Abnormal Security
Abnormal Security
Abnormal Security dezvoltă soluții cloud-native de securitate a e-mailului pentru companii. Tehnologia sa ajută la detectarea și prevenirea amenințărilor, inclusiv a phishingului, programelor malware, ransomware-ului, ingineriei sociale și preluării conturilor, iar produsele sale se concentrează pe protecția e-mailului de afaceri și detectarea atacurilor de phishing. Activând în sectorul securității cibernetice, compania reunește o echipă de peste 500 de angajați pentru a ajuta organizațiile să își securizeze comunicațiile corporative prin e-mail.

Trust Analyst II - GRC at Abnormal Security (Remote, United States)

Lead governance, policy, risk management, internal controls, and compliance readiness for Abnormal Security’s cybersecurity SaaS programs. Support certifications, audits, remediation, and governance operations across AI, data, and security domains.

Descriere

  • Lead AI, data, security, and related governance committees by setting agendas, coordinating stakeholders, and closing decisions.
  • Manage the policy lifecycle, including drafting, revisions, maintenance, stakeholder review, acknowledgments, and Policy Center administration.
  • Run risk management operations covering the risk register, assessments, exceptions, renewal reviews, documentation, and the 12-month exception cap.
  • Track regulatory and industry developments and advise leadership on program strategy and potential impact.
  • Align program execution with strategy while delivering GRC milestones on schedule and to a high standard.
  • Improve internal control effectiveness through monitoring, control enhancements, and guidance on control design and operation.
  • Conduct compliance readiness assessments and provide senior leaders and business partners with updates, recommendations, and roadmaps.
  • Educate and train process, control, and risk owners on control requirements, documentation, and risk responsibilities.
  • Define and report key risk indicators and key performance indicators.
  • Identify policy and process gaps or conflicts and develop solutions with business partners.
  • Lead remediation and risk mitigation through root cause analysis, action-plan development and tracking, and recurring risk analysis.
  • Design and manage program operations and the technology that supports them.
  • Contribute to ad hoc projects as needed.
  • Report control testing, audit, risk assessment, issue management, program health, achievements, and risks to project teams, partners, and senior management.

Cerințe

  • Bring 4–7 years of experience in cybersecurity, technology risk, GRC, and/or technical compliance.
  • Have at least 2 years of experience implementing and maintaining ISO 27001.
  • Have led at least one complete ISO 27001 certification cycle, including the 2022 revision, from initiation through completion.
  • Demonstrate project management experience across concurrent compliance initiatives, cross-functional teams, Agile or Waterfall methods, and tools such as ServiceNow.
  • Have owned or facilitated cross-functional AI, data, or security governance programs or committees.
  • Understand security concepts, ISMS implementation and maintenance, control mapping across frameworks, and continuous control monitoring and automation.
  • Have implemented and managed ISO 27001 and ISO 27701 programs, including Statements of Applicability, risk treatment plans, risk acceptance criteria, internal audit programs, and management reviews.
  • Have worked with external auditors and managed internal stakeholders.
  • Have experience with audit automation and continuous control monitoring tools.
  • Can coordinate multiple stakeholders and vendors while sustaining project momentum.
  • Bachelor’s degree or equivalent military experience is preferred.
  • ISO 27001, ISO 27701, or ISO 42001 Lead Auditor Certification is preferred.
  • CRISC, CISSP, CPA, CISA, PMP, or CISM certification is preferred.
  • Experience with NIST CSF, NIST SP 800-53/171, or other control frameworks is preferred.
  • Familiarity with AI governance frameworks such as ISO/IEC 42001 and NIST AI RMF is preferred.
  • Experience in a technology, SaaS/cloud, or regulated public company is preferred.
  • Two or more years of Big Four experience is preferred.

Beneficii

  • Bonus or incentive compensation may be available.
  • Equity may be available.
  • A comprehensive benefits package is offered.
  • Pre-employment checks follow applicable legislation and Abnormal AI’s security and privacy standards.

Locuri de muncă similare

Kreato Global | BPO and Language Solutions

Remote English-Spanish OPI/VRI Interpreter

Kreato Global | BPO and Language Solutions

Interpret remotely between English- and Spanish-speaking people in medical, financial, social service, and customer care settings. Provide language support for Kreato Global across Latin America.

Deschide
RecruitGo

Remote Executive Assistant, Outreach and Marketing — Philippines

RecruitGo

Handle administrative support, CRM, outreach, and marketing for RecruitGo, an Employer of Record serving global clients with talent from emerging markets. Support two UK-facing clients with day-to-day administration and creative campaigns.

Deschide