Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

GRC Cybersecurity Specialist

We Place People Executive Search Firm

Job Description

Job Description

Location: Chicago, IL

 

Location: Chicago, IL
Employment Type: Direct Hire / Full-Time
Work Arrangement: Onsite
Work Authorization: U.S. Citizen or Green Card Holder required

Our client is seeking an experienced Cybersecurity Governance, Risk & Compliance (GRC) Specialist II to join its Information Security organization in Chicago.

This position is ideal for a cybersecurity professional who has done more than participate in audits, complete compliance checklists, or respond to security questionnaires. The successful candidate will have hands-on experience with cybersecurity governance and risk management and will understand how security programs are structured, governed, measured, and improved within a complex organization.

While compliance is an important component of the position, the strongest emphasis is on Governance and Risk . Candidates should be comfortable discussing how cybersecurity decisions are made, how accountability and ownership are established, how risk is identified and evaluated, and how policies, standards, exceptions, and risk-treatment decisions are managed across an organization.

What You'll Be Doing

Cybersecurity Governance

  • Help operate and mature the organization's cybersecurity governance program.
  • Develop, maintain, and improve information security policies, standards, procedures, and governance documentation.
  • Work with security, technology, business, and leadership teams to establish clear ownership and accountability for cybersecurity requirements.
  • Help ensure security policies and standards translate into practical controls and operating processes.
  • Provide guidance to stakeholders on security requirements, governance processes, and appropriate security practices.
  • Identify gaps between established security requirements and actual business or technology practices and help drive appropriate remediation.

Cybersecurity Risk Management

  • Perform and support cybersecurity risk assessments across technology, business processes, vendors, applications, and services.
  • Identify security risks, assess their potential business impact, and communicate findings clearly to both technical and non-technical stakeholders.
  • Work with risk owners to determine appropriate remediation, mitigation, acceptance, transfer, or other risk-treatment strategies.
  • Manage and evaluate security exception requests and help ensure accepted risks have appropriate ownership, documentation, approvals, and expiration or review dates.
  • Track identified risks and remediation activities through resolution.
  • Help leadership understand cybersecurity risk so informed business decisions can be made.

Third-Party & Client Security

  • Conduct security reviews and risk assessments of vendors and third-party service providers.
  • Manage remediation and follow-up activities associated with identified vendor risks.
  • Support the ongoing third-party security risk management lifecycle.
  • Lead or coordinate responses to client security questionnaires, assessments, and security-related inquiries.
  • Gather and validate evidence demonstrating the effectiveness of security controls.
  • Participate in client and third-party discussions as an Information Security subject matter expert.

Security Controls & Frameworks

  • Evaluate technology environments and security programs against established cybersecurity frameworks, standards, and internal requirements.
  • Work with frameworks and assessment methodologies including NIST, ISO 27001, SOC, and SIG .
  • Assess whether controls are appropriately designed, implemented, documented, and operating as intended.
  • Partner with technology and security teams to address control gaps and strengthen the organization's overall security posture.

AI Governance & Risk

  • Support governance and risk management associated with Artificial Intelligence technologies and use cases.
  • Evaluate AI-related security, governance, privacy, and technology risks.
  • Help establish appropriate controls, standards, and risk-management practices for responsible AI adoption.
  • Work with stakeholders to evaluate new AI capabilities from a cybersecurity and risk perspective.

Security Awareness & GRC Operations

  • Support and help manage the organization's Security Awareness program, including planning, training evaluation, measurement, and continuous improvement.
  • Support administration and optimization of GRC platforms, workflows, reporting, and risk records.
  • Maintain accurate documentation and reporting related to risks, controls, exceptions, assessments, and remediation activities.
  • Help improve GRC processes as the cybersecurity program continues to mature.

What We're Looking For

Education & Experience

  • Bachelor's degree or equivalent combination of education and experience.
  • Approximately 5+ years of IT Security experience , including meaningful experience within cybersecurity governance, risk, or GRC.
  • At least 4 years of Information Security experience with exposure to technical security environments.
  • Hands-on cybersecurity experience is strongly preferred.

Governance & Risk Experience – Critical

Candidates should be able to clearly explain their experience with:

  • Cybersecurity governance structures and processes.
  • Security policy and standards development.
  • Roles, responsibilities, ownership, and accountability within a security program.
  • Cybersecurity risk identification and assessment.
  • Risk scoring, prioritization, remediation, and treatment.
  • Risk acceptance and security exception processes.
  • Translating technical security findings into business risk.
  • Working with risk and control owners to drive issues through resolution.

