Demo

Governance, Risk, and Compliance Lead

D and H Distributing Co
Harrisburg, PA Full Time
POSTED ON 2/17/2025
AVAILABLE BEFORE 5/11/2025

SUMMARY

D&H Distributing is looking to hire a GRC Lead to assist with managing the Governance, Risk, and Compliance (GRC) program. You will be responsible for developing and ensuring compliance with security policy, carrying out security assessments, and leading the development and management of a cybersecurity risk management program. Your experience should include exposure to common cybersecurity frameworks including NIST and ISO 27001. Auditing and experience in implementing an ISMS is strongly preferred.

ESSENTIAL DUTIES AND RESPONSIBILITIES

  • Lead internal ISO 27001 audits and coordinate with third party auditing firms to perform external audits
  • Lead with the implementation and operation of Governance Risk and Compliance (GRC) tooling to further improve and automate our GRC processes
  • Lead with all ongoing compliance activities related to the implementation, maintenance, monitoring, and continuous improvement of the Information Security Management System (ISMS)
  • Evaluate the effectiveness of information security controls and performance by developing, monitoring, gathering, and analyzing information security and compliance metrics for management
  • Perform third party risk assessments to maintain oversight of third party vendors
  • Manage and coordinate client assurance questionnaires, audits and assessments, and calls
  • Help support various parts of the company to adopt / maintain a common risk and control framework
  • Develop, enhance, operationalize enterprise-level security, risk and privacy policies, processes and controls to mitigate risk and comply with applicable laws and regulations
  • Perform activities to monitor and assess the security, risk and privacy controls on an ongoing basis. Work closely with the operational departments (Legal, Engineering, Sales, Support, Operations, ...) to develop and monitor policies and standards in compliance with applicable privacy policy & regulations
  • Stay up to date on the latest security and industry trends including their compliance requirements
  • Maintain familiarity with cybersecurity frameworks such as NIST, CIS, and other security technology by attending workshops and reviewing publications
  • Monitor environment for malicious behavior utilizing a variety of security tools and take appropriate remediation
  • Coordinate across organization to ensure mutual success in protecting D&H
  • Monitor changes to the environment to identify if those changes compromise security
  • Investigate security breaches and other cybersecurity incidents with minimal assistance
  • Work with the business units to remediate identified issues with minimal assistance
  • Assist in process improvements to enhance the efficiency of current operational procedures
  • Participate in access control and governance including provisioning / deprovisioning and recertification of accounts
  • Effectively deal with rapid change in a positive manner
  • Participate in all company / location driven communication efforts, including huddles, department meetings, and other related efforts
  • Maintain a positive and professional working relationship with peers, management, support resources, and the community with a constant commitment to teamwork and exemplary customer service to present a professional image of D&H Distributing
  • Perform all other duties as assigned by management in a professional and efficient manner

EDUCATION and / or EXPERIENCE

Education

  • Bachelor's degree in Cybersecurity or similar area of study required or equivalent years of related work experience
  • 3 - 5 years of experience in cybersecurity
  • Industry certifications (CEH, Security , SANS, CISSP, OSCP, CCNA Security or similar) preferred
  • Experience

  • Experience with system maintenance, monitoring, and alert resolution preferred
  • Scripting experience in PowerShell, Python or Perl preferred
  • NIST Standards, ISO 27001, and / or PCI DSS
  • Security Policy Development
  • User Access Reviews (UARs)
  • Security and Privacy Impact Assessments (PIAs)
  • Exposure to SOC2 / SOX / etc.
  • Auditing experience, specifically ISO 27001 (preferred)
  • ServiceNow (a plus)
  • If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
    Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

    What is the career path for a Governance, Risk, and Compliance Lead?

    Sign up to receive alerts about other jobs on the Governance, Risk, and Compliance Lead career path by checking the boxes next to the positions that interest you.
    Income Estimation: 
    $105,259 - $133,442
    Income Estimation: 
    $129,191 - $164,117
    Income Estimation: 
    $152,549 - $188,894
    Income Estimation: 
    $194,072 - $240,547
    Income Estimation: 
    $135,994 - $168,063
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $70,462 - $84,818
    Income Estimation: 
    $77,991 - $108,747
    Income Estimation: 
    $87,093 - $107,335
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $87,093 - $107,335
    Income Estimation: 
    $111,725 - $147,313
    Income Estimation: 
    $112,673 - $137,290
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $112,673 - $137,290
    Income Estimation: 
    $139,945 - $168,577
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

    Job openings at D and H Distributing Co

    D and H Distributing Co
    Hired Organization Address Harrisburg, PA Full Time
    Territory Sales Manager, Components Candidate preferred location in west coast territory. D&H is growing! Join 100 year ...
    D and H Distributing Co
    Hired Organization Address Harrisburg, PA Full Time
    HPI Outside Business Development Manager Join a 100 Year old and growing electronics and technology company based in Har...
    D and H Distributing Co
    Hired Organization Address Harrisburg, PA Full Time
    Sr Financial Analyst Join a 100 Year old and growing electronics and technology company based in Harrisburg, PA that off...
    D and H Distributing Co
    Hired Organization Address Clearwater, FL Full Time
    Summary The primary role of Sales Specialist (SS) is to drive pipeline opportunity creation and achieve sales targets fo...

    Not the job you're looking for? Here are some other Governance, Risk, and Compliance Lead jobs in the Harrisburg, PA area that may be a better fit.

    Senior IT Governance, Risk and Compliance Analyst

    Della Infotech, Harrisburg, PA

    AI Assistant is available now!

    Feel free to start your new journey!