About the role
- Oversee WELLSTAR’s ISO 27001 ISMS and SOC 2 Type 2 control framework
- Establish and continuously improve policies, processes, and GRC practices
- Own the compliance onboarding process for newly acquired entities
- Conduct gap analyses, risk assessments, and maturity evaluations
- Maintain the GRC risk register and support third-party risk reviews
- Track and present GRC KPIs and compliance metrics to leadership
- Support awareness campaigns and employee training
- Monitor changes in regulatory requirements and industry trends
Requirements
- 8+ years of experience in GRC, compliance, risk management, or IT audit
- Familiarity with governance and compliance frameworks
- Experience with GRC tools such as Anecdotes, Vanta, Drata, OneTrust, or LogicGate
- Relevant certifications (CISA, CISM, CRISC, or ISO 27001 Lead Implementer/Auditor) are an asset
- Strong written and verbal skills to translate complex standards into clear steps for non-technical teams
- Ability to work cross-functionally with senior stakeholders in business, legal, IT, and security
- Impact and exposure
- Growth and ownership
- Mission and purpose
- Career development
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
GRCcompliancerisk managementIT auditgap analysisrisk assessmentmaturity evaluationcompliance onboardingpolicy establishmentprocess improvement
Soft skills
strong written communicationstrong verbal communicationcross-functional collaborationstakeholder engagementemployee trainingawareness campaign support
Certifications
CISACISMCRISCISO 27001 Lead ImplementerISO 27001 Auditor