×
Register Here to Apply for Jobs or Post Jobs. X

Sr. Security Governance, Risk & Compliance Specialist

Job in Northern, Floyd County, Kentucky, USA
Listing for: Clario
Full Time position
Listed on 2026-09-10
Job specializations:
  • IT/Tech
    Information Security & Data Protection, Cybersecurity, IT Consultant, IT Business Analyst
Salary/Wage Range or Industry Benchmark: 110000 - 150000 USD Yearly USD 110000.00 150000.00 YEAR
Job Description & How to Apply Below
Location: Northern

The Senior Security GRC Specialist is a high-impact role focused on strengthening and maintaining information security governance, risk, and compliance across the organization. This position partners closely with QA, IT, Information Security, Legal, Product, and other internal stakeholders, as well as external clients, vendors, auditors, and assessment partners. The role will help drive security and compliance initiatives, support risk management activities, coordinate audits and certifications, manage third-party security risk, and continuously improve security governance, policies, processes, and controls.

What

You’ll Be Doing
  • Security Governance, Risk & Compliance:
    Support and mature the organization’s Security GRC program, helping ensure IT, Product, and Information Security controls align with applicable policies, standards, regulations, and best practices.
  • Audit & Assessment Coordination:
    Coordinate and support external client audits, certifications, and assessments, including SOC 1, SOC 2, ISO 27001/2700x, client audits, and other security assessments or accreditations.
  • Compliance Monitoring:
    Evaluate the compliance status of IT, Product, and Information Security controls. Partner with control owners to identify gaps, develop remediation plans, track progress, and drive issues through resolution.
  • Risk Management:

    Support the organization’s risk management framework, including assessing inherent and residual risk, evaluating risk tolerance, facilitating risk discussions, and supporting periodic internal and third-party risk assessments.
  • Third-Party

    Risk Management:

    Execute established processes to assess, monitor, and manage information security risks associated with third parties, vendors, and other external partners.
  • Client Assurance & Regulatory Support:
    Serve as a key point of contact for QA, Regulatory, Customer, and other stakeholder interactions related to security and compliance. Support responses to audits, client questionnaires, RFPs, findings, and other assurance requests.
  • Policy & Standards Governance:
    Support the development, maintenance, and governance of the Information Security policies, standards, procedures, and related documentation.
  • Process Improvement:
    Identify opportunities to improve and mature IT and Information Security compliance processes. Use industry standards, emerging risks, regulations, and stakeholder feedback to recommend practical improvements.
  • Security Frameworks:
    Apply standards and best practices from frameworks such as ISO/IEC 27001, NIST, COBIT, and ITIL to support the organization’s security and compliance objectives.
  • Reporting & Metrics:
    Develop compliance and risk reports, metrics, and management insights to communicate the status of key risks, controls, remediation activities, and compliance initiatives to stakeholders at various levels.
  • Security Awareness:
    Support security education and awareness initiatives by helping communicate new policies, procedures, and security practices to IT teams and the broader organization.
  • Cross-Functional Collaboration:

    Build strong relationships across technical and non-technical teams and influence stakeholders to support security, compliance, risk management, and governance objectives.
  • Program & Process Support:
    Contribute to the selection, implementation, improvement, and management of GRC tools, platforms, processes, and operational procedures.
  • Prioritization & Delivery:
    Effectively prioritize multiple initiatives and deliverables while maintaining a high level of quality and attention to detail. Perform other related duties and projects as assigned.
What We Look For
  • Bachelor’s degree in Information Systems, Information Technology, Cybersecurity, or a related field. An Associate’s degree may be considered based on…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary