Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

IT Security Specialist - GRC Lead

Quable

GRC Lead

Ibexa is a European marketing orchestration platform that empowers organisations to deliver seamless, data-driven customer experiences across the entire digital journey. By unifying content management, customer data, engagement, product information, and interactive data collection capabilities — including solutions such as Qualifio, Raptor, Quable, Actito — Ibexa enables marketing and digital teams to break down silos and orchestrate high-impact, personalised experiences at scale. We are a team of more than 350 professionals across Europe. As Ibexa continues to expand its footprint across Europe and beyond, we are looking for ambitious sales professionals who are eager to help organisations transform their marketing ecosystems and unlock new growth opportunities.

About the Role

We are looking for a GRC Lead to help build, operate, and continuously improve our security governance framework across a growing SaaS organisation. As a key member of the IT Security team, you will own the governance, risk, compliance, and certification dimensions of our security program. You will work closely with Engineering, Infrastructure, Internal IT, HR, Legal, Product, and executive leadership to ensure that security requirements are properly defined, documented, monitored, and evidenced. You will be the primary owner of our ISO 27001 roadmap, risk management framework, security policies, client security questionnaires, and auditor interactions. This role combines strategic thinking, operational execution, stakeholder management, and a pragmatic approach to compliance.

What You Will Do
Governance & Compliance
  • Own and maintain the company's Information Security Management System (ISMS)
  • Lead the ISO 27001 certification and continuous improvement roadmap
  • Define, document, and continuously improve security policies, standards, procedures, and controls
  • Ensure security governance remains aligned with business objectives and regulatory requirements
  • Coordinate security-related activities with Legal, HR, DPO, Internal IT, Infrastructure, and Product teams
Risk Management
  • Own and maintain the corporate security risk register
  • Facilitate risk identification, assessment, treatment, and follow-up activities
  • Drive remediation planning and ensure appropriate tracking of security actions
  • Support management decision-making through risk-based recommendations
Client & External Security Interactions
  • Lead responses to customer security questionnaires and due diligence requests
  • Coordinate security-related discussions during sales cycles and customer audits
  • Act as the primary point of contact for external auditors and certification bodies
  • Coordinate penetration testing engagements and remediation follow-up
  • Prepare security documentation and evidence packages for customers and auditors
Security Processes & Reporting
  • Define and maintain security processes across the organization
  • Coordinate incident follow-up processes and post-incident action tracking
  • Produce governance dashboards and security reporting for leadership
  • Contribute to KPI definition and measurement frameworks
  • Support quarterly security committees and executive security reviews
Cross-Functional Collaboration
  • Work closely with the Technical Security Lead on security initiatives
  • Partner with Infrastructure, Internal IT, and Engineering teams to ensure compliance requirements are effectively implemented
  • Support security awareness initiatives and company-wide security programs
  • Contribute to the continuous improvement of Technical and Organizational Measures (TOMs)
Job Requirements
What We Are Looking For
  • 5+ years in GRC, Information Security, Internal Audit, or a related field
  • Hands-on experience with ISO 27001, security audits, compliance assessments, and risk management
  • Experience handling customer security reviews and questionnaires
  • Background in SaaS, cloud, software, or technology environments
  • Strong understanding of information security governance and risk management
  • Familiarity with security frameworks such as ISO 27001, SOC 2, and NIST
  • Knowledge of cloud environments, software development, and data privacy principles

Skills

  • Excellent written communication and documentation skills
  • Fluent in English and French
  • Strong stakeholder management and collaboration abilities
  • Ability to translate security requirements into practical business processes
  • Detail-oriented, structured, and effective with both technical and non-technical audiences
  • Able to challenge constructively while fostering collaboration
What Success Looks Like

Within your first year, you will

  • Maintain and continuously improve our ISO 27001 compliance posture and extend scope to entities not covered yet
  • Improve the quality and efficiency of customer security interactions
  • Increase visibility of security KPIs and governance reporting
  • Strengthen security processes and evidence management across the organization
  • Become a trusted advisor to leadership and operational teams on governance, risk, and compliance matters
Why Join Us

You will play a central role in shaping the security maturity of a growing software organization. Working directly with the Head of IT and C-level executive and alongside technical security specialists, you will have the opportunity to influence how security is embedded into our products, operations, and culture while helping the company scale in a secure and compliant way.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the IT Security Specialist - GRC Lead in United States vacancy
  •  ...Cybersecurity Director is accountable for leading the organization’s cybersecurity...  ...closely with senior leaders, IT, and business stakeholders to enable secure, resilient, and effective technology...  ...Governance, Risk, and Compliance (GRC) functions, with accountability for... 
    Suggested
    Full time
    Temporary work
    Local area

    Marathon Petroleum Corporation

    Houston, TX
    2 days ago
  • Dovel Technologies, Inc is looking for a Cybersecurity Consultant based in McLean, VA. In this full-time role, you will lead cyber risk management across various client applications while ensuring compliance with NIST requirements. The ideal candidate will have a Bachelor... 
    Suggested
    Full time
    Flexible hours

