IT Security Specialist - GRC Lead
Quable
GRC Lead
Ibexa is a European marketing orchestration platform that empowers organisations to deliver seamless, data-driven customer experiences across the entire digital journey. By unifying content management, customer data, engagement, product information, and interactive data collection capabilities — including solutions such as Qualifio, Raptor, Quable, Actito — Ibexa enables marketing and digital teams to break down silos and orchestrate high-impact, personalised experiences at scale. We are a team of more than 350 professionals across Europe. As Ibexa continues to expand its footprint across Europe and beyond, we are looking for ambitious sales professionals who are eager to help organisations transform their marketing ecosystems and unlock new growth opportunities.
About the Role
We are looking for a GRC Lead to help build, operate, and continuously improve our security governance framework across a growing SaaS organisation. As a key member of the IT Security team, you will own the governance, risk, compliance, and certification dimensions of our security program. You will work closely with Engineering, Infrastructure, Internal IT, HR, Legal, Product, and executive leadership to ensure that security requirements are properly defined, documented, monitored, and evidenced. You will be the primary owner of our ISO 27001 roadmap, risk management framework, security policies, client security questionnaires, and auditor interactions. This role combines strategic thinking, operational execution, stakeholder management, and a pragmatic approach to compliance.
What You Will Do
Governance & Compliance
- Own and maintain the company's Information Security Management System (ISMS)
- Lead the ISO 27001 certification and continuous improvement roadmap
- Define, document, and continuously improve security policies, standards, procedures, and controls
- Ensure security governance remains aligned with business objectives and regulatory requirements
- Coordinate security-related activities with Legal, HR, DPO, Internal IT, Infrastructure, and Product teams
Risk Management
- Own and maintain the corporate security risk register
- Facilitate risk identification, assessment, treatment, and follow-up activities
- Drive remediation planning and ensure appropriate tracking of security actions
- Support management decision-making through risk-based recommendations
Client & External Security Interactions
- Lead responses to customer security questionnaires and due diligence requests
- Coordinate security-related discussions during sales cycles and customer audits
- Act as the primary point of contact for external auditors and certification bodies
- Coordinate penetration testing engagements and remediation follow-up
- Prepare security documentation and evidence packages for customers and auditors
Security Processes & Reporting
- Define and maintain security processes across the organization
- Coordinate incident follow-up processes and post-incident action tracking
- Produce governance dashboards and security reporting for leadership
- Contribute to KPI definition and measurement frameworks
- Support quarterly security committees and executive security reviews
Cross-Functional Collaboration
- Work closely with the Technical Security Lead on security initiatives
- Partner with Infrastructure, Internal IT, and Engineering teams to ensure compliance requirements are effectively implemented
- Support security awareness initiatives and company-wide security programs
- Contribute to the continuous improvement of Technical and Organizational Measures (TOMs)
Job Requirements
What We Are Looking For
- 5+ years in GRC, Information Security, Internal Audit, or a related field
- Hands-on experience with ISO 27001, security audits, compliance assessments, and risk management
- Experience handling customer security reviews and questionnaires
- Background in SaaS, cloud, software, or technology environments
- Strong understanding of information security governance and risk management
- Familiarity with security frameworks such as ISO 27001, SOC 2, and NIST
- Knowledge of cloud environments, software development, and data privacy principles
Skills
- Excellent written communication and documentation skills
- Fluent in English and French
- Strong stakeholder management and collaboration abilities
- Ability to translate security requirements into practical business processes
- Detail-oriented, structured, and effective with both technical and non-technical audiences
- Able to challenge constructively while fostering collaboration
What Success Looks Like
Within your first year, you will
- Maintain and continuously improve our ISO 27001 compliance posture and extend scope to entities not covered yet
- Improve the quality and efficiency of customer security interactions
- Increase visibility of security KPIs and governance reporting
- Strengthen security processes and evidence management across the organization
- Become a trusted advisor to leadership and operational teams on governance, risk, and compliance matters
Why Join Us
You will play a central role in shaping the security maturity of a growing software organization. Working directly with the Head of IT and C-level executive and alongside technical security specialists, you will have the opportunity to influence how security is embedded into our products, operations, and culture while helping the company scale in a secure and compliant way.