We are particularly interested in candidates who understand why governance processes exist and how they influence cybersecurity decision-making , rather than candidates whose GRC experience has primarily consisted of compliance testing or audit support.

Additional Qualifications

  • Strong working knowledge of NIST, ISO 27001, SOC, and SIG or comparable security frameworks and assessment methodologies.
  • Experience performing third-party/vendor security assessments.
  • Experience responding to client security questionnaires and security reviews.
  • Experience with AI governance, AI security, or AI risk management .
  • Strong technical writing skills with the ability to develop clear policies, standards, risk documentation, and executive-level communications.
  • Experience working with GRC platforms and related workflow technologies.
  • Understanding of role-based access controls and identity/security concepts.
  • Working knowledge of security technologies and concepts such as authentication, encryption, firewalls, SIEM, IDS/IPS, vulnerability management, privileged access management, and mobile security.
  • Ability to communicate cybersecurity risk effectively to both technical teams and business stakeholders.
  • Strong analytical, organizational, project-management, and problem-solving skills.

Preferred certifications may include

CISSP, CISA, CISM , or relevant AI governance, audit, risk, or security credentials.

The Candidate We're Looking For

The right person will not view GRC as simply an audit or compliance function. We are looking for someone who understands that strong cybersecurity governance establishes how security decisions are made, who owns those decisions, how accountability is maintained, and how risk is evaluated and addressed .

You should be comfortable discussing real examples of situations where you identified a cybersecurity risk, worked with stakeholders to determine an appropriate response, documented or communicated that risk, and followed the issue through remediation or formal acceptance.

This is a highly collaborative position requiring the ability to work effectively with cybersecurity professionals, engineers, technology teams, business leaders, vendors, and clients.

This is a full-time, direct-hire position requiring onsite work in Chicago. Candidates must be U.S. Citizens or Green Card holders.

 

How to Apply:

Our client has hired us to help facilitate the initial interview and recruiting process. Please attach your current version of your resume and make sure you complete our initial pre-screening questions that will be used for determining which applicants will be considered at this time. Thank you for your interest.

 

\nCompany Description

We Place People is a premiere Executive Search Firm working with leading companies nationwide. We have a direct relationship with our clients and a 95% hire rate! We differentiate ourselves from other firms & work closely with our candidates throughout the interview process. WE PLACE PEOPLE is what we do best!

Company Description

We Place People is a premiere Executive Search Firm working with leading companies nationwide. We have a direct relationship with our clients and a 95% hire rate! We differentiate ourselves from other firms & work closely with our candidates throughout the interview process. WE PLACE PEOPLE is what we do best!

Vacancy posted 10 days ago
Similar jobs that could be interesting for youBased on the GRC Cybersecurity Specialist in Chicago, IL vacancy
  • $116k - $144k

     ...You’ll Do Are you driven to strengthen security programs, reduce risk, and help organizations meet evolving cybersecurity expectations? As a Security GRC Specialist II , you’ll be a key member of the Governance, Risk, and Compliance (GRC) team, leading and executing core... 
    Suggested
    Work experience placement
    Worldwide
    Flexible hours

    Kirkland & Ellis

    Chicago, IL
    4 days ago
  • $222k - $304.5k

     ...are, you’re in the right place.Who We AreIn order to be the cybersecurity partner of choice, we must trailblaze the path and shape the...  .... We are seeking a passionate and experienced AIRS Solutions Specialist to support the go-to-market (GTM) strategy and execution for... 
    Suggested
    Full time
    Remote work
    Visa sponsorship
    Work visa

    Palo Alto Networks

    Chicago, IL
    3 days ago
  • $78k - $156k

     ...place to work for diversity, working mothers, female executives, and scientists. THE OPPORTUNITY This Cybersecurity Specialist position can work out remotely within the U.S . The Cybersecurity Specialist is responsible for assisting and identifying... 
    Suggested
    Remote work

    Abbott Laboratories company

    Chicago, IL
    2 days ago
  • $140k - $192.5k

     ...your career alongside people who are just as passionate as you are, you're in the right place. Who We Are In order to be the cybersecurity partner of choice, we must trailblaze the path and shape the future of our industry. This is something our employees work at... 
    Suggested
    Remote work
    Visa sponsorship
    Work visa

