Senior Consultant - GRC Technology | Remote, USA
OptivOptiv manages cyber risk so you can secure your full potential. Cybersecurity advisory services and solutions. Powered by the best minds in cyber.
How you’ll make an impact
- Able to perform as delivery lead and “point of contact" for routine and complex GRC technology implementation projects
- Perform client-facing activities such as product demonstrations, facilitate design workshops, remediation, and status meeting participation if required
- Design and configure/develop GRC technology applications for potentially multiple GRC systems based on technical requirements using SDLC concepts and iterative design and build methodology. These systems may include Archer, ServiceNow, LogicGate, OneTrust, Diligent, or a variety of others in the industry. Navex. Training will be provided where necessary.
- Develop or leverage API connectors for integrations between 3rd party systems and the GRC technology.
- Integrate disparate software applications via API function calls.
- Design and develop modules within GRC platforms such as Archer and ServiceNow including layout, workflow, reporting, notifications, questionnaires, access control, packaging, SSO, and LDAP access configuration.
- Lead GRC Technology implementation activities, connector configuration, custom rule development, workflow configuration and development, and third-party system integration.
- Lead User Acceptance Testing and bug-related engineering efforts.
- Design, implement, and educate on specific technology build processes, code migration, and source control use.
- Provide knowledge transfer and postproduction support activities as necessary.
- Effective communicator with clients and internal team members.
- Maintain professional and technical knowledge by attending educational workshops; reviewing professional publications; establishing personal networks; and participating in professional associations such as ISSA.
- Obtain and maintain top-tier vendor certification(s).
- Complete administrative project tasks like time and expense entry, status reporting, and project completion reporting.
- Acts as a contributor in Optiv communities for solutions of focus
What we’re looking for
- Bachelor's degree and approximately 5-7 years of related work experience with 3-5 years of related work experience using and implementing GRC technology.
- Ability to support high demand and tight timelines to produce quality deliverables
- Minimum of 3 years of Advance Workflow, data feeds via API or import, testing, and dashboard/reporting development in GRC technology
- Experience with Custom Objects and the ability to create and build to meet the functional and technical requirements defined Desirable experience within one or more of the following Security Architecture and/or Enterprise Architectural Frameworks (e.g., SABSA, TOGAF, O-ESA).
- Knowledge of general risk, compliance, and security concepts and methods such as risk assessments, control attestations and testing, policy management, vendor risk management, vulnerability assessments, data classification, privacy assessments, incident response, security policy creation, enterprise security strategies, architectures, and governance.
- Strong understanding of networking (TCP/IP, OSI model), operating system fundamentals (Windows, UNIX, mainframe), security technologies (firewalls, IDS/IPS, etc.), and application programming/scripting languages (C, Java, Perl, Shell).
- Strong understanding of regulatory requirements and compliance issues affecting clients related to privacy and data protection, such as PCI DSS, GLBA, Basel II, EU Data Protection Directive, International Cross Border, and U.S. State Data Privacy Laws.
- Working knowledge of operating systems, virtual machine environments, mainframe security packages, and relational database management systems.
- Practical knowledge of configuring GRC technology such as Archer, ServiceNow, LogicGate, OneTrust, or Navex.
- Skills in usage or design and implementation of API services (SOAP, REST).
- A good understanding of the SDLC and Agile sprint methodologies is required. Experience with JIRA is a plus.
- Work independently in a highly dynamic environment with the ability to collaborate with an inter-functional team.
- Ability to build relationships with and influence other functional areas
- Well-developed negotiation skills.
- Ability to build consensus.
- Ability to manage multiple tasks in parallel
- Willingness to travel to meet client needs if required
- Related professional certifications such as the GRCP, RIMS-CRMP, CISSP, CISM, and/or CISA, are preferred but not required
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Agile APIs C CISA CISM CISSP Compliance Firewalls Governance IDS Incident response IPS Java Jira LDAP Mainframe PCI DSS Perl Privacy Risk assessment Risk management Scripting SDLC SSO TCP/IP TOGAF UNIX Windows
More jobs like this
Remote Remote Full TimeSenior Senior-levelUSD 120K - 200K * USD 120K+ *
GuidePoint Security LLC
Career development Conferences Flex hours Flex vacation Health care
Remote, UNITED STATES, United … Remote, UNITED STATES, United States Full TimeSenior Senior-levelUSD 127K - 175K USD 127K+
Palo Alto Networks
Senior Consultant, Offensive Security, Proactive Services (Unit 42)Application security Audits AWS Azure Bash Burp Suite +36
Career development Health care Medical leave Salary bonus
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Information Security Specialist jobs
- Open Senior Information Security Analyst jobs
- Open IT Security Analyst jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Consultant SOC / CERT H/F jobs
- Open Senior Information Security Engineer jobs
- Open Information Security Officer jobs
- Open Security Operations Engineer jobs
- Open Analyste CERT / Incident Responder junior (H/F) jobs
- Open Ingénieur DevSecops H/F jobs
- Open Staff Security Engineer jobs
- Open Cybersecurity Consultant jobs
- Open Senior Security Architect jobs
- Open Chief Information Security Officer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Analyste CERT / Incident Responder senior (H/F) jobs
- Open o365 Security Architect jobs
- Open Senior Security Analyst jobs
- Open Principal Security Engineer jobs
- Open Senior Cyber Security Engineer jobs
- Open Staff Product Security Engineer jobs
- Open Electronic Warfare Advanced Tactical Trainer jobs
- Open Product Security Engineer jobs
- Open Security Researcher jobs
- Open Cyber Security Architect jobs
- Open GCP-related jobs
- Open SOC-related jobs
- Open Risk assessment-related jobs
- Open Network security-related jobs
- Open Governance-related jobs
- Open Pentesting-related jobs
- Open ISO 27001-related jobs
- Open Analytics-related jobs
- Open CISM-related jobs
- Open SaaS-related jobs
- Open Threat intelligence-related jobs
- Open IAM-related jobs
- Open Malware-related jobs
- Open Java-related jobs
- Open Security Clearance-related jobs
- Open Vulnerability management-related jobs
- Open CISA-related jobs
- Open DevOps-related jobs
- Open Kubernetes-related jobs
- Open Security assessment-related jobs
- Open Forensics-related jobs
- Open APIs-related jobs
- Open SQL-related jobs
- Open CI/CD-related jobs
- Open EDR-related jobs