NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Security Engineer in United States of America
1 month ago
Apply with autofill
Apply with autofill
Kyoceraavx-us·1 month ago
1 month ago

Information Security Engineer, GRC

Fountain Inn, United States of AmericaMid · 2-5 yearsSecurity Engineer

Sign up free to see how well your resume matches this role.

Boost your chances at kyoceraavx-us

How you compare FREE

?
Your scoreYour score: not yet known
→
49
Top 10%Top 10%: 49 out of 100

Top 10% of NextRaise users matched against Security Engineer roles in United States.

Must-have skills for this role

  • grc
  • nist
  • iso 27001
  • risk assessment

PDF or DOCX · no account needed

Apply faster with autofill FREEThe NextRaise extension autofills your application in one click.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Design, implement, audit, and maintain governance, risk management, and compliance (GRC) controls for the organization’s information security program aligned to the National Institute of Standards and Technology (NIST), the Center for Internet Security (CIS), and the International Organization for Standardization (ISO) 27000 family of frameworks.
  • Drive policy, risk assessments, third party risk, audit readiness, and continuous compliance with regulatory and industry standards, using an organized and project managed approach.
  • Governance, policy & control design: Maintain policies/standards; map obligations to NIST CSF, NIST SP 800-53/800-171, CIS, and ISO 27001; define testable controls, procedures, and evidence requirements.
  • Risk management & exceptions: Conduct risk assessments; document scenarios and residual risk; maintain risk register, compensating controls, and remediation plans; support exception/acceptance decisions with rationale and evidence.
  • Compliance & audit readiness: Test controls (design/operating effectiveness), document gaps, assemble audit evidence, and track findings to validated closure.
  • Third-party risk: Assess vendor security (questionnaires, SOC/ISO artifacts, evidence review), document risk and required controls/terms, and drive remediation follow-ups.
  • Control implementation support & monitoring: Partner with IT/SecOps to implement and run controls (access, logging, vuln mgmt, encryption, backup/DR) and define monitoring, evidence sources, and test cadence.
  • Metrics & stakeholder communication: Produce dashboards and brief status reports on risk, control health, audit readiness, and remediation aging for technical and non-technical stakeholders.
  • Operational support & enablement: Provide GRC support for incidents/vulnerabilities and privacy obligations; publish practical guidance (standards, job aids, FAQs) to increase control adoption and reduce exceptions.

What they're looking for

  • Bachelor's degree
  • 10+ years experience in information security, including GRC, or risk/compliance roles.
  • Demonstrated experience with NIST frameworks (NIST CSF, NIST SP 800-53, NIST RMF, NIST SP 800-171), CIS 8.1, and ISO 27001.
  • Hands-on experience conducting risk assessments, control assessments, and audit responses.
  • Experience with regulatory requirements relevant to the organization (e.g., CMMC, TISAX, CTPAT, GDPR, IATF).
  • Strong communication skills; experience producing executive-level reporting.
  • Experience with GRC tooling (e.g., Archer, ServiceNow GRC, OneTrust, RSA) and security monitoring platforms.

Nice to have

  • Master’s degree or relevant advanced certification.
  • Certifications: CISSP, CISM, CRISC, CGEIT, or equivalent.
  • Experience with cloud security (AWS/Azure/GCP) controls and cloud compliance frameworks.

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

Design, implement, audit, and maintain governance, risk management, and compliance (GRC) controls for the organization’s information security program aligned to the National Institute of Standards and Technology (NIST), the Center for Internet Security (CIS), and the International Organization for Standardization (ISO) 27000 family of frameworks. Drive policy, risk assessments, third party risk, audit readiness, and continuous compliance with regulatory and industry standards, using an organized and project managed approach.

  • Governance, policy & control design: Maintain policies/standards; map obligations to NIST CSF, NIST SP 800-53/800-171, CIS, and ISO 27001; define testable controls, procedures, and evidence requirements.
  • Risk management & exceptions: Conduct risk assessments; document scenarios and residual risk; maintain risk register, compensating controls, and remediation plans; support exception/acceptance decisions with rationale and evidence.
  • Compliance & audit readiness: Test controls (design/operating effectiveness), document gaps, assemble audit evidence, and track findings to validated closure.
  • Third-party risk: Assess vendor security (questionnaires, SOC/ISO artifacts, evidence review), document risk and required controls/terms, and drive remediation follow-ups.
  • Control implementation support & monitoring: Partner with IT/SecOps to implement and run controls (access, logging, vuln mgmt, encryption, backup/DR) and define monitoring, evidence sources, and test cadence.
  • Metrics & stakeholder communication: Produce dashboards and brief status reports on risk, control health, audit readiness, and remediation aging for technical and non-technical stakeholders.
  • Operational support & enablement: Provide GRC support for incidents/vulnerabilities and privacy obligations; publish practical guidance (standards, job aids, FAQs) to increase control adoption and reduce exceptions.

REQUIRED QUALIFICATIONS:

  • Bachelor's degree
  • 10+ years experience in information security, including GRC, or risk/compliance roles.
  • Demonstrated experience with NIST frameworks (NIST CSF, NIST SP 800-53, NIST RMF, NIST SP 800-171), CIS 8.1, and ISO 27001.
  • Hands-on experience conducting risk assessments, control assessments, and audit responses.
  • Experience with regulatory requirements relevant to the organization (e.g., CMMC, TISAX, CTPAT, GDPR, IATF).
  • Strong communication skills; experience producing executive-level reporting.
  • Experience with GRC tooling (e.g., Archer, ServiceNow GRC, OneTrust, RSA) and security monitoring platforms.

 

PREFERRED QUALIFICATIONS:

  • Master’s degree or relevant advanced certification.
  • Certifications: CISSP, CISM, CRISC, CGEIT, or equivalent.
  • Experience with cloud security (AWS/Azure/GCP) controls and cloud compliance frameworks.

Kyocera-AVX is an Equal Opportunity Employer:  All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or status as a protected veteran.

Company

Kyoceraavx-us
Fountain Inn, United States of America

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Kyoceraavx Us's careers site·first seen 8 Aug 2026·last verified 10 Sept 2026·How we source jobs

Similar jobs

  • Sr. Systems Security Engineer (Onsite - Largo, FL) TS/SCI Clearance required at globalhrLARGO, United States of America–match not yet calculated
  • Sr Security Engineer at michaelsIrving, United States of America–match not yet calculated
  • Cybersecurity Engineer at dutchbros1930 W Rio Salado Pkwy Tempe AZ 85281–match not yet calculated
  • Associate Cybersecurity Engineer at dutchbros1930 W Rio Salado Pkwy Tempe AZ 85281–match not yet calculated
  • Systems Security Engineer I - 304214 at dnigovRome, United States of America–match not yet calculated

Browse more jobs

  • Security Engineer jobs in United States
  • Security Analyst jobs in United States
  • Cloud Security Engineer jobs in United States
  • Penetration Tester jobs in United States
  • Security Engineer jobs in India
  • Security Engineer jobs in United Kingdom