> Markdown version of [/jobs/ext/3428653-security-grc-specialist](https://www.wearedevelopers.com/jobs/ext/3428653-security-grc-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security GRC Specialist - **Company:** BIOMEDICAL SYSTEMS USA LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Systems, Smartsuite, Information Technology - **Published:** September 9, 2026 - **Apply:** https://startup.jobs/sr-security-governance-risk-compliance-specialist-us-biomedical-systems-india--9974703 ## About the Role * Bachelor's degree in Information Systems, Information Technology, Cybersecurity, or a related field. An Associate's degree may be considered based on relevant experience and certifications. * 5+ years of experience in Information Technology, Information Security, Governance, Risk, and/or Compliance. * Strong experience building, maintaining, or maturing Security Governance, Risk, and Compliance programs. * Solid understanding of information security risk management and compliance methodologies. * Experience facilitating and leading risk discussions using both qualitative and quantitative information. * Knowledge of common information security and IT frameworks, including ISO/IEC 27001, NIST Cybersecurity Framework, NIST 800-53, COBIT, and ITIL. * Experience supporting or coordinating security audits, assessments, certifications, and client assurance activities. * Experience with third-party/vendor security risk management. * Understanding of solution lifecycle management and associated information security and compliance requirements. * Experience developing and implementing Standard Operating Procedures (SOPs), policies, and processes. * Strong ability to influence and collaborate with stakeholders at different levels, including situations where formal authority is not present. * Demonstrated ability to establish and leverage internal and external cross-functional relationships. * Strong business acumen and the ability to understand business needs and translate them into practical security and compliance solutions. * Excellent written and verbal communication skills, with the ability to communicate security risks, findings, recommendations, and requirements to both technical and non-technical audiences. * Experience working with globally distributed teams and stakeholders. * Strong learning agility and ability to adapt to evolving security risks, regulations, technologies, and business requirements. * Relevant security certifications are preferred, such as CISSP, CRISC, CISM, CISA, or FAIR. ## Description The role will help drive security and compliance initiatives, support risk management activities, coordinate audits and certifications, manage third-party security risk, and continuously improve security governance, policies, processes, and controls. What You'll Be Doing * Security Governance, Risk & Compliance: Support and mature the organization's Security GRC program, helping ensure IT, Product, and Information Security controls align with applicable policies, standards, regulations, and best practices. * Audit & Assessment Coordination: Coordinate and support external client audits, certifications, and assessments, including SOC 1, SOC 2, ISO 27001/2700x, client audits, and other security assessments or accreditations. * Compliance Monitoring: Evaluate the compliance status of IT, Product, and Information Security controls. Partner with control owners to identify gaps, develop remediation plans, track progress, and drive issues through resolution. * Risk Management: Support the organization's risk management framework, including assessing inherent and residual risk, evaluating risk tolerance, facilitating risk discussions, and supporting periodic internal and third-party risk assessments. * Third-Party Risk Management: Execute established processes to assess, monitor, and manage information security risks associated with third parties, vendors, and other external partners. * Client Assurance & Regulatory Support: Serve as a key point of contact for QA, Regulatory, Customer, and other stakeholder interactions related to security and compliance. Support responses to audits, client questionnaires, RFPs, findings, and other assurance requests. * Policy & Standards Governance: Support the development, maintenance, and governance of the Information Security policies, standards, procedures, and related documentation. * Process Improvement: Identify opportunities to improve and mature IT and Information Security compliance processes. Use industry standards, emerging risks, regulations, and stakeholder feedback to recommend practical improvements. * Security Frameworks: Apply standards and best practices from frameworks such as ISO/IEC 27001, NIST, COBIT, and ITIL to support the organization's security and compliance objectives. * Reporting & Metrics: Develop compliance and risk reports, metrics, and management insights to communicate the status of key risks, controls, remediation activities, and compliance initiatives to stakeholders at various levels. * Security Awareness: Support security education and awareness initiatives by helping communicate new policies, procedures, and security practices to IT teams and the broader organization. * Cross-Functional Collaboration: Build strong relationships across technical and non-technical teams and influence stakeholders to support security, compliance, risk management, and governance objectives. * Program & Process Support: Contribute to the selection, implementation, improvement, and management of GRC tools, platforms, processes, and operational procedures. * Prioritization & Delivery: Effectively prioritize multiple initiatives and deliverables while maintaining a high level of quality and attention to detail. * Perform other related duties and projects as assigned.