    Dovel Technologies, Inc

    Mc Lean, VA
    1 day ago
  •  ...Kushner and Elad Gil, and backed by leading Silicon Valley builders...  ...impact millions of people. As our GRC Lead, you’ll own the...  ...data flow inventory, contractual security obligations, and a reassessment...  ...cadence across HR, Finance, Legal, IT, and Engineering: so data... 
    Suggested
    Worldwide
    Day shift

    BrainCo

    San Francisco, CA
    1 day ago
  • Discount Tire is looking for a Cyber Governance, Risk & Compliance (GRC) Manager in Scottsdale, Arizona. The ideal candidate will have a...  ...years of related experience. This role requires designing and leading a robust GRC program aligning with business priorities.... 
    Suggested
    Work at office

    Discount-Tire

    Scottsdale, AZ
    4 days ago
  • Drata is seeking a Staff Software Engineer in San Francisco to serve as a technical leader across multiple teams. The successful candidate will design and build scalable systems while mentoring engineers and guiding architectural decisions. You will collaborate closely ...
    Suggested

    Careers at Drata

    San Francisco, CA
    14 hours ago
  •  ...Branch is looking for a professional to oversee its Information Security program, ensuring the execution of strategies and governance functions...  ...and relevant experience in risk management, data privacy, and IT/IS operations, along with knowledge of regulatory requirements.... 

    Bank of China Limited, New York Branch

    New Windsor, NY
    3 days ago
  • Overview: Job Purpose The Engineer, Information Security GRC is part of a team responsible for the global Information Security program. The role would gain exposure to the full suite of businesses and products which underpin the Parent ICE company.   Information... 
    Work experience placement

    Intercontinental Exchange

    Provo, UT
    8 days ago
  •  ...the world. The Royal Caribbean Group’s IT-Global Information Security Team has an exciting career opportunity for a full-time Lead, IS Third Party Risk Management reporting...  ...and experienced Lead, Information Risk and GRC with a strong emphasis on Third-Party Risk... 
    Full time

    Royal Caribbean Group

    Miami, FL
    3 days ago
  • $155k

     ...Cybersecurity GRC Team Lead This is a remote-eligible opportunity offering flexible work arrangements...  ...impactful team within the Information Security Office (ISO) at UT Austin. The...  ...university's research mission and enterprise IT operations. You will get to work with... 
    Full time
    Work at office
    Remote work
    Flexible hours

    The University of Texas at Austin Staff

    United States
    1 day ago
  • $124.3k - $234.6k

     ...customer trust, protecting Adobe's customers, employees, and platforms while enabling innovation at scale. We seek a GRC Strategy & Security Insights Lead to drive a data driven shift in our GRC program. This role is positioned where strategy, action, and communication... 
    Temporary work
    Local area
    Worldwide
    Shift work

    Adobe

    San Jose, CA
    2 days ago
  •  ...GRC & Cybersecurity Lead Tokyo, Japan About Paidy Inc. Paidy is Japan's pioneer and leading...  ...is everyone's responsibility, but our security team leads the charge on solving some...  ...initiatives with business objectives, managing IT risk, driving audit readiness, and... 
    Ongoing contract
    Local area
    Remote work
    Flexible hours

    Paidy

    United States
    14 hours ago
  • $83.1k - $141.3k

     ...world's most sophisticated clients using leading technology and exceptional service. This...  ...Cybersecurity Governance, Risk and Compliance (GRC) team within Northern Trust's Technology...  ...'s or Master's degree in Information Security, Computer Science, or a related field.... 
    H1b
    Flexible hours

    Northern Trust

    Chicago, IL
    3 days ago
  • $78.75 - $113.75 per hour

     ...TS SCI W/ CI Poly Cleared Vulnerability/GRC Lead Our client, a leader in the HCM space is in need of a GRC/Vulnerability Lead for a...  ...individual will be working a hybrid schedule out of Reston VA, support security, compliance, and risk management initiatives. The Lead will be... 
    Hourly pay
    Contract work

    ClearBridge Technology Group

    Reston, VA
    4 days ago
  •  ...can be anywhere in the world. Reports to: Chief Information Security Officer (CISO) THE OPPORTUNITY HHP is commercializing the...  ...evidence of a credible compliance program before they sign. The GRC Lead makes that evidence real. This role sits inside the CISO... 
    Remote work
    Worldwide
    Flexible hours
    Afternoon shift
    Weekday work

    Human Health Project Inc

    Los Angeles, CA
    4 days ago
  • $155k

     ...Job Posting Title: Cybersecurity GRC Team Lead ---- Hiring Department: Information Security Office ---- Position Open To: All Applicants ----...  ...the university's research mission and enterprise IT operations. You will get to work with a very intelligent... 
    Full time
    For contractors
    Work at office
    Immediate start
    Remote work
    Flexible hours

    The University of Texas at Austin

    Austin, TX
    14 hours ago
  • $118.5k - $148k

     ...hiring Job Title: Cybersecurity GRC Lead Location: Burlington, MA (Hybrid -...  ...supporting audits, inspections, and customer security assessments Strong analytical,...  ...Trident Consulting is a premier IT staffing firm providing high-impact workforce... 
    Full time
    Contract work
    Worldwide
    Relocation package

