integrity, Security, and Privacy functions within GRC. Ability to align with internal stakeholders on quality scores and feedback. Experience working...

TJX Companies, Inc.
Framingham, Massachusetts

Ability to identify and assesses the severity and potential impact of risks and communicate findings to risk owners in a way that consistently drives objective, fact-based decisions about risk that optimize the trade-off between risk mitigation and business performance. Come join us! We are looking ...

Lantheus
Bedford, Massachusetts

Operationalize GRC capability areas including policy and exception management, security awareness and training, third-party risk management, security reviews and audits, enterprise security risk management, compliance management, business continuity, disaster recovery. The Director of Cybersecurity ...