Talent.com
Information Security Governance, Risk and Compliance (GRC) Lead
Information Security Governance, Risk and Compliance (GRC) LeadO'Melveny & Myers LLP • Dallas, TX, US
Information Security Governance, Risk and Compliance (GRC) Lead

Information Security Governance, Risk and Compliance (GRC) Lead

O'Melveny & Myers LLP • Dallas, TX, US
job_description.job_card.variable_hours_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Information Security Governance, Risk and Compliance (GRC) Lead

O'Melveny & Myers LLP has an immediate opening for a remote Information Security Governance, Risk and Compliance (GRC) Lead in one of our Texas offices. The GRC Lead serves as the subject matter expert for firmwide Information Security GRC initiatives, collaborating closely with the Information Security Officer. This role encompasses the development, implementation and ongoing coordination of GRC efforts, tracking information security risks, conducting risk analyses and mitigation options, coordinating information security metrics, and regular reporting to Information Security leadership. The Lead enforces GRC rigor globally for firmwide information security obligations and helps implement a comprehensive control framework to execute the GRC strategy. The role oversees administration of standards and controls, risk management, third-party risk management (TPRM), baseline security controls and technology compliance initiatives. It coordinates information security audits and assessments, tracks responses, and interacts with clients and external auditors. It may also involve reviewing outside counsel guidelines and developing a third-party risk management program, including due diligence documentation such as questionnaires and SOC reports.

Responsibilities Include

  • Lead firmwide Information Security GRC initiatives in partnership with the Information Security team.
  • Assist and coordinate with the ISO 27001 annual certification preparations, as well as client audits.
  • Track external requirements such as outside counsel guidelines and assist with review and response as needed.
  • Oversee Information Security GRC activities and coordinate with the Information Security Officer.
  • Serve as a subject matter expert and trusted advisor for leadership on Information Security GRC matters.
  • Serve as the primary contact for responding to business unit inquiries regarding operational compliance.
  • Collaborate with IT, legal, finance and operations to develop a cohesive Information Security GRC program.
  • Partner with business units during solutions onboarding to ensure adequate controls are in place and enabled.
  • Conduct regular risk assessments and analyze emerging risks across the organization.
  • Coordinate with stakeholders to implement effective risk mitigation strategies.
  • Maintain a strategic and comprehensive GRC program that includes policies, standards, processes and guidelines.
  • Stay updated on regulatory changes and industry standards (ISO, NIST, GDPR, HITRUST, HIPAA).
  • Provide guidance to team members to ensure compliance with relevant laws and regulations.
  • Deliver GRC reports to management, emphasizing compliance status, risk exposure and mitigation efforts.
  • Oversee third-party and vendor risk as part of the organization's risk management strategy.
  • Document and enforce cybersecurity standards that balance risk with business operations.
  • Ensure audit readiness by documenting GRC activities, policies, assessments and corrective actions.
  • Implement process improvements using GRC tools and methodologies to drive productivity gains.
  • Cooperate with internal and external auditors to maintain and implement controls that meet GRC requirements.
  • Motivate functional areas to adopt practices that comply with cybersecurity policies and standards.
  • Provide leadership in collaboration with technical and business teams to strengthen business resiliency.
  • Guide team to align with security, audit and risk management efforts in ongoing security program assessments.
  • Assist Information Security with projects as needed.
  • Stay abreast of current technologies, developments, security compliance requirements, standards, and industry trends.
  • Perform analysis of security threats and vulnerabilities and use threat intelligence to anticipate and mitigate risks.
  • Ensure secure handling of privileged accounts and credentials.

Qualifications

  • Five years of experience in GRC or as a cybersecurity practitioner, including roles in security analysis, compliance, and risk management.
  • Experience working in a distributed and hybrid office environment.
  • Understanding of information security and privacy frameworks : ISO / IEC 27001 required; NIST, HIPAA, HITRUST, GDPR, and GLBA are optional.
  • Bachelor's degree in Cybersecurity, Computer Science, Data Science, or related field.
  • Experience conducting tabletop exercises, coordinating disaster recovery exercises, and other information security control tests is ideal.
  • Excellent analytical and problem-solving abilities.
  • Effective communication and interpersonal skills; ability to work independently and in a multidisciplinary team.
  • Professional certifications are a plus (CISSP, CISM, CISA, CRISC, CGRC).
  • We offer an excellent salary and benefits package. For more information, or to be considered for this position, please apply online at www.omm.com. EOE M / F / D / V. No phone inquiries please.

