Security GRC Specialist Job at Lawrence Harvey, New York, NY

Q3EvQ3hzRTVlNnpDMmNNaWErS1lIc2tLTlE9PQ==
  • Lawrence Harvey
  • New York, NY

Job Description

Lawrence Harvey is partnered with a SaaS start-up looking to build up their GRC program in New York City. We are seeking a Security GRC Specialist to drive the evolution and scaling of a governance, risk, and compliance program with a heavy focus on automation and cross-functional collaboration. This role provides significant ownership, working closely with leadership to align compliance efforts with business goals, while reducing manual work through tooling and process innovation.

Core Responsibilities:

Policy & Compliance Automation:

  • Design, implement, and optimize compliance processes using automation to support audit-readiness and continuous monitoring.

Documentation & Framework Management:

  • Draft, maintain, and enhance internal policies, procedures, standards, and guidelines in accordance with evolving regulatory and security frameworks (SOC 1/2, ISO 27001, HIPAA, GDPR, NIST, CCPA, CSA STAR).

Risk & Vendor Management:

  • Conduct formal risk assessments across internal applications, third-party vendors, and partner integrations, with a focus on protecting sensitive data and minimizing business risk.

Tooling & Technical Enablement:

  • Evaluate and deploy GRC-related technologies such as evidence collection platforms, control monitoring solutions, and identity governance tools

Strategic Compliance Enablement:

  • Promote compliance as a value-add function, enabling growth and customer trust through sound risk and privacy practices.

Required Skills & Experience:

  • 6-7+ years directly in Security, GRC or related experience
  • Solid understanding of major compliance frameworks: SOC1/2, HIPAA, ISO 27001, GDPR, CCPA, NIST
  • Experience with cloud-native and SaaS environments - AWS, GCP or Azure experience is preferable
  • Proven ability to drive process automation and tooling integration to reduce repetitive work
  • Effective written and verbal communicator, capable of translating complex regulatory requirements into business-friendly guidance
  • Hands-on experience with GRC tools
  • Familiarity with scripting languages (e.g., Python) is a plus
  • Exposure to global privacy frameworks and previous experience in cybersecurity roles is beneficial

Job Tags

Similar Jobs

BJC HealthCare

Nurse Job at BJC HealthCare

 ...Information About the Role ~ OR Pod 3 Location Barnes Jewish Hospital Main Campus South West Tower Role Details~ OR experience preferred ~4-10 hour shifts (0615-1645)~ Cardiothoracic position ~ Holidays: 1 per year, rotate Winter/Spring ~... 

Upper Valley Services

Shared Living Provider Job at Upper Valley Services

 ...Job Description Job Description Salary: Seeking a home with a live-in couple or just two friends who are looking to make a difference. Share your home and life with an amazing man who needs support with his. Support needs include assistance walking, dressing... 

Groove Technology Solutions

General Application Job at Groove Technology Solutions

 ...Solutions is a leading provider of innovative technology solutions for the hospitality industry, offering a wide range of services from DIRECTV, Internet, and Wi-Fi to video surveillance, phone systems, energy management, and other cutting-edge in-room technologies.... 

Russell Tobin

Social Media Coordinator Job at Russell Tobin

 ...to prioritize and multitask. Excellent verbal and written communication skills. Passion for social media as a business strategy...  ...offers eligible employees comprehensive healthcare coverage (medical, dental, and vision plans), supplemental coverage (accident insurance... 

GardaWorld Security Services U.S.

Surveillance Security Officer - Warehouse Job at GardaWorld Security Services U.S.

 ...Job Description GardaWorld Security Services is Now Hiring a Surveillance Security Officer! Ready to suit up as a Surveillance Security...  ...this could be more than a job! 26% of our corporate employees started as frontline workers. If you're ambitious with an...