Jobs and Careers
RO

Governance Risk & Compliance Manager I (Contract Talent)

Robert Half
San Ramon, United Statesfull_timeVerifiedPosted 30 Dec 2024

About the role

Robert Half, one of FORTUNE’s World’s Most Admired Companies and a Fortune 100 Best Companies to Work For is hiring for a Governance Risk & Compliance Manager I to join the Data Privacy department.

What You'll Do:

  • Works closely with direct management, peers and subject matter experts to understand business requirements related to security, privacy and regulatory compliance, and to map those requirements to current security and project requirements with low complexity requirements. Ensure the continued adoption, maturity and growth of the following functional areas by adequate planning and sustained execution of required activities:
    • Information Risk Management
    • Compliance
    • Security and Data Privacy
    • Policy Lifecycle Management
    • Security Awareness
  • Work with other direct management to identify Information Security Policies that require low to intermediate complexity of updates and also track policy exceptions requested for existing policies. Support Policy awareness and monitoring activities for sustaining adequate compliance
  • Ensure that new projects and existing application and system implementations comply with applicable compliance frameworks and RH’s information security and data privacy requirements.
  • Act as an internal resource within Enterprise Information Security supporting EIS, ITSS, Protiviti CIO, CTO, and the Business for any security or privacy IT risk and ensure timely resolution of issues and initiatives of low complexity
  • Provide guidance to with the implementation, monitoring, and reporting of control processes, documentation, and compliance measures
  • Promote and manage the communication of best practices for enhanced collaboration among Information Security (InfoSec)
  • Identify opportunities for security posture improvement and closely partner with the larger InfoSec organization
  • Maintain the efficiency of the program as well as track results
  • Actively represent and show presence in the organization as a contributor to  security awareness and expanding knowledge through news bytes, providing their position on security effectiveness/exposures
  • Perform operational tasks associated with RHI Risk Management program, which will include monitoring risk decisions from stakeholders, tracking risk remediation efforts, conducting third party security assessments and responding to security and privacy customer RFI questionnaires

What You'll Need:

  • Direct Management and IT Management/ Control owners
  • Provide information, answers to security inquiries
  • Bachelor's Degree (B.A.) or equivalent combination of education and experience in Information Risk Management, Engineering, Management Information Systems or related curriculum
  • Basic understanding of systems development life cycle methodologies required
  • Capacity to learn GRC methodologies, risk analytic tools and development of information risk metrics required
  • Capacity to learn about executing activities related to Information Security Policy Lifecycle required
  • Capacity for learning to review and respond to security and compliance questions in RFIs required
  • Limited knowledge of Application Security, Infrastructure security, audit, and control methods
  • Capacity to learn about gap analysis assessments, review and validation of relevant security, privacy and regulatory requirements
  • 1 or more Professional certifications from ISACA (CISA, CISM), (ISC)2 (CISSP), IAPP (CIPP, CIPP/IT), not needed but a plus
  • Excellent communication, teamwork and client service skills.
  • Demonstrated integrity within a professional environment
  • Experience interacting with external auditors, management, and internal resources to discuss and address security concerns not mandator but a plus
  • Self learner and ability to work in an agile and cross functional environment.
  • General project management skills.
  • Results-oriented person who can achieve tangible improvements in the corporate security arena.  
  • Strong analytical/troubleshooting skills
  • Aptitude to prioritize tasks
  • Strong organizational, time management, decision making, and problem solving skills
  • A professional with a some understanding of  information risk and compliance principles, theories, and concepts. General knowledge of related disciplines
  • Works on problems of diverse scope where analysis of data requires evaluation of identifiable factors
  • Demonstrates good judgment in selecting methods and techniques for obtaining solutions. Interacts with senior internal and external personnel
  • Normally receives moderate instruction on day-to-day work, general instructions on new assignments

The typical hourly pay rate for this p

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Robert Half

View company profile →