Velsera

    Senior InfoSec GRC Specialist

    Velsera
    Posted 11/5/2025Lead/Manager
    Full-time
    Technology
    Information Security
    GRC
    Risk Management
    Compliance
    Governance

    Job Description

    What will you do? Compliance & Governance Develop, implement, and maintain comprehensive information security policies, standards, and procedures aligned with the ISO 27001 framework Lead, manage, and mature the organization's Information Security Management System including risk treatment, internal audits, and readiness for external certification audits. Serve as the subject matter expert (SME) for Security and Privacy Rules, ensuring compliance for all systems, processes, and applications handling PII and Protected Health Information (PHI). Conduct continuous monitoring and evidence collection to demonstrate compliance with relevant frameworks. Plan, conduct and manage internal and supplier audits Plan GRC activities, prioritise and implement them in timebound manner. Perform detailed security risk assessments and gap analyses on new and existing systems, with a focus on cloud infrastructure Collaborate with Product, Technology, IT and Security teams to implement security controls into cloud / infra / environments, ensuring compliance. Provide technical guidance to them on implementing controls and best practices, specifically related to cloud security architecture and configurations. Review risk mitigations periodically and track remediation efforts to closure. Conduct third-party vendor risk assessments, focusing on their adherence to required compliance standards. Develop and deliver targeted security awareness and training programs focused on HIPAA and ISO 27001 requirements for all staff, including technical teams. Evaluate and recommend new security technologies and processes to enhance the compliance and risk posture. Stay current on emerging cloud security threats, regulatory changes, and updates to the ISO 27001 family of standards and HIPAA. What do you bring to the table?

    · Experience:

    • Minimum of 8+ years of progressive experience in Information Security GRC, with a focus on risk management, compliance, and governance.
    • Proven, hands-on experience driving and maintaining ISO 27001 certification programs.
    • Deep practical knowledge and experience of implementing security controls ensuring compliance in a technical, cloud-centric environment.
    • Strong technical competency in Cloud Security (AWS, Azure, or GCP) and related cloud-native security services.
    • Education: Bachelor's degree in IT, Computer Science or related field.

    Certifications (One or more highly preferred):

    CISSP (Certified Information Systems Security Professional) CISA (Certified Information Systems Auditor) ISO 27001 Lead Implementer/Auditor

    • CCSK (Certificate of Cloud Security Knowledge) or equivalent Cloud-specific security certification (e.g., AWS Certified Security, Azure Security Engineer).

    Soft Skills

    • Proficiency in written and verbal communication skills with the ability to translate complex security and compliance requirements / controls into clear actionable
    • Strong project management and organizational skills to handle multiple, simultaneous audit and compliance initiatives.
    • A collaborative and proactive mindset, with the ability to influence and lead cross-functional teams without direct authority.
    • Flexible Work & Time Off - Embrace hybrid work models and enjoy the freedom of unlimited paid time off to support work-life balance.
    • Health & Well-being - Access comprehensive group medical and life insurance coverage, along with a 24/7 Employee Assistance Program (EAP) for mental health and wellness support.

    Growth & Learning - Fuel your professional journey with continuous learning and development programs designed to help you upskill and grow. Recognition & Rewards - Get recognized for your contributions through structured reward programs and campaigns. Engaging & Fun Work Culture - Experience a vibrant workplace with team events, celebrations, and engaging activities that make every workday enjoyable. & Many More...

    💼 Want More Jobs Like This?

    Get similar opportunities delivered to your inbox. Free, no account needed!

    Similar Jobs You Might Like

    QA Engineer - CMS Sitecore

    PTC
    Not specifiedabout 2 hours ago
    Full-time
    QA Engineering
    CMS
    Sitecore
    Functional Testing
    Data Validation

    Product Designer

    Nex
    RemoteNot specifiedabout 3 hours ago
    Full-time
    Product Design
    User Experience
    UI Design
    Prototyping
    User Research

    Sr. Business Technology Support Specialist

    Samsara
    Not specifiedabout 3 hours ago
    Full-time
    SaaS Applications
    Okta
    Google Workspace
    Slack
    Zoom

    PaaS-SaaS-DevOps Engineer (REMOTE)

    NTT DATA
    Not specifiedabout 3 hours ago
    Full-time
    Azure
    PaaS
    DevOps
    Terraform
    Data Pipelines

    Want to see all 20,708 jobs?

    You're currently viewing 1 out of 20,708 available remote opportunities

    🔒 20,707 more jobs are waiting for you

    Unlock All Jobs

    Access every remote opportunity

    Advanced Filters

    Find your perfect match faster

    Daily Updates

    New opportunities every day

    Save & Alerts

    Never miss an opportunity

    Weekly
    $4
    Perfect for quick searches
    POPULAR
    Monthly
    $12
    Best for active job seekers
    Yearly
    $48
    Save 67% • Best value
    Unlock All 20708 Jobs

    Join thousands of remote workers who found their dream job

    Frequently Asked Questions

    What's included in premium access?

    Premium members get unlimited access to all remote job listings, advanced search filters, job alerts, and the ability to save favorite jobs.

    Can I cancel anytime?

    Yes! You can cancel your subscription at any time from your account settings. You'll continue to have access until the end of your billing period.

    Do you offer refunds?

    We offer a 7-day money-back guarantee on all plans. If you're not satisfied, contact us within 7 days for a full refund.

    Is my payment secure?

    Absolutely! We use Stripe for payment processing, which is trusted by millions of businesses worldwide. We never store your payment information.