The Senior Cyber GRC Specialist is an individual contributor responsible for assessing and managing cybersecurity risks arising from third-party relationships and deviations from approved security policies and standards. The role serves as a technical risk advisor across Security, Technology, Procurement, Legal, Privacy, and business teams.
This position requires practical cybersecurity knowledge to review technical controls, ask appropriate follow-up questions, challenge incomplete or unsupported responses, evaluate compensating controls, and translate technical risk into clear business impact. The role assesses risk and provides recommendations; formal risk acceptance remains with the authorized business and security approvers.
•Perform risk-based cybersecurity assessments of vendors, suppliers, SaaS providers, cloud service providers, and other third parties during onboarding, reassessment, renewal, and material service changes.
•Review security questionnaires, independent assurance reports, certifications, penetration test summaries, architecture information, vulnerability management practices, incident response capabilities, and other relevant security evidence.
•Engage vendor and internal technical teams to clarify security architecture, control design, identified gaps, remediation commitments, and residual risk.
•Identify and document third-party cyber risks, determine risk severity, recommend risk treatment, and track agreed remediation actions through closure.
•Apply assessment depth based on service criticality, data sensitivity, connectivity, hosting model, regulatory exposure, and potential business impact.
•Administer the security exception management lifecycle, including intake, completeness review, risk assessment, routing, approval coordination, expiration, renewal, closure, and reporting.
•Evaluate exception requests against applicable security policies and standards, including the business justification, scope, duration, technical exposure, compensating controls, remediation plan, and residual risk.
•Challenge exception submissions when risks are not adequately understood, supporting evidence is insufficient, or proposed compensating controls do not reasonably reduce exposure.
•Partner with Security Architecture, Cloud Security, Application Security, Infrastructure, Identity and Access Management, Vulnerability Management, and other subject matter experts when specialized validation is required.
•Prepare clear risk recommendations for authorized approvers and governance forums while maintaining appropriate separation between risk assessment, risk ownership, and risk acceptance.
•Maintain accurate risk records and supporting evidence in the designated governance, risk, and compliance platform.
•Develop and report metrics on assessment volume, risk severity, remediation status, overdue actions, exception aging, renewals, expirations, and risk concentrations.
•Identify recurring control gaps and trends across vendors and exceptions and recommend improvements to policies, standards, assessment criteria, contract requirements, and governance processes.
•Support audits, certifications, regulatory inquiries, and customer assurance activities related to third-party cyber risk and security exception management.
•Contribute to continuous improvement of risk methodologies, procedures, templates, decision criteria, and stakeholder guidance.
•This role would report to the Senior Manager, Cyber Governance & Risk Management.
What We're Looking For:
•5 -10 years of experience in cybersecurity, information security risk, technology risk, third-party risk management, security architecture, security engineering, or a related discipline.
•Demonstrated experience performing technical security assessments of vendors, cloud services, applications, infrastructure, or enterprise technology environments.
•Experience evaluating policy or control exceptions, compensating controls, remediation plans, and residual risk is strongly preferred.
•Working knowledge of identity and access management, multifactor authentication, privileged access, cloud security, network security, vulnerability management, endpoint protection, application security, encryption, logging and monitoring, incident response, resilience, and data protection.
•Ability to interpret common security evidence, including SOC reports, ISO 27001 certifications, penetration test summaries, vulnerability information, security architecture documentation, and control descriptions.
•Working knowledge of recognized cybersecurity and risk frameworks, such as ISO 27001, NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, and TISAX.
•Strong analytical judgment with the ability to distinguish administrative gaps from material technical risk and to evaluate whether proposed controls adequately reduce exposure.
•Ability to communicate clearly with technical teams, vendors, business owners, procurement, legal, privacy, auditors, and senior stakeholders.
•Strong documentation, organization, and follow-through skills, with the ability to manage multiple assessments, exceptions, and remediation actions concurrently.
•Ability to operate independently, escalate material concerns appropriately, and provide objective, evidence-based risk recommendations.