- ...Cybersecurity Director is accountable for leading the organization’s cybersecurity... ...closely with senior leaders, IT, and business stakeholders to enable secure, resilient, and effective technology... ...Governance, Risk, and Compliance (GRC) functions, with accountability for...SuggestedFull timeTemporary workLocal area
- Dovel Technologies, Inc is looking for a Cybersecurity Consultant based in McLean, VA. In this full-time role, you will lead cyber risk management across various client applications while ensuring compliance with NIST requirements. The ideal candidate will have a Bachelor...SuggestedFull timeFlexible hours
- ...Kushner and Elad Gil, and backed by leading Silicon Valley builders... ...impact millions of people. As our GRC Lead, you’ll own the... ...data flow inventory, contractual security obligations, and a reassessment... ...cadence across HR, Finance, Legal, IT, and Engineering: so data...SuggestedWorldwideDay shift
- Discount Tire is looking for a Cyber Governance, Risk & Compliance (GRC) Manager in Scottsdale, Arizona. The ideal candidate will have a... ...years of related experience. This role requires designing and leading a robust GRC program aligning with business priorities....SuggestedWork at office
- Drata is seeking a Staff Software Engineer in San Francisco to serve as a technical leader across multiple teams. The successful candidate will design and build scalable systems while mentoring engineers and guiding architectural decisions. You will collaborate closely ...Suggested
- ...Branch is looking for a professional to oversee its Information Security program, ensuring the execution of strategies and governance functions... ...and relevant experience in risk management, data privacy, and IT/IS operations, along with knowledge of regulatory requirements....
- Overview: Job Purpose The Engineer, Information Security GRC is part of a team responsible for the global Information Security program. The role would gain exposure to the full suite of businesses and products which underpin the Parent ICE company. Information...Work experience placement
- ...the world. The Royal Caribbean Group’s IT-Global Information Security Team has an exciting career opportunity for a full-time Lead, IS Third Party Risk Management reporting... ...and experienced Lead, Information Risk and GRC with a strong emphasis on Third-Party Risk...Full time
$155k
...Cybersecurity GRC Team Lead This is a remote-eligible opportunity offering flexible work arrangements... ...impactful team within the Information Security Office (ISO) at UT Austin. The... ...university's research mission and enterprise IT operations. You will get to work with...Full timeWork at officeRemote workFlexible hours$124.3k - $234.6k
...customer trust, protecting Adobe's customers, employees, and platforms while enabling innovation at scale. We seek a GRC Strategy & Security Insights Lead to drive a data driven shift in our GRC program. This role is positioned where strategy, action, and communication...Temporary workLocal areaWorldwideShift work- ...GRC & Cybersecurity Lead Tokyo, Japan About Paidy Inc. Paidy is Japan's pioneer and leading... ...is everyone's responsibility, but our security team leads the charge on solving some... ...initiatives with business objectives, managing IT risk, driving audit readiness, and...Ongoing contractLocal areaRemote workFlexible hours
$83.1k - $141.3k
...world's most sophisticated clients using leading technology and exceptional service. This... ...Cybersecurity Governance, Risk and Compliance (GRC) team within Northern Trust's Technology... ...'s or Master's degree in Information Security, Computer Science, or a related field....H1bFlexible hours$78.75 - $113.75 per hour
...TS SCI W/ CI Poly Cleared Vulnerability/GRC Lead Our client, a leader in the HCM space is in need of a GRC/Vulnerability Lead for a... ...individual will be working a hybrid schedule out of Reston VA, support security, compliance, and risk management initiatives. The Lead will be...Hourly payContract work- ...can be anywhere in the world. Reports to: Chief Information Security Officer (CISO) THE OPPORTUNITY HHP is commercializing the... ...evidence of a credible compliance program before they sign. The GRC Lead makes that evidence real. This role sits inside the CISO...Remote workWorldwideFlexible hoursAfternoon shiftWeekday work
$155k
...Job Posting Title: Cybersecurity GRC Team Lead ---- Hiring Department: Information Security Office ---- Position Open To: All Applicants ----... ...the university's research mission and enterprise IT operations. You will get to work with a very intelligent...Full timeFor contractorsWork at officeImmediate startRemote workFlexible hours$118.5k - $148k
...hiring Job Title: Cybersecurity GRC Lead Location: Burlington, MA (Hybrid -... ...supporting audits, inspections, and customer security assessments Strong analytical,... ...Trident Consulting is a premier IT staffing firm providing high-impact workforce...Full timeContract workWorldwideRelocation package$153.6k - $192k
...intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy and deep... ...with technical execution. As a Senior GRC Engineer, you will drive critical GRC processes... ...partners by producing documentation and leading training sessions Evangelize best...Work at officeImmediate startRemote workWork from home3 days per week$120k - $156k
...Clearsulting LLC is seeking a Consulting Manager for Governance, Risk & Compliance in Dallas, TX. You will lead implementations of Workiva GRC, manage project delivery, and engage with clients to assess their needs. This role requires 6+ years of relevant experience, strong...Remote workFlexible hours$135k - $150k
...leverage the power of our 300+ venues, leading sports franchises, marquee music... ...cheer! Job Summary The GRC Lead drives the execution and... ...management, compliance, and information security governance. They will contributor partner with IT, Legal, Privacy, Finance, and...Full timeWork experience placementLocal areaFlexible hours- - CMMC Champion and Head of IT Security and GRC - Direct Recruiters, Inc.# CMMC Champion and Head of IT Security and GRC## Job DescriptionCMMC... ...Hardware and Software) for DoD type customers.* Experience leading CMMC Certification at the corporate level for a similar type...Work at officeLocal areaMonday to Friday
- ...Westborough Workplace Flexibility: Hybrid Job Duties The Senior IT Security GRC Analyst (Global) is accountable for the following core... ...work experience (IT Security, GRC, etc.). At least 5 years of Lead/Manager experience. Thorough knowledge and understanding of Cybersecurity...Work experience placementLocal area
$153.6k - $192k
Brex is seeking a Senior GRC Engineer in Seattle to drive critical Governance, Risk, and Compliance processes. This role involves automating security controls and building integrations to maintain compliance as Brex expands. Candidates should have over 5 years of experience...- ...LVT (LiveView Technologies) in American Fork, Utah is seeking an Information Security Manager (GRC). This role involves managing SOC 2 audit processes, conducting risk assessments, and supporting regulatory adherence. The ideal candidate has over 5 years of experience...
- ...Job Title Information Security Consultant Job Description Conduct information security... ...monitoring, and data analytics. Plan and lead sub-tasks or smaller components of... ...industries (NIS2, GDPR, etc.) and experience with GRC platforms and risk management tools....Permanent employmentContract workRemote workFlexible hours
- ...world, moving beyond traditional security solutions to deliver AI-driven,... ...Information Security Manager (GRC) to join our growing... ...necessary. Collaborate with IT, Finance, and Legal to represent... ...~ Demonstrates an ability to lead effectively in dynamic, fast‑paced...Work at office
- Waterfront Training Solutions Inc. is seeking an IT Systems & Compliance Specialist in Chesapeake, VA. This full-time role focuses on achieving CMMC... ...certifications, and strong knowledge of network security. The position is strictly on-site, ensuring effective management...Full time
$175k - $275k
...critical infrastructure that developers need to securely scale their products to large... ...& response. We are expanding our internal GRC function to scale our compliance, risk, and... ...we ship software, not a separate track. Lead our next certifications. Drive initiatives...Contract workRemote work$148.5k - $223.9k
Overview The Public Sector GRC Lead role is part of Informatica's Security and Compliance organization, focusing on maintaining and expanding compliance authorizations that enable Informatica's cloud products to serve government customers at scale. The incumbent will serve...$160k - $190k
A technology firm in California seeks a Risk and Compliance Lead to manage security compliance initiatives across the organization. This role involves... ...candidate will have over 6 years of experience in security GRC, strong communication skills, and hands-on experience with...- A leading IT staffing firm in New Orleans is seeking a Lead IT GRC professional. This role offers an opportunity to be part of a collaborative team that prioritizes innovation and continuous learning. The company provides various career resources, training, and a comprehensive...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Security Specialist - GRC Lead. Be the first to apply!
- remote cyber security analyst United States
- cyber security analyst no experience United States
- junior cyber security analyst United States
- cyber security analyst United States
- information security consultant United States
- cyber security business analyst United States
- entry level cyber security analyst United States
- cyber security analyst internship United States
- cyber security operations analyst United States
- IT security analyst United States

