Cybersecurity GRC Specialist II

Kirkland and Ellis
Austin, TX, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$116,000.0 - $144,000.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence User Authentication Cyber Security Intrusion Detection and Prevention Information Systems Security Architecture Professional Smartsuite Security Information and Event Management Mobile Security Software Vulnerability Management Firewalls (Computer Science) Information Technology RSA Archer Platform

Job description

Are you driven to strengthen security programs, reduce risk, and help organizations meet evolving cybersecurity expectations?

As a Security GRC Specialist II, you’ll be a key member of the Governance, Risk, and Compliance (GRC) team, leading and executing core GRC programs while serving as a trusted Information Security subject matter expert. This role blends strategic oversight with hands-on execution-partnering with technical teams, business stakeholders, clients, and vendors to ensure security controls, policies, and risk practices are effective, compliant, and clearly communicated.

What You’ll Do

  • Client & Third-Party Assessments: Lead responses to client security assessments, questionnaires, and audits, documenting evidence and performing risk assessments as needed.
  • Policy & Standards Management: Create, maintain, and evolve security policies, standards, guidelines, and supporting documentation through strong technical writing.

  • Risk & Compliance Assurance: Manage and support processes that ensure Information Technology (IT) systems meet cybersecurity, risk, and compliance requirements.

  • Security Consulting & SME Support: Serve as an Information Security subject matter expert, advising technical and non-technical stakeholders across the organization.

  • Vendor Risk Management: Manage the third-party Security Vendor Risk Management program, including assessments, remediation tracking, and lifecycle oversight.

  • Exception & Risk Treatment: Oversee the security exception request process and provide guidance on appropriate risk treatment decisions.

  • Security Awareness Program: Manage the full lifecycle of the Security Awareness program, including roadmap development, training evaluation, and effectiveness measurement.

  • GRC Platform Administration: Support and optimize Governance, Risk, and Compliance (GRC) technology platforms and associated workflows.

  • Controls & Compliance Evaluations: Conduct evaluations of IT programs and components to confirm alignment with published security standards and frameworks.

Requirements

Do you have experience in Regulatory Frameworks (Architecture security)?, Do you have a Bachelor’s degree?, * Education: Bachelor’s degree or equivalent with five (5) years of work experience in IT Security is required.

  • Certifications: Certified Information Systems Security Professional (CISSP), Certified Information Security Auditor (CISA), Certified Information Security Manager (CISM), Advanced in AI Audit (AAIA), Advanced in AI Risk (AAIR), Advanced in AI Security Management (AAISM) or other relevant training and certifications are preferred.
  • Information Security Experience: Four (4) or more years of Information Security experience, with hands-on technical experience strongly preferred.
  • Framework & GRC Knowledge: Strong working knowledge of security frameworks and standards such as ISO 27001, National Institute of Standards and Technology (NIST), System and Organization Controls (SOC), and Standardized Information Gathering (SIG) is required.
  • AI Risk: Experience in Artificial Intelligence (AI) governance, security, and risk management is required.
  • Technical Writing & Communication: Proven ability to produce clear, well-structured security documentation and communicate complex technical topics to varied audiences.
  • Risk & Vendor Management Skills: Experience leading risk assessments, vendor security reviews, and client-facing security discussions with professionalism and tact.
  • GRC Tools & Technologies: Familiarity with GRC platforms, role-based access controls, and a broad range of security technologies and tools.
  • Analytical & Organizational Strength: Strong problem-solving, project management, and time management skills with the ability to work independently or collaboratively.
  • Technical Acumen: Working knowledge of areas such as authentication, encryption, firewalls, SIEM, intrusion detection/prevention, vulnerability management, mobile security, and privileged access management.
  • Collaboration & Professionalism: Client-focused mindset with strong interpersonal skills, attention to detail, and a commitment to maintaining accurate records and documentation.

Benefits & conditions

401 West 4th Street, Austin, TX 78701, Hybrid work $116,000 - $144,000 a year - Full-time, Pulled from the full job description

  • Health insurance
  • Paid time off, The base salary range below represents the low and high end of the salary range for this position in Chicago. This range may differ based on your geographic location and cost of living considerations. At Kirkland & Ellis, we consider compensation more than just a base salary. We offer an exceptional range of flexible benefits including comprehensive healthcare, paid time off, and retirement. We also offer personal support and tailored learning and development opportunities all designed to help you realize your full potential both in life and at work.

Compensation Range:

Chicago: $116,000 - $144,000

About the company

At Kirkland & Ellis, we don’t just meet the standard for legal excellence - we set it. Our culture is built on teamwork, ingenuity and an unwavering commitment to continuous growth. We tackle the most sophisticated legal challenges with bold ideas and innovative solutions, powered by the exceptional experience and ambition of our 7,000+ people, including 4,000+ attorneys, across 23 offices worldwide. Our dedicated professionals share our lawyers’ commitment to excellence and show up each day to do meaningful work that helps drive global business, investment and innovation forward.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

4:15 min

Scaling DevSecOps and researching mobile application security standards

Moataz Nabil Moataz Nabil · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar · WWC 2023

10:42 min

Essential soft skills and evaluating security candidates

Kurt Eder · LIVE

2:04 min

Challenges of maintaining security in rapid mobile app delivery

Moataz Nabil Moataz Nabil · LIVE

Videos

See all

Related articles

See all