> Markdown version of [/jobs/ext/2508637-grc-specialist](https://www.wearedevelopers.com/jobs/ext/2508637-grc-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Specialist - **Company:** STRATASYS LIMITED - **Location:** United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Access Network, Cyber Security, Security Information and Event Management, Software Vulnerability Management, Information Technology - **Published:** August 12, 2026 - **Apply:** https://careers.stratasys.com/talentcommunity/apply/1418528400/?locale=en_US ## About the Role * 4+ years of experience in Governance, Risk & Compliance (GRC), Information Security, Cybersecurity, or a related discipline. * Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field * Strong understanding of cybersecurity frameworks and standards such as ISO 27001 and NIST Cybersecurity Framework. * Hands-on experience with security technologies such as SIEM, endpoint security, DLP, vulnerability management, or similar security platforms. * Strong analytical and problem-solving skills with the ability to assess security risks and recommend practical solutions. * Experience working across multiple stakeholders and cross-functional teams. * Excellent written and verbal communication skills in English. ## Description We're looking for a GRC Specialist to help strengthen our cybersecurity governance, risk, and compliance practices across a global organization. In this role, you'll work closely with IT, Engineering, Procurement, and business teams to ensure our security controls, third-party risk management, and compliance processes support a secure and resilient business environment. This is an excellent opportunity to join a collaborative cybersecurity team and make a meaningful impact on the security posture of a global technology company. What You'll Do: Vulnerability Management * Support the organization's vulnerability management program through CVE monitoring, risk prioritization, and coordination of remediation activities. * Work closely with technical teams to improve software and infrastructure security and drive timely resolution of security findings. Identity & Access Governance * Manage identity governance activities, including access reviews, permission recertification campaigns, and user lifecycle processes. * Monitor privileged and high-risk accounts and support continuous improvement of access control practices. Security Governance & Compliance * Support security awareness initiatives across the organization. * Contribute to maintaining ISO 27001 compliance by supporting audits, control reviews, documentation, and governance activities. * Participate in continuous improvement initiatives to strengthen cybersecurity processes and controls. Supply Chain & Third-Party Security * Conduct security assessments and approvals for suppliers and third-party vendors. * Evaluate connectivity requests, network access, and security controls for internal and external integrations. * Help ensure third-party engagements align with Stratasys security policies and risk management standards. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)