THE TEAM YOU WILL BE JOINING
- Established enterprise organization continuing to expand and mature its Information Security function
- Growing security team creating greater specialization across Security Engineering, Security Operations, and Governance, Risk & Compliance
- Opportunity to join at an important stage in the evolution of the organization's GRC program
- Collaborative role partnering across Information Security, IT, Human Resources, system owners, and business leadership
- Environment where strong documentation, practical risk management, and cross-functional partnership are highly valued
WHAT THEY OFFER YOU
- Direct-hire opportunity within a growing Information Security organization
- Ability to take meaningful ownership across governance, risk, compliance, policy, and third-party risk initiatives
- Opportunity to help mature and standardize security policies, controls, procedures, and audit processes
- Exposure to recognized security and control frameworks including NIST, CIS Controls, SOC 2, and SOX
- Highly collaborative role with visibility across technology and business functions
- Opportunity to become a key individual contributor within the organization's evolving GRC function
WHAT YOU WILL DO
- Maintain and improve information security policies, standards, procedures, control documentation, and supporting governance materials
- Help align the organization's security program with frameworks including the NIST Cybersecurity Framework and CIS Controls
- Manage and maintain the organization's risk register and risk acceptance processes
- Document identified risks, compensating controls, owners, remediation plans, exceptions, and ongoing review activity
- Coordinate third-party and vendor security assessments, questionnaires, supporting documentation, and evidence
- Review contractual, regulatory, customer, and audit requirements to identify required controls and documentation
- Support SOC 2, SOX, and other internal or external audit activities
- Coordinate evidence collection, control walkthroughs, issue tracking, and remediation follow-up
- Develop repeatable audit procedures, workpapers, processes, and supporting documentation
- Prepare risk and compliance metrics and updates for leadership and other stakeholders
- Work cross-functionally to identify control gaps, document findings, assign remediation ownership, and drive items through completion
- Support identity and access control reviews when necessary, while maintaining a broader focus on governance, compliance, policies, procedures, and risk management
BACKGROUND PROFILE
- 3+ years of experience within Governance, Risk & Compliance, IT Audit, Risk Management, Information Security Compliance, or a related discipline
- Working knowledge of a recognized security or control framework such as NIST Cybersecurity Framework or CIS Controls
- Experience supporting internal or external audits and collecting and organizing supporting evidence
- Strong understanding of risk assessments, control design, control testing, remediation tracking, and policy documentation
- Experience with third-party or vendor risk management is highly valuable
- Exposure to SOC 2, SOX, or similar compliance environments preferred
- Ability to interpret technical security information and communicate findings to both technical and business stakeholders
- Experience with GRC, ticketing, workflow, or audit-management technologies such as ServiceNow GRC, Archer, Jira, or similar platforms
- Familiarity with Active Directory and Microsoft Entra ID is beneficial, particularly around access reviews and audit evidence
- Strong documentation, organization, analytical, and follow-through skills
- Experience in a regulated or critical-infrastructure environment is beneficial but not required
- Certifications such as CISA, CRISC, Security+, or ISO 27001 are valuable but not required
LOCATION
- Fort Mill, SC
- Onsite