    Palo Alto Networks

    Chicago, IL
    3 days ago
  • $98k - $130k

     ...department in our Washington, D.C., or Chicago office as a Senior Specialist: Business Development and Marketing (Cyber Security and Data...  ...some of the firm's most dynamic practice areas, including Cybersecurity and Data Privacy and related practice-adjacent areas. This... 
    Suggested
    Contract work
    Work at office
    Local area
    Shift work

    Mayer Brown

    Chicago, IL
    2 days ago
  • Kodi Connect is seeking a remote, full-time Outreach professional to identify senior IT and Cybersecurity executives and secure attendance at North America events. You will own the full lifecycle from first outreach to confirmed seat, using Salesloft, LinkedIn Navigator... 
    Remote job
    Full time

    Nashville Public Radio

    Chicago, IL
    22 hours ago
  • $93.8k - $130.6k

     ...ELIGIBLE FOR VISA SPONSORSHIP***** What You'll Do: This role serves as an integral part of the governance, risk management, and compliance (GRC) team, providing comprehensive support across multiple GRC capabilities including change management and strategy, exam management,... 
    Work at office
    Remote work
    Shift work
    2 days per week

    The Options Clearing Corporation (OCC)

    Chicago, IL
    4 days ago
  • $100k - $120k

     ...actionable recommendations to remediate potential control gaps.Support certain centralized department activities, administration of the GRC tool, and prepare dashboarding and information gathering to support team reporting requirements.Demonstrate excellent communication... 
    Work experience placement

    Robert Half

    Chicago, IL
    1 day ago
  • $169.01k - $370.53k

     ...consider a career in Advisory. KPMG is currently seeking a Specialist Director, Cloud Security to join our Managed Services...  ...guardrails, policies, and control frameworks; Partner with cloud, cybersecurity, architecture, and business leaders to embed security into platform... 
    H1b
    Local area

    KPMG

    Chicago, IL
    2 days ago
  • $94k - $115k

    How you’ll make an impact:The Senior Compliance Associatewill work inside Strata’s Information Technology group and assist with all aspects of governance, risk, and compliance. This position works collaboratively to ensure Strata complies with industry regulations, client...
    Work experience placement
    Work at office

    Strata Decision Technology

    Chicago, IL
    4 days ago
  • $235k - $365k

     ...with deep trial and investigative expertise, trusted by companies to navigate their most complex and high-stakes challenges in cybersecurity, data privacy, artificial intelligence, and white-collar matters.This market-leading team is consistently recognized by top industry... 

    Jameson Legal

    Chicago, IL
    1 day ago
  • $140k - $170k

     ...clients;Providing technical assessment/audit and guidance to clients on the adequacy of cyber security controls in accordance with cybersecurity frameworks that are included in one or more of the following - NIST CSF 2.0, HIPAA, ISO 27001 and 27002, SOC2, NERC-CIP, Assist... 
    Work at office
    Local area
    Remote work
    Work from home
    3 days per week

    CRA International

    Chicago, IL
    22 hours ago
  • $130k - $152.5k

     ...appropriate;Providing technical assessment/audit and guidance to clients on the adequacy of cyber security controls in accordance with cybersecurity frameworks that are included in one or more of the following - NIST CSF 2.0, HIPAA, ISO 27001 and 27002, SOC2, NERC-CIP,... 
    Work at office
    Local area
    Work from home
    3 days per week

    CRA International

    Chicago, IL
    22 hours ago
  • $120k - $145k

     ...(TAS) team assists private equity and corporate clients by providing cohesive diligence across financial, tax, data analytics, cybersecurity, and technical accounting. Leveraging data-based insights, strong technical knowledge and industry experience, the TAS team supports... 
    Full time
    Work at office
    Worldwide

    Houlihan Lokey

    Chicago, IL
    22 hours ago
  • $95k - $160k

     ...providing cohesive diligence across financial, tax, data analytics, cybersecurity, and technical accounting. Leveraging data-based insights,...  ...strategic dealmaking financial reporting requirements. Our specialists have deep knowledge of deals, sectors, and accounting matters... 
    Full time
    Worldwide

    Houlihan Lokey

    Chicago, IL
    22 hours ago
  • $85k - $115k

     ...produce sustainable business results.Join our team and create your future.Huron is seeking a highly skilled Senior Associate, Sourcing Specialist to support enterprise‑wide hiring initiatives across the U.S. and Canada. In this key role, you will source top passive talent... 
    Full time
    Local area
    Remote work
    Shift work

    Huron Consulting Group

    Chicago, IL
    22 hours ago
  • $95.6k - $162.4k

    About Northern TrustAs a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world’s most successful individuals, families, corporations and institutions. Since 1889, ...
    Full time
    H1b
    Worldwide
    Flexible hours

