Overview
Recorded Future seeks a Technology Risk & Compliance Lead to manage assurance requirements and ensure compliance with customer and regulatory security, confidentiality, and privacy standards using frameworks such as CMMC, SOC 2, and ISO 27001. The role maintains the organization’s assurance and compliance obligations, aligning with customer and regulatory expectations and advising leadership on IT risk, with responsibility for design and implementation of risk and control frameworks.
What You'll Do :
- Prepare for internal and external assessments (SOC 2, ISO, CMMC, etc.) by ensuring controls are audit-ready and validated on an ongoing basis.
- Conduct risk assessments to identify potential security and availability risks and advise on control design and governance to mitigate these risks.
- Review and update the organization’s risk register (new risks, changes to existing risks, etc.).
- Track and remediate control deficiencies or gaps identified through testing and validate mitigating controls to address residual risk.
- Coordinate with technology teams to validate risk owners and mitigation plans and report results to internal compliance functions.
- Maintain evidence repositories to support internal and external assessment and certification testing.
- Report risk and control status to senior management and governance committees.
- Partner in developing strategy, objectives, and action plans for assurance obligations.
- Participate in multi-stakeholder meetings and provide administrative support for senior-level discussions.
- Maintain a deep understanding of the business and assurance obligations to guide execution plans.
- Ensure ongoing compliance with statutory and regulatory requirements, anticipate future legislation and customer demands, and advise management on actions needed.
- Identify, collect, synthesize, and communicate risks and blockers concisely for senior leadership alignment.
- Regularly define and review key success metrics for data-focused tracking and seek improvements for visibility aligned with organizational objectives.
What You'll Bring :
Strong knowledge of IT general controls and related operations.Experience with control frameworks (SOC2, ISAE3000, ISO27001, FedRAMP, CMMC, etc.).Strong interpersonal, communication, and presentation skills for interaction with business leaders and teams at all levels.Strong negotiation and consensus-building skills.Ability to meet project deliverables.Commitment to a work environment that respects and develops skills across diverse backgrounds.Preferred Qualifications :
Bachelor's degree or equivalent; degree in computer science, information technology, or a related field is preferred.Professional certifications such as CISSP, CISA, CRISC, CIPP, or similar are a plus.Spanish and / or Ukrainian language proficiency is a plus.Why join Recorded Future
Recorded Future values diversity and inclusion, with a global team of professionals and a track record of serving clients across industries. We welcome candidates who share our commitment to high standards, inclusion, and ethics.
Equal Opportunity Employer
Recorded Future is an equal opportunity and affirmative action employer. We do not discriminate on the basis of race, religion, color, national origin, gender (including pregnancy), sexual orientation, gender identity, age, marital status, veteran status, disability, or any other characteristic protected by law. We may collect voluntary information for equal opportunity and diversity reporting; participation is optional and will not affect hiring decisions. We will provide reasonable accommodations for applicants with disabilities upon request.
#J-18808-Ljbffr