Description -
Job Summary: We are seeking a highly skilled and experienced GRC Principal to join our team. The ideal candidate will have a deep understanding of the Factor Analysis of Information Risk (FAIR) model, the NIST Cybersecurity Framework (CSF), and be proficient in leveraging the SafeSecurity platform. With over 10 years of experience in Governance, Risk, and Compliance (GRC), with a strong emphasis on risk management, this individual will play a critical role in enhancing our GRC capabilities.
Key Responsibilities:
Lead the development and implementation of cyber risk management strategies using the FAIR model and SafeSecurity platform.
Conduct comprehensive risk assessments and quantify cyber risks in terms of loss magnitude and likelihood.
Collaborate with cross-functional teams to identify, assess, and mitigate cyber risks.
Provide expert guidance on GRC practices and ensure compliance with industry standards and regulations.
Implement and integrate the NIST Cybersecurity Framework (CSF) into the organization's GRC practices.
Develop strategies to align the organization's cybersecurity efforts with the NIST CSF, including identifying, protecting, detecting, responding, and recovering from cyber threats.
Communicate risk findings and recommendations to senior leadership and stakeholders.
Stay current with emerging cyber threats, vulnerabilities, and best practices in risk management.
Qualifications:
Bachelor's degree in Information Security, Cybersecurity, Risk Management, or a related field. Advanced degree preferred.
Minimum of 10 years of experience in GRC, with a strong emphasis on risk management.
In-depth knowledge of the FAIR model and experience using the SafeSecurity platform.
Proven track record of conducting risk assessments and developing risk mitigation strategies.
Strong understanding of the NIST Cybersecurity Framework (CSF) and experience implementing it in GRC practices.
Strong understanding of industry standards and regulations related to cybersecurity and risk management.
Excellent analytical, problem-solving, and communication skills.
Ability to work effectively in a fast-paced, dynamic environment.
Preferred Skills:
Certifications such as CISSP, CISM, CRISC, or similar.
Experience with other cyber risk management frameworks and tools.
Strong leadership and project management skills.
Disclaimer
• This job description describes the general nature and level of work performed in this role. It is not intended to be an exhaustive list of all duties, skills, responsibilities, knowledge, etc. These may be subject to change and additional functions may be assigned as needed by management.
Job -
Data & Information TechnologySchedule -
Full timeShift -
No shift premium (United States of America)Travel -
Relocation -
Equal Opportunity Employer (EEO) -
HP, Inc. provides equal employment opportunity to all employees and prospective employees, without regard to race, color, religion, sex, national origin, ancestry, citizenship, sexual orientation, age, disability, or status as a protected veteran, marital status, familial status, physical or mental disability, medical condition, pregnancy, genetic predisposition or carrier status, uniformed service status, political affiliation or any other characteristic protected by applicable national, federal, state, and local law(s).
Please be assured that you will not be subject to any adverse treatment if you choose to disclose the information requested. This information is provided voluntarily. The information obtained will be kept in strict confidence.
If you’d like more information about HP’s EEO Policy or your EEO rights as an applicant under the law, please click here: Equal Employment Opportunity is the Law Equal Employment Opportunity is the Law – Supplement
HP is looking for an Inside Sales Account Manager skilled in consultative selling and customer relationship management to drive revenue and meet sales targets.
Experienced Help Desk Specialist needed to provide remote support for the Air Force’s Core Engine Maintenance System, ensuring technical issue resolution and security compliance.
Experienced GIS Analyst wanted to support DOJ Civil Rights Division with mapping, analysis, and reporting using ESRI ArcGIS and demographic datasets.
Security Control Assessor Representative needed to support Aretum’s federal government clients by assessing security controls and facilitating authorization processes remotely.
An experienced Cloud IAM Security Engineer is needed to lead identity and access management initiatives for Multi Media, LLC, securing millions of users on a global live streaming platform.
Support critical Air Force IT operations at Hanscom AFB as an Information Technology Specialist with Credence, focusing on secure network environments and communications.
Navitus is hiring a Developer I to deliver innovative, customer-focused solutions through Dynamics 365 CRM and related enterprise systems.
An IT Consultant with MSP experience is needed at Saltmarsh in Tampa to provide client IT support and contribute to technology projects within a supportive and growth-driven environment.
Experienced cybersecurity professional sought to serve as ISSO III supporting DoD compliance and security at the Naval Surface Warfare Center Philadelphia Division.
Target's Cybersecurity team is looking for a skilled Senior Engineer to enhance threat detection capabilities using cutting-edge tools and intelligence.
Morgan Stanley is looking for a skilled DevOps Engineer to join their Threat Hunt team and defend their global network through innovative data and security engineering solutions.
Support the VA’s enterprise Entra ID systems as a remote Tier 1 System Administrator resolving technical issues and managing help desk ticket queues.
Experienced Information System Security Manager needed to oversee federal compliance and security programs in a remote contingent role for ARETUM.
ComplexCare Solutions is looking for a skilled Endpoint Services Administrator to deliver exceptional remote IT support and manage workstation environments.