Remote, Canada; Remote, United States
Remote
Senior
Full Time
💰$139,200 - $189,000
remotesecurityrisk managementAIautomation
Requirements
- •5+ years of experience in security risk management, working with security-centric risk management or compliance frameworks (e.g., NIST RMF, NIST 800-39, ISO 31000).
- •Experience designing and executing qualitative and quantitative risk analyses that translate technical risks into measurable business impact.
- •A track record of driving risk assessments, risk registers, and remediation efforts to closure across IT, Procurement, Internal Audit, Legal, Product, and Engineering, in a heavily regulated or multi-entity environment.
- •Experience interpreting technical control requirements and translating them for both technical and non-technical stakeholders.
- •Demonstrated bias toward automation: you've personally built scripts, workflows, or AI-enabled tooling that reduced manual risk or GRC work.
- •Comfort operating with ambiguity, managing multiple concurrent assessments, and reprioritizing under tight deadlines.
- •Exceptional written and verbal communication skills with demonstrated ability to translate security risks into business risks.
- •Strong understanding of cloud security, SaaS security models, and DevSecOps practices.
What You'll Do
- •Own risk identification, analysis, and prioritization across third-party risk (TPRM), security risk assessments, and security findings, using an established risk framework (e.g., NIST RMF, ISO 31000, or NIST 800-39).
- •Translate technical vulnerabilities, control gaps, and risk findings into clear, quantified risk statements that non-security stakeholders and leadership can act on.
- •Drive remediation of findings and risk exceptions to closure, partnering with Engineering, IT, Product, and Legal, and escalating stalled or high-severity items.
- •Mature and maintain a risk register and quarterly reporting cadence that gives leadership clear visibility into open risk, remediation progress, and trends.
- •Own and mature AI risk management, including AI impact assessments, AI risk assessments, and risk treatments, to support ISO 42001 certification.
- •Design, develop, and implement key risk indicators and supporting metrics for top risks in the risk register.
- •Identify manual, repetitive steps in risk and TPRM workflows and personally build the automation, scripting, or AI-enabled tooling to remove them.
- •Contribute to the roadmap for the risk program, incorporating new frameworks, regulatory changes, and lessons learned from past assessments.
- •Monitor the internal and external risk landscape (new frameworks, threat trends, business changes) to identify and escalate emerging risks before they become findings.
Nice to Have
- •Familiarity with AI governance frameworks (e.g., ISO 42001, NIST AI RMF).
- •Relevant certifications (e.g., CISSP, CISM, CISA, CRISC) are preferred but not required.
Benefits
- •Benefits to support your health, finances, and well-being
- •Flexible Paid Time Off
- •Team Member Resource Groups
- •Equity Compensation & Employee Stock Purchase Plan
- •Growth and Development Fund
- •Parental Leave