    Northern Trust

    Chicago, IL
    2 days ago
  •  ...publicly traded organization is seeking a Senior Internal Controls Specialist to join its Internal Controls team. This role offers the...  ...mitigate risk. Assist with governance, risk, and compliance (GRC) system administration, reporting, dashboards, and program documentation... 
    Work at office

    Buckingham Search

    Chicago, IL
    2 days ago
  • $67k - $120k

     ...build your ambition. Join Amrize as a Senior Internal Control Specialist and help construct what's next. If you're ready to put your skills...  ...centralized department activities, administration of the GRC tool, and prepare dashboarding and information gathering to support... 
    Work experience placement
    Work at office
    Local area
    Flexible hours

    Holcim Ltd.

    Chicago, IL
    2 days ago
  •  ...You'll Do:Join our dynamic Security Engineering team as a Senior Associate and make a significant impact on our organization's cybersecurity posture. In this role, you'll manage privileged access systems that protect our most critical assets, implement AI-based security... 
    Full time
    Remote work
    2 days per week

    The Options Clearing Corporation

    Chicago, IL
    22 hours ago
  • $130k - $152.5k

     ...analysis that provide clients with clear, implementable solutions to complex business concerns.Position OverviewCRA is seeking a Cybersecurity Consultant (Assessments / Due Diligence / Advisory) to support client engagements focused on evaluating and managing... 
    Work at office
    Work from home
    3 days per week

    CRA International

    Chicago, IL
    4 days ago
  • $65k - $70k

     ...Job Description Job Description Summary of Position : The Welding Instruction and Trades Outreach Specialist is responsible for expanding welding and trades-based programs at the Lutz Center, Orleans, Gately, and in target communities. This individual will plan and... 
    Full time
    Apprenticeship
    Summer work
    Work at office
    Monday to Friday

    After School Matters

    Chicago, IL
    16 days ago
  •  ...emphasizes data‑driven analysis, evidence handling, and collaboration with counsel to deliver insightful results. The position requires knowledge of cybersecurity concepts, strong communication, and experience with forensics tools. #J-18808-Ljbffr Charles River Associates

    Charles River Associates

    Chicago, IL
    3 days ago
  • $100k - $115k

     ...together seamlessly across 50-plus practices and 21 offices in the world’s major financial centers.The OpportunityWe are seeking a Specialist, Business Development (Transactional) to join the Firm in our New York office on a hybrid basis. In this role, the Specialist... 
    Full time
    Local area
    Remote work

    Skadden, Arps, Slate, Meagher & Flom and Affiliates

    Chicago, IL
    4 days ago
  • $117.4k - $177.6k

    To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.Job CategorySalesJob DetailsAbout SalesforceSalesforce is the #1 AI CRM, where humans with agents drive customer success together...
    Full time
    Temporary work

    Salesforce

    Chicago, IL
    22 hours ago
  • $114.7k - $194.9k

    About Northern TrustAs a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world’s most successful individuals, families, corporations and institutions. Since 1889, ...
    H1b
    Worldwide
    Flexible hours

    Northern Trust

    Chicago, IL
    4 days ago
  • QUALIFICATIONSU.S. Bachelor’s degree or equivalent work experience required4+ years of consulting, law, risk, compliance, communications, or other relevant professional services experience Demonstrated intellectual curiosity and integrity, including affinity and abiding...
    For contractors
    Apprenticeship
    Work experience placement
    For subcontractor

    McKinsey & Company

    Chicago, IL
    1 day ago
  • Join JPMorganChase as a Collateral Services Specialist II and play a pivotal role in our lending services. This position offers a unique opportunity for career growth and development, where your skills in conflict management and critical thinking will be highly valued.... 

    JP Morgan Chase

    Chicago, IL
    22 hours ago
  • $95.6k - $162.4k

    Responsibilities Contingent labor category management Collaborate with technology partners to develop and execute sourcing and procurement strategies Analyze industry and vendor data / trends and make recommendations to technology partners about key insights, trade-offs...
    H1b

    Northern Trust

    Chicago, IL
    2 days ago
  • $100k - $105k

    A financial services firm based in Chicago seeks an Associate for its Corporate Actions team. The candidate will coordinate corporate action documentation, ensure accurate processing of events, and prepare reports for investment managers. A Bachelor's degree and 2+ years...
    Work at office

    Guggenheim Investments

    Chicago, IL
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to GRC Cybersecurity Specialist. Be the first to apply!