עדיין מחפשים עבודה במנועי חיפוש? הגיע הזמן להשתדרג!
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
We are seeking a skilled and experienced Cyber GRC Lead to join Alice (Formerly ActiveFence) CISO team. The ideal candidate will be responsible for driving the security initiatives.
Key Responsibilities:
- Third-Party Risk Management (TPRM) & Supply Chain Security:
- Lead the end to end Operational TPRM lifecycle, assessing and continuously monitoring the security postures of vendors, SaaS platforms, AI tool providers.
- Establish risk criteria for third party tools, ensuring third party AI integrations do not introduce data leakage, or intellectual property risks.
- Security Awareness & Culture & Behavioral Programs:
- Design and manage the enterprise wide security awareness and training program using modern platforms.
- Conduct targeted phishing simulations, role based security training and specialized training among others on GenAI risks (prompt injection, shadow AI, data exposure).
- Customer Due Diligence (DDQs) & Sales Enablement:
- Manage and streamline the end to end customer security assessment process (DDQs, RFPs, Security Questionnaires, customer audits).
- Build and maintain a centralized, automated knowledge base to expedite responses, directly removing friction from sales velocity and supporting enterprise revenue goals.
- Risk Management Frameworks & Risk Advisory:
- Lead ongoing security risk assessments, maintaining a dynamic Risk Register mapped to real world business impacts.
- Provide continuous risk advisory services across business units, establishing risk treatment and mitigation plans that balance operational agility with guardrails.
- GRC Automation & Continuous Compliance:
- Architect and leverage high-level GRC automation tools to move from point in time audits to continuous control monitoring.
- Drive process automation for evidence collection, vendor assessments, and policy management to reduce manual overhead across technical teams.
- Compliance, Frameworks & AI Governance:
- Maintain core information security certifications (ISO 27001, SOC 2 Type II, etc)
- Build, operationalize, scale the organization's AI Governance Framework, referencing established benchmarks (NIST AI RMF, ISO/IEC 42001).
- Lead internal and external audit readiness, acting as the primary liaison for independent auditors.
- Close Collaboration with Legal, Privacy & DPO:
- Partner directly with Legal and Privacy teams to operationalize global data protection standards (GDPR, CCPA, EU AI Act) align security controls with contractual commitments.
Professional Experience:
- 4+ years of hands on experience in Cyber GRC, IT audit, or security consulting within global, fast paced technology companies.
- Proven track record of owning SOC 2 Type II and ISO 27001 compliance lifecycles.
- Direct experience partnering with Legal and Privacy teams on GDPR compliance and privacy risk assessments.
- Demonstrated track record handling customer DDQs, vendor security reviews (TPRM), and managing security awareness platforms.
- Technical, Automation & AI Capabilities:
- Strong technical proficiency in utilizing GRC automation platforms to automate control testing, evidence gathering, and vendor workflows.
- Working knowledge of cloud security (AWS/GCP/Azure), AI/ML operational risks
- Deep familiarity with core frameworks: NIST CSF, ISO 27001, NIST AI RMF, ISO 42001.
- Leadership & Stakeholder Management:
- Exceptional communication and negotiation skills, capable of translating complex security and compliance demands into clear business terms
- A pragmatic, business first mindset focused on designing guardrails that empower teams rather than introducing operational roadblocks.
- Fluent in professional English (written and verbal).
Preferred Qualifications (Pluses):
- Industry certifications: CISA, CRISC, CISM, CISSP, CIPP/E, or IAPP AIGP.
- Experience with automated TPRM and vendor intelligence solutions
- Practical scripting capabilities to custom build or tie together GRC automation workflows.
Alice is a trust, safety, and security company built for the AI era. We safeguard the communicative technologies people use to create, collaborate, and interact—whether with each other or with machines.
In a world where AI has fundamentally changed the nature of risk, Alice provides end-to-end coverage across the entire AI lifecycle. We support frontier model labs, enterprises, and UGC platforms with a comprehensive suite of solutions: from model hardening evaluations and pre-deployment red-teaming to runtime guardrails and ongoing drift detection.
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.