    J-18808-Ljbffr

    serp_jobs.job_alerts.create_a_job

    Information Security • Dallas, TX, US

    Job_description.internal_linking.related_jobs
    Oracle Cloud HCM Security Lead

    Oracle Cloud HCM Security Lead

    VirtualVocations • Arlington, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for an Oracle Cloud HCM Security Lead to drive security configuration and governance.Key Responsibilities : Lead the design and implementation of security configurations withi...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_hours • serp_jobs.job_card.promoted • serp_jobs.job_card.new
    Information Security Tech Lead Analyst

    Information Security Tech Lead Analyst

    Citigroup Inc. • Irving, TX, US
    serp_jobs.job_card.full_time
    About Citi : Citi, the leading global bank, has approximately 200 million customer accounts and does business in more than 160 countries and jurisdictions. Citi provides consumers, corporations, gove...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Senior Manager AI Security

    Senior Manager AI Security

    VirtualVocations • Garland, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for a Technical Lead - AI Model and Project Security.Key Responsibilities Design, implement, and maintain technical controls for AI development tools and platforms Lead the ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_hours • serp_jobs.job_card.promoted • serp_jobs.job_card.new
    Endpoint Security Lead (Associate Director) - CrowdStrike

    Endpoint Security Lead (Associate Director) - CrowdStrike

    Glocomms • Dallas, TX, United States
    serp_jobs.job_card.full_time
    A top-tier financial services firm is seeking a seasoned cybersecurity professional to lead the design, deployment, and governance of enterprise endpoint protection solutions.This leadership role i...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Information Security Risk Manager

    Information Security Risk Manager

    Argent Financial Group • Dallas, TX, US
    serp_jobs.job_card.full_time
    Job Title : Information Security Risk Manager.The Information Security Risk Manager has a highly collaborative role with primary responsibility for identifying risks across Argent’s informatio...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Director of Governance Risk Compliance

    Director of Governance Risk Compliance

    VirtualVocations • Garland, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for a Director of Governance, Risk, and Compliance (GRC).Key Responsibilities Develop and direct an enterprise-wide GRC program to support growth and security Lead and manag...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Senior Associate, Internal Audit Information Technology & Security

    Senior Associate, Internal Audit Information Technology & Security

    The Options Clearing Corporation • Dallas, TX, United States
    serp_jobs.job_card.full_time
    THIS POSITION IS NOT ELIGIBLE FOR VISA SPONSORSHIP • • • • •.This role will support and lead independent assessments of OCC's Information Technology and Security environment, risk management, and other ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    IT Governance Risk Compliance Analyst

    IT Governance Risk Compliance Analyst

    VirtualVocations • Plano, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for an IT Governance, Risk and Compliance Analyst.Key Responsibilities Support daily GRC operations, policy development, and audit readiness Evaluate IT control effectivenes...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_1_day • serp_jobs.job_card.promoted
    Governance, Risk, and Compliance Manager

    Governance, Risk, and Compliance Manager

    Weaver • Dallas, TX, US
    serp_jobs.job_card.full_time
    Governance, Risk, and Compliance Manager.Weaver is a full-service national accounting, advisory and consulting firm with opportunities for professionals in many different fields.We seek to bring a ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Senior Information Security Analyst

    Senior Information Security Analyst

    The Intersect Group • Plano, TX, US
    serp_jobs.job_card.full_time
    Get AI-powered advice on this job and more exclusive features.This range is provided by The Intersect Group.Your actual pay will be based on your skills and experience — talk with your recruiter to...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_hours • serp_jobs.job_card.promoted • serp_jobs.job_card.new
    Information Security Risk Analyst (GRC)

    Information Security Risk Analyst (GRC)

    American National Bank of Texas • Terrell, TX, United States
    serp_jobs.job_card.full_time
    Information Security Risk Analyst.Information and Cyber Security Program.Conduct comprehensive risk assessments to identify and evaluate potential threats and vulnerabilities to information systems...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Information Security Architect

    Information Security Architect

    VirtualVocations • Garland, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for an Information Security Lead Architect.Key Responsibilities Develop and implement information security architecture strategy and roadmap Provide guidance and oversight t...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Governance, Risk, and Compliance Manager - Asset Management

    Governance, Risk, and Compliance Manager - Asset Management

    Weaver • Dallas, TX, US
    serp_jobs.job_card.full_time
    Governance, Risk, and Compliance Manager - Asset Management.Weaver is a full-service national accounting, advisory and consulting firm with opportunities for professionals in many different fields....serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Governance, Risk & Compliance Manager

    Governance, Risk & Compliance Manager

    Jobot • Dallas, TX, US
    serp_jobs.job_card.full_time
    Top tier advisory firm w / hybrid schedule & focus on work / life balance.This Jobot Job is hosted by : Mitch Hagen.Are you a fit? Easy Apply now by clicking the "Apply Now" button and sending us your...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Senior SOC Manager

    Senior SOC Manager

    VirtualVocations • Mesquite, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Security Operations Center (SOC) Manager.Key Responsibilities Oversee daily SOC activities for timely detection and response to security incidents Manage, mento...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Senior Manager, Information Security

    Senior Manager, Information Security

    VirtualVocations • Mesquite, Texas, United States
    serp_jobs.job_card.full_time
    Manager, Information Security Risk Management.Key Responsibilities Lead the supplier governance program and oversee supplier due diligence processes Partner with stakeholders for supplier sourci...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Information Security Manager

    Information Security Manager

    VirtualVocations • Garland, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for an Information Security Manager to oversee security operations and ensure compliance with federal standards. Key Responsibilities : Develop and implement security policies,...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Director Governance, Risk & Compliance (GRC)

    Director Governance, Risk & Compliance (GRC)

    Baylor University Medical Center • Dallas, TX, US
    serp_jobs.job_card.full_time
    Director of Healthcare Governance, Risk, and Compliance.The Director of Healthcare Governance, Risk, and Compliance, reporting to the CISO, is responsible for developing, implementing, and overseei...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted