Jobs and Careers
IV

Government Risk and Compliance (GRC) Lead

Ivalua
New York City, United Statesfull_timeVerifiedPosted 13 Mar 2025
💰 $208,000/yr($112,000/yr$208,000/yr)

About the role

Governance Risk and Compliance (GRC) Lead 

(New York City - US)

Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions.

COMPANY OVERVIEW

At Ivalua we are a global community of exceptional professionals, who believe that digital transformation revolutionizes supply chain sustainability and resiliency to unlock the power of supplier collaboration. 

We achieve this through our leading cloud-based spend management platform that empowers hundreds of the world's most admired brands to effectively manage all categories of spend and all suppliers to increase profitability, improve ESG (environmental, social, and corporate governance) performance, lower risk, and improve productivity. Driven by our passions and fueled by our shared ambitions, we empower and challenge each other to create meaningful experiences for our colleagues, customers, partners, and communities. 

 

Learn more at www.ivalua.com. Follow us on LinkedIn and Twitter.

THE OPPORTUNITY

CONTEXT:

Our team is very hands-on with a strong mindset of problem solving while also having the ability to think of the implementation holistically and provide solutions that solve the customer’s long-term challenges. Our team works hard, plays hard and enjoys all indoor and outdoor activities that the company organizes from time to time, so that you can focus, work collaboratively, and be at your creative best. 

With over 60 global team members, the IT team works hard, plays hard and enjoys all indoor and outdoor activities that the company organizes from time to time, so that you can focus, work collaboratively, and be at your creative best. 

ROLE: 

This is an exciting opportunity for a GRC lead. You will be part of the InfoSec team with a mission to  build, maintain and continuously improve its Information Security program, giving peace of mind, assurance of protection and safety to our customers. 

WHAT YOU WILL DO WITH US 

  • Lead security self assessments, audits, certifications for various compliance initiatives e.g. OC1/SOC2, ISO 27001, FedRAMP, IRAP, PCI-DSS, SecNum Cloud, CE+, BSI C5, NIST 800-53 etc.
  • Understand and assess technical controls at different layers of TCP/IP model, including evaluating technical control implementation and communicating clear and actionable requirements to various technical teams
  • Coordinate and manage customer security audits and contract reviews for AMER region and support other regions
  • Effectively respond to InfoSec questions and present technical architecture and security controls to customers and prospects 
  • Perform continuous compliance and monitoring capabilities, including executing on various security and availability controls (e.g. BIA,  DR testing, security incident response, etc.) 
  • Manage the security incident response process (responding to reported security incidents, working closely with key stakeholders to coordinate incident remediation efforts, ensure proper communication and task assignment during incident response, etc.)
  • Help automate and enhance security operation processes
  • Support Governance, Risk & Compliance (GRC) tools implementation and utilization

YOUR PROFILE

If you have the below experience and strengths this role could be for you:

Skills and Experience:

  • Preferred Bachelor’s Degree in a related field or equivalent experience
  • At least 5 years experience working with IT and security personnel as well as security concepts at all layers of a technology (e.g. Network, Infrastructure, Web Application, Cloud Platforms (e.g. Azure, AWS, GCP) environments
  • Strong working knowledge of a broad range of audit and Information Security frameworks (NIST CSF & 800-53, ISO27001, SOC, HITRUST, HIPAA, FedRAMP, PCI, GDPR, etc.)
  • Hands on experience in leading  audits/reviews against some of the InfoSec frameworks mentioned above
  • Knowledge of risk and security industry literature and knowledge bases (OWASP, MITRE ATT&CK, NIST 800-39, etc.)
  • Relevant audit and/or Information Security certifications (e.g., CISSP, CISA, CISM, Azure Cloud Security) are desired

Soft Skills :

  • Excellent interpersonal, communication and organizational skills
  • Team player with the ability to interface effectively with a broad range of individuals and roles, including IT and vendors
  • High degree of initiative, dependable and able to work well with limited supervision

WHAT HAPPENS NEXT<

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Ivalua

View company profile →