Sr. Information Security GRC Specialist
Raleigh, North Carolina
BHG Financial
BHG Financial is the original disruptor in business working capital and unsecured consumer loans.Who You Are
You are a motivated IS professional who is passionate about governance, risk, and compliance (GRC). You excel at producing results and have experience in an audited environment. You are an energetic, highly motivated individual, and thrive in a fast-paced environment where you can assist BHG in meeting its compliance requirements and reducing risk to the BHG brands.
What You'll Do
- You will assist in the development, maintenance, and enhancement of the IS GRC Program by collaborating with the overall IS Team as well as multiple BHG stakeholders.
- Serve as a point of contact and subject matter expert for BHG's Business Continuity and Disaster Recovery Program.
- Build relationships with stakeholders, working with them to maintain the BC/DR program to ensure adequate resources and documentation are in place to support recovery efforts.
- Coordinate the resting of BC/DR plans to verify the ability to meet Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).
- Assisting in the development and maintenance of IS policies, standards, and procedures.
- Maintaining and reporting out IS metrics, detailed and board level.
- Supporting security awareness training and activities throughout the organization.
- Assisting in developing enterprise and functional team-specific presentations to promote a security mindset.
- Perform IS risk assessments on strategic initiatives and internal systems.
- Support developing remediation plans for issues and risks, coordinate activities with owners, and track remediation to completion.
- Analyzing third parties for adherence to BHG policies and standards.
- Evaluating risks related to policy and standard exceptions.
- Helping respond to customer or other third-party inquiries related to BHG’s IS program.
- Coordinating audits and information gathering for financial audits, SOC 2 examinations, third-party assessments, etc. while ensuring a timely response.
- Performing control assessments against BHG’s control framework.
- Identifying opportunities for automation and process efficiencies and assisting in the implementation of GRC toolsets.
- Collaborating with other BHG teams such as Enterprise Risk Management (ERM), product, Legal, People Development (PD), etc. to ensure BHG is complying with policies, standards, and regulatory requirements.
- Working with the GRC Team to ensure the BHG stays abreast of new regulatory, legal, compliance, and security requirements.
- Performing other duties as required.
What You'll Need
- At least four (4) years of proven experience in the IS GRC field or a combination of experience in related disciplines.
- Experience in a BC/DR role, with a solid understanding of planning and testing.
- Bachelor’s Degree, ideally in Computer Engineering, Computer Science, or Information Systems Management or equivalent work experience in the field of IS.
- Possess current or working towards relevant certifications (e.g., CISA, CISM, CRISC, etc.).
- Knowledge of compliance requirements such as FFIEC, PCI, SOX, GLBA, CCPA, etc.
- Knowledge of IS frameworks such as SOC 2, NIST, ISO, FISMA, etc.
- Knowledge of IS risk frameworks such as OCTAVE, FAIR, ISACA Risk IT, ISO 27005, NIST 800-30, etc.
- Problem analysis and resolution at both a strategic and functional level.
- The ability to organize and manage multiple priorities.
- Strong documentation skills.
- Excellent interpersonal and communication skills.
- Ability to translate technical requirements to business objectives.
Why You Should Join BHGWe strive to offer amenities, opportunities, events, and programming that support the interests of our teams, while furthering the culture that makes us Great Place to Work® certified. Some of the benefits you can expect when you join BHG include: · 100% coverage of monthly health insurance premiums· Competitive PTO and vacation policies· Company 401(k) plan with employer contributions after one year· On-site gym access and memberships, with personal trainers, and certified nutritionists on staff· Company-sponsored training and certification opportunities· Monthly award ceremonies where top achievers are celebrated and receive additional bonuses· Ongoing volunteer opportunities to give back to the community through our BHG Cares program If you’re ready for a career where you can exercise your passions, be surrounded by co-workers who are relentlessly committed to service, and have a team-player mindset, apply today!
** All Remote employees at BHG Financial are required to work within the United States of America.
BHG Financial is committed to equal treatment and opportunity in all aspects of recruitment, selection, and employment without regard to gender, race, religion, national origin, ethnicity, disability, gender identity/expression, sexual orientation, veteran or military status, or any other category protected under the law. BHG Financial is an equal opportunity employer; committed to a community of inclusion, and an environment free from discrimination, harassment, and retaliation.
#LI-Remote
* Salary range is an estimate based on our salary survey 💰
Tags: Audits Automation CCPA CISA CISM Compliance Computer Science CRISC Finance FinTech FISMA Governance ISACA ISO 27005 NIST Octave Risk assessment Risk management SOC SOC 2
Perks/benefits: Career development Fitness / gym Flex vacation Health care Insurance Startup environment Team events
More jobs like this
Explore more InfoSec/Cybersecurity career opportunities
Find open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Analysis, Cryptography, Digital Forensics and Cyber Security in general, filtered by job title or popular skill, toolset and products used.
- Open Information Security Specialist jobs
- Open Security Operations Analyst jobs
- Open Senior Information Security Analyst jobs
- Open Senior SOC Analyst jobs
- Open Staff Product Security Engineer jobs
- Open Security Operations Engineer jobs
- Open Senior Cybersecurity Engineer jobs
- Open Electronic Warfare Advanced Tactical Trainer jobs
- Open IT Security Engineer jobs
- Open IT Security Analyst jobs
- Open Information System Security Officer (ISSO) jobs
- Open Cyber Security Specialist jobs
- Open Manager Pentest H/F jobs
- Open Head of Information Security jobs
- Open Cyber Hunt SME jobs
- Open Security Consultant jobs
- Open Analyste CERT / Incident Responder senior (H/F) jobs
- Open Ethical hacker / Pentester H/F jobs
- Open Staff Application Security Engineer jobs
- Open Lead Security Engineer jobs
- Open Senior Security Operations Engineer jobs
- Open Senior Information Security Engineer jobs
- Open Staff Security Engineer jobs
- Open Analyste CERT / Incident Responder junior (H/F) jobs
- Open Senior Security Analyst jobs
- Open Application security-related jobs
- Open Governance-related jobs
- Open Network security-related jobs
- Open Risk assessment-related jobs
- Open Pentesting-related jobs
- Open ISO 27001-related jobs
- Open Clearance-related jobs
- Open DevOps-related jobs
- Open Kubernetes-related jobs
- Open Vulnerability management-related jobs
- Open DevSecOps-related jobs
- Open Analytics-related jobs
- Open Java-related jobs
- Open IAM-related jobs
- Open CISM-related jobs
- Open SaaS-related jobs
- Open APIs-related jobs
- Open CI/CD-related jobs
- Open Forensics-related jobs
- Open Malware-related jobs
- Open CISA-related jobs
- Open Threat intelligence-related jobs
- Open Terraform-related jobs
- Open IDS-related jobs
- Open OWASP-related jobs