Logo for Clario

Sr. Security Governance, Risk & Compliance Specialist

Role overview

Qualifications

  • Bachelor’s degree in Information Systems, Information Technology, Cybersecurity, or a related field
  • 5+ years of experience in Information Technology, Information Security, Governance, Risk, and/or Compliance
  • Strong experience building, maintaining, or maturing Security Governance, Risk, and Compliance programs
  • Knowledge of common information security and IT frameworks, including ISO/IEC 27001, NIST Cybersecurity Framework, NIST 800-53, COBIT, and ITIL

Responsibilities

  • Support and mature the organization’s Security GRC program
  • Coordinate and support external client audits, certifications, and assessments
  • Evaluate the compliance status of IT, Product, and Information Security controls
  • Execute established processes to assess, monitor, and manage information security risks associated with third parties

Key facts

Hard skills

Other skills

  • Communication
  • Detail Oriented
  • Problem Solving
  • Teamwork
  • Adaptability

About the company

Clario logo

Clario

Contract Research Organizations (CRO)

Clario is a leading healthcare research and technology company that generates high quality clinical evidence for our pharmaceutical, biotech, and medical device partners. We offer comprehensive evidence generation solutions that combine eCOA, cardiac safety, medical imaging, precision motion, and respiratory endpoints. Since our founding more than 50 years ago, Clario has delivered deep scientific expertise and broad endpoint technologies to help transform lives around the world. Our endpoint data solutions have supported clinical trials over 26,000 times in more than 100 countries. Our global team of science, technology, and operational experts have supported over 60% of all FDA drug approvals since 2019. For more information, visit Clario.com

Company details

Company typeXLarge
IndustryContract Research Organizations (CRO)
Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

The Senior Security GRC Specialist is a high-impact role focused on strengthening and maintaining information security governance, risk, and compliance across the organization. This position partners closely with QA, IT, Information Security, Legal, Product, and other internal stakeholders, as well as external clients, vendors, auditors, and assessment partners.

The role will help drive security and compliance initiatives, support risk management activities, coordinate audits and certifications, manage third-party security risk, and continuously improve security governance, policies, processes, and controls.

What You’ll Be Doing

  • Security Governance, Risk & Compliance: Support and mature the organization’s Security GRC program, helping ensure IT, Product, and Information Security controls align with applicable policies, standards, regulations, and best practices.

  • Audit & Assessment Coordination: Coordinate and support external client audits, certifications, and assessments, including SOC 1, SOC 2, ISO 27001/2700x, client audits, and other security assessments or accreditations.

  • Compliance Monitoring: Evaluate the compliance status of IT, Product, and Information Security controls. Partner with control owners to identify gaps, develop remediation plans, track progress, and drive issues through resolution.

  • Risk Management: Support the organization’s risk management framework, including assessing inherent and residual risk, evaluating risk tolerance, facilitating risk discussions, and supporting periodic internal and third-party risk assessments.

  • Third-Party Risk Management: Execute established processes to assess, monitor, and manage information security risks associated with third parties, vendors, and other external partners.

  • Client Assurance & Regulatory Support: Serve as a key point of contact for QA, Regulatory, Customer, and other stakeholder interactions related to security and compliance. Support responses to audits, client questionnaires, RFPs, findings, and other assurance requests.

  • Policy & Standards Governance: Support the development, maintenance, and governance of the Information Security policies, standards, procedures, and related documentation.

  • Process Improvement: Identify opportunities to improve and mature IT and Information Security compliance processes. Use industry standards, emerging risks, regulations, and stakeholder feedback to recommend practical improvements.

  • Security Frameworks: Apply standards and best practices from frameworks such as ISO/IEC 27001, NIST, COBIT, and ITIL to support the organization’s security and compliance objectives.

  • Reporting & Metrics: Develop compliance and risk reports, metrics, and management insights to communicate the status of key risks, controls, remediation activities, and compliance initiatives to stakeholders at various levels.

  • Security Awareness: Support security education and awareness initiatives by helping communicate new policies, procedures, and security practices to IT teams and the broader organization.

  • Cross-Functional Collaboration: Build strong relationships across technical and non-technical teams and influence stakeholders to support security, compliance, risk management, and governance objectives.

  • Program & Process Support: Contribute to the selection, implementation, improvement, and management of GRC tools, platforms, processes, and operational procedures.

  • Prioritization & Delivery: Effectively prioritize multiple initiatives and deliverables while maintaining a high level of quality and attention to detail.

  • Perform other related duties and projects as assigned.

What We Look For

  • Bachelor’s degree in Information Systems, Information Technology, Cybersecurity, or a related field. An Associate’s degree may be considered based on relevant experience and certifications.

  • 5+ years of experience in Information Technology, Information Security, Governance, Risk, and/or Compliance.

  • Strong experience building, maintaining, or maturing Security Governance, Risk, and Compliance programs.

  • Solid understanding of information security risk management and compliance methodologies.

  • Experience facilitating and leading risk discussions using both qualitative and quantitative information.

  • Knowledge of common information security and IT frameworks, including ISO/IEC 27001, NIST Cybersecurity Framework, NIST 800-53, COBIT, and ITIL.

  • Experience supporting or coordinating security audits, assessments, certifications, and client assurance activities.

  • Experience with third-party/vendor security risk management.

  • Understanding of solution lifecycle management and associated information security and compliance requirements.

  • Experience developing and implementing Standard Operating Procedures (SOPs), policies, and processes.

  • Strong ability to influence and collaborate with stakeholders at different levels, including situations where formal authority is not present.

  • Demonstrated ability to establish and leverage internal and external cross-functional relationships.

  • Strong business acumen and the ability to understand business needs and translate them into practical security and compliance solutions.

  • Excellent written and verbal communication skills, with the ability to communicate security risks, findings, recommendations, and requirements to both technical and non-technical audiences.

  • Experience working with globally distributed teams and stakeholders.

  • Strong learning agility and ability to adapt to evolving security risks, regulations, technologies, and business requirements.

  • Relevant security certifications are preferred, such as CISSP, CRISC, CISM, CISA, or FAIR.

EEO Statement

Clario is an equal opportunity employer.  Clario evaluates qualified applicants without regard to race, color, religion, gender, national origin, age, sexual orientation, gender identity or expression, protected veteran status, disability/handicap status, or any other legally protected characteristic.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Risk and Compliance Analyst Related jobs

Other jobs at Clario

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.