All roles

Senior Principal, IT Governance, Risk and Compliance, GRC

Remote · USA Full-time New today

Job Description:

  • Serve as the primary IT audit liaison, ensuring clear communication, efficient evidence collection, and timely resolution of audit inquiries across technology and business teams
  • Work with Internal and External auditors, business stakeholders and suppliers as appropriate on required IT control assessments and audits
  • Provide first level of support and consulting to the business and IT on internal audit activities and results as well as risk mitigation initiatives in response to audit findings
  • Manage overall remediation process and create and oversee action plans to remediate issues
  • Ensure audit readiness by proactively identifying control weaknesses and coordinating pre‑audit walkthroughs, evidence validation, and test preparation.
  • Assist the Director, IT Governance, Risk, and Compliance and Senior Director, IT Governance, Risk and Compliance with IT governance and controls, internal and external audit readiness and support, and policy and standard development
  • Responsible for daily governance, risk, control, and compliance functions leveraging ServiceNow
  • Participate in and contribute to the IT Governance, Risk and Compliance program, ensuring IT controls, policies, processes, and procedures support the mission of the Red Cross and meet state and federal regulations and laws, as well as best practices
  • Collaborate with and influence technology and business leaders and staff to create, sustain, and strengthen internal control framework for the organization through control identification, design, implementation, and testing
  • Provide guidance, training, and motivation necessary to create control awareness, ownership and accountability to stakeholders
  • Consult with Information Security, Office of General Counsel/Legal, Supply Management, Risk Management, Audit Services, and other appropriate parties sharing expertise and knowledge to strengthen the Red Cross control environment
  • Interpret regulatory compliance requirements and assist with gap analysis of current policies, procedures, and practices as they relate to established guidelines outlined by NIST-800-53/171/30 and other regulatory standards
  • Provide guidance, interpretation, and support of SOC 1 and SOC 2 Security Trust criteria
  • Research regulations by reviewing regulatory bulletins and other sources of information, to maintain quality service by establishing and enforcing organization standards
  • Drive continuous improvement of the GRC program by identifying control inefficiencies, modernizing governance processes, and recommending ServiceNow automation opportunities.
  • Participate in on-going evaluations and validation of IT control effectiveness and internal business processes via ServiceNow and other tools, as they relate to compliance activities within areas of responsibility
  • Ensure high‑quality documentation and evidence standards across the organization to support repeatable, audit‑ready control operations.
  • Identify and communicate opportunities to enhance technical controls which contribute to sustaining a robust control environment
  • Document, track, and report on control gap findings, risk, impacts and recommendations to management
  • Participate in the establishment of actionable metrics to drive the control assessment process and influence behaviors to IT Leadership
  • Manage the Exception and Risk Acceptance Process as it relates to control gaps and audit findings
  • Proactively monitor emerging risks and coordinate targeted control assessments to identify vulnerabilities before they surface in audits
  • Support and assist with coordination and implementation of Information Technology policies and standards to sustain regulatory and compliance initiatives as required by the business needs
  • Work and consult with the IT GRC colleagues during policy review and communication
  • Analyze policies, standards, procedures, and guidelines for regulatory and compliance requirements, and recommend solutions for identified weaknesses, to improve compliance operations, recommend and assist in changes to best practices

Requirements:

  • Bachelor’s degree in a related field required (IT, audit, and/or information security) or closely related discipline.
  • Minimum 10 years of related experience or equivalent combination of education and related experience required
  • 3-5 years of experience in IT GRC or IT audit with hands-on ServiceNow GRC experience
  • Working knowledge of control frameworks, IT general controls, and security controls such as, NIST, ISO, COBIT, FedRAMP, SOC 2, ISO 27001
  • Highly motivated and proactive with strong organizational, communication, and project management skills
  • Experience drafting, remediating, or editing of IT policies, standards, procedures and controls
  • Experience working cross-functional with engineers, product and security teams, business leaders at all levels of the organization
  • Demonstrated ability to coordinate large-scale IT audit engagements, drive remediation outcomes, and elevate control maturity across complex environments
  • Strong capability to translate regulatory and technical control requirements into practical, actionable guidance for diverse technical and non‑technical stakeholders.
  • Experience coordinating with internal and/or external audit teams
  • Ability to understand key controls and communicate them in a digestible way to IT technologists, control owners, and senior leaders
  • Strong written and oral communication skills with utilization of appropriate tools (MS Excel, ServiceNow, etc.)
  • Solid analytical and problem-solving skills in process review and issue remediation
  • Open-mindedness, creative thinking, willingness to take calculated risks, and make informed decisions
  • A sense of unparalleled passion, energy, and eagerness to contribute to and support the mission of the Red Cross

Benefits:

  • Medical, Dental Vision plans
  • Health Spending Accounts & Flexible Spending Accounts
  • PTO: Starting at 15 days a year; based on type of job and tenure
  • Holidays: 11 paid holidays comprised of six core holidays and five floating holidays
  • 401K with up to 6% match
  • Paid Family Leave
  • Employee Assistance
  • Disability and Insurance: Short + Long Term
  • Service Awards and recognition

Apply tot his job Apply To this Job

Related roles

Manager, Governance, Risk & Compliance

Remote · USA Full-time

Grant Writer/Contractor

Remote · USA Full-time

Art, Photography & Graphic Design Internships

Remote · USA Full-time

Sr Manager, Growth and Revenue Digital Marketing (REMOTE)

Remote · USA Full-time

Growth Strategist (Account Executive)

Remote · USA Full-time

Growth Strategist II - Outbound

Remote · USA Full-time

Growth Strategy Lead

Remote · USA Full-time

Telephone Triage Registered Nurse

Remote · USA Full-time

Medical Insurance Collector

Remote · USA Full-time

Sr AI/ML Engineer - Remote Nationwide or Hybrid in MN/DC

Remote · USA Full-time

Senior Tableau Developer

Remote · USA Full-time

Experienced Customer Service Representative – Work From Home Opportunities with blithequark

Remote · USA Full-time

Experienced Customer Service Representative – Remote Work Opportunity at blithequark

Remote · USA Full-time

Talent Acquisition Lead

Remote · USA Full-time

Experienced Remote Customer Service Representative – Delivering Exceptional Support in a Dynamic Entertainment Environment at blithequark

Remote · USA Full-time

Experienced Virtual Chat Assistant – Entry-Level Remote Careers, Earn $25-$35 Per Hour with Flexible Hours

Remote · USA Full-time

Senior Manager, Paid Media (US - REMOTE)

Remote · USA Full-time

Intake Coordinator

Remote · USA Full-time

Senior Healthcare Fraud Investigator (Aetna SIU)

Remote · USA Full-time

Experienced Data Entry Specialist – Customer Support, Phone, Remote

Remote · USA Full-time