    Trident Consulting

    Burlington, MA
    1 day ago
  • $153.6k - $192k

     ...intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy and deep...  ...with technical execution. As a Senior GRC Engineer, you will drive critical GRC processes...  ...partners by producing documentation and leading training sessions Evangelize best... 
    Work at office
    Immediate start
    Remote work
    Work from home
    3 days per week

    Brex

    San Francisco, CA
    2 days ago
  • $120k - $156k

     ...Clearsulting LLC is seeking a Consulting Manager for Governance, Risk & Compliance in Dallas, TX. You will lead implementations of Workiva GRC, manage project delivery, and engage with clients to assess their needs. This role requires 6+ years of relevant experience, strong... 
    Remote work
    Flexible hours

    Clearsulting

    Dallas, TX
    2 days ago
  • $135k - $150k

     ...leverage the power of our 300+ venues, leading sports franchises, marquee music...  ...cheer! Job Summary The GRC Lead drives the execution and...  ...management, compliance, and information security governance. They will contributor partner with IT, Legal, Privacy, Finance, and... 
    Full time
    Work experience placement
    Local area
    Flexible hours

    Aeg Worldwide Inc

    Los Angeles, CA
    7 days ago
  • - CMMC Champion and Head of IT Security and GRC - Direct Recruiters, Inc.# CMMC Champion and Head of IT Security and GRC## Job DescriptionCMMC...  ...Hardware and Software) for DoD type customers.* Experience leading CMMC Certification at the corporate level for a similar type... 
    Work at office
    Local area
    Monday to Friday

    TryApplyNow

    Reston, VA
    2 days ago
  •  ...Westborough Workplace Flexibility: Hybrid Job Duties The Senior IT Security GRC Analyst (Global) is accountable for the following core...  ...work experience (IT Security, GRC, etc.). At least 5 years of Lead/Manager experience. Thorough knowledge and understanding of Cybersecurity... 
    Work experience placement
    Local area

    Olympus Corporation of the Americas

    New York, NY
    1 day ago
  • $153.6k - $192k

    Brex is seeking a Senior GRC Engineer in Seattle to drive critical Governance, Risk, and Compliance processes. This role involves automating security controls and building integrations to maintain compliance as Brex expands. Candidates should have over 5 years of experience... 

    Brex

    Seattle, WA
    3 days ago
  •  ...LVT (LiveView Technologies) in American Fork, Utah is seeking an Information Security Manager (GRC). This role involves managing SOC 2 audit processes, conducting risk assessments, and supporting regulatory adherence. The ideal candidate has over 5 years of experience... 

    LVT (LiveView Technologies)

    American Fork, UT
    2 days ago
  •  ...Job Title Information Security Consultant Job Description Conduct information security...  ...monitoring, and data analytics. Plan and lead sub-tasks or smaller components of...  ...industries (NIS2, GDPR, etc.) and experience with GRC platforms and risk management tools.... 
    Permanent employment
    Contract work
    Remote work
    Flexible hours

    Airbus

    United States
    3 days ago
  •  ...world, moving beyond traditional security solutions to deliver AI-driven,...  ...Information Security Manager (GRC) to join our growing...  ...necessary. Collaborate with IT, Finance, and Legal to represent...  ...~ Demonstrates an ability to lead effectively in dynamic, fast‑paced... 
    Work at office

    LiveView Technologies

    American Fork, UT
    2 days ago
  • Waterfront Training Solutions Inc. is seeking an IT Systems & Compliance Specialist in Chesapeake, VA. This full-time role focuses on achieving CMMC...  ...certifications, and strong knowledge of network security. The position is strictly on-site, ensuring effective management... 
    Full time

    Waterfront Training Solutions Inc.

    Chesapeake, VA
    14 hours ago
  • $175k - $275k

     ...critical infrastructure that developers need to securely scale their products to large...  ...& response. We are expanding our internal GRC function to scale our compliance, risk, and...  ...we ship software, not a separate track. Lead our next certifications. Drive initiatives... 
    Contract work
    Remote work

    WorkOS

    San Francisco, CA
    1 day ago
  • $148.5k - $223.9k

    Overview The Public Sector GRC Lead role is part of Informatica's Security and Compliance organization, focusing on maintaining and expanding compliance authorizations that enable Informatica's cloud products to serve government customers at scale. The incumbent will serve... 

    100 Salesforce, Inc.

    San Francisco, CA
    1 day ago
  • $160k - $190k

    A technology firm in California seeks a Risk and Compliance Lead to manage security compliance initiatives across the organization. This role involves...  ...candidate will have over 6 years of experience in security GRC, strong communication skills, and hands-on experience with... 

    Applied Intuition

    Sunnyvale, CA
    1 day ago
  • A leading IT staffing firm in New Orleans is seeking a Lead IT GRC professional. This role offers an opportunity to be part of a collaborative team that prioritizes innovation and continuous learning. The company provides various career resources, training, and a comprehensive... 

    Apex Systems

    New Orleans, LA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to IT Security Specialist - GRC Lead. Be the first to apply!