Haystack
← Back to Jobs
Other
ST

GRC Architect

SRI Tech SolutionsUnited States🇺🇸United StatesPosted 8 Sept 2026

Why This Role Stands Out

Shape the future of cybersecurity strategy and architecture with SRI Tech Solutions, a company recognized for its innovation and commitment to growth. You will thrive in this hybrid role if you are a mid-senior GRC professional eager to integrate cyber risk into enterprise strategy and build a strong security culture. This is an excellent opportunity to develop your expertise and make a significant impact.

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
United States
Posted
22 hours ago
CompliancePenetration TestingRegulatory ComplianceRisk Management

Job Description

A.           Governance

• Security policy management

• Cybersecurity strategy

• Security architecture – secure by design

• Security metrics and executive reporting

• Build cyber culture and awareness and training  run monthly and quarterly reporting for 10 phishing templates provided by the vendor. Review and administer quarterly security phishing training which may require light contextual changes to templates. 

• Confirm ZeroFox program is running accurately for look-alike domains and report gaps to the IP team. Recommend any configuration changes as appropriate. 

• Review Holisticyber usage and monitor usage relative to license and provide commentary on risk associated with data. Provide support for customer compliance by filling out the holisticyber TPRM. If a prospective third party has not filed, vCISO will coordinate with the business partner and the third party for remediation. VCISO will also consult and advise on findings with the L4 team and provide recommendations to business partners and register on the risk register when required. These should be at a rate of ~10 a month maximum with only a portion requiring interaction. Additionally, vCISO may be required to provide TPRM responses to groups Client wishes to sell services to. In this instance vCISO would be responsible for approximately 1 per month.  

b. Risk Management

• Integrate cyber risk with enterprise-wide risk strategy

• Manage risk register

• Third party risk management

• Risk Remediation, acceptance, and tracking with use of IT-RIP form

• Risk communication

c. Compliance management

• Security and privacy legal and regulatory compliance

• Adherence to security standards

• Continuous control monitoring

• Audit and assurance

d. Cyber Resilience

• Maintain cyber resilient applications and systems

• Business continuity and disaster R=recovery

• Crisis management

• Cyber resilience testing

e. Security Operations

• Information assets protection

• Security monitoring

• Incident detection and response

• Application security

• Vulnerability management

• Recommend Penetration Testing (Red Team/Blue Team, Network, Infrastructure, Web Application, API, and Code Review) for annual project/budget

• Review testing results and track findings on IT Risk Register and advice on remediation

• Threat management

• Identity management

• Incident response coordination with third party

f. Security Architecture

• Security architecture- secure by design

• Translate business requirements to technology solutions

• Technology evaluation and selection

• Technology design and implementation

• Technical risk assessments and architecture reviews

Similar jobs