- Company Name
- BlueSky Resource Solutions
- Job Title
- Lead GRC Engineer
- Job Description
-
Job Title: Lead GRC Engineer
Role Summary: Lead the organization’s Governance, Risk & Compliance program, driving risk assessment, remediation, and audit readiness across IT infrastructure, applications, and third‑party services while ensuring alignment with regulatory frameworks and internal policies.
Expactations:
- Deliver comprehensive risk management and GRC strategies for insurance/financial services environments.
- Act as a primary liaison between IT, compliance, legal, and audit functions.
- Maintain audit‑ready evidence and documentation for SOC 2, ISO 27001, and similar standards.
Key Responsibilities
- Identify, assess, and quantify technology risks across infrastructure, applications, and third‑party services.
- Develop and implement risk remediation plans in partnership with engineering, security, and business units.
- Escalate high‑impact risks to senior leadership with clear business impact analysis and mitigation recommendations.
- Implement and continuously improve GRC frameworks, tools, and best practices (e.g., COBIT, NIST, ISO 27001/2, SOC 2).
- Evaluate IT controls related to access management, change management, data protection, and related areas.
- Support internal and external audits (SOC 2, ISO 27001, etc.) by providing documentation, evidence, and analysis.
Required Skills
- 7+ years in IT risk, audit, or GRC roles within insurance or financial services.
- Proficient in risk management principles and control frameworks (COBIT, ISO 27001, SOC 2).
- Knowledge of cybersecurity regulations such as NYDFS 23 NYCRR 500.
- Experience with GRC platforms (Archer, ServiceNow GRC, OneTrust) and cloud technologies (AWS, Azure).
- Strong analytical, documentation, and communication skills; ability to translate technical risks into business terms.
Required Education & Certifications
- Bachelor’s degree in Information Systems, Cybersecurity, Business Administration, or related field.
- Professional certifications highly desirable: CRISC, CISA, CISSP.