368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$89k – $201k per year (Estimated)
Location
In office (Marysville)
Seniority
Senior · 3+ years exp
Employment
Contractor
Overview
Company
Impact
Profile match
SonSoft is a global IT services and consulting company that specializes in custom software development, systems integration, and technical staffing solutions. The enterprise serves organizations across key sectors such as healthcare, banking, automotive, and retail, helping them modernize infrastructure and optimize operational workflows.

SonSoft Inc. is a USA based corporation duly organized under the laws of the Commonwealth of Georgia. SonSoft Inc is growing at a steady pace specializing in the fields of Software Development, Software Consultancy and Information Technology Enabled Services.

  • Implement the overall risk management framework and processes, tools, and reporting methodologies on a continuous cycle.
  • Develop and standardize processes and procedures for ongoing risk identification, tracking, monitoring, and evaluating security measures and remediation efforts; communicate security control deficiencies and recommend mitigation plans, report status progress and with non-compliance issues; measure adherence to the security controls from a policy, governance and risk standpoint.
  • Perform third party supplier risk assessments by reviewing contracts for compliance with security policies, standards and practices; document security gaps and recommend appropriate remediation actions as necessary to minimize risks to the business.
  • Assist with documenting security policies, standards, and guidelines based on the organization's requirements, maturity level, and compliance objectives.
  • Facilitate awareness communications to various audiences, coordinate, and maintain project schedules, plans, and scope using standard project management methodologies.

Daily Task Performed:-

  • Planning, designing and implementing an overall risk management process for the organization;
  • Risk identification, analysis, tracking, monitoring, documenting exceptions, and communicating risks to owners
  • risk assessment, which involves analyzing risks as well as identifying, describing and estimating the risks affecting the business;
  • risk evaluation, which involves comparing estimated risks with criteria established by the organization such as costs, legal requirements and environmental factors, and evaluating the organization's previous handling of risks;
  • establishing and quantifying the organization's 'risk appetite', i.e. the level of risk they are prepared to accept;
  • risk reporting in an appropriate way for different audiences, for example, to the board of directors so they understand the most significant risks, to business heads to ensure they are aware of risks relevant to their parts of the business and to individuals to understand their accountability for individual risks;
  • corporate governance involving external risk reporting to stakeholders;
  • carrying out processes such as purchasing insurance, implementing health and safety measures and making business continuity plans to limit risks and prepare for if things go wrong;
  • conducting audits of policy and compliance to standards, including liaison with internal and external auditors;
  • providing support, education, and training to staff to build risk awareness within the organization
  • maintaining current documentation of all related activities for GRC Unit

Musts

  • Bachelor degree in Information Systems or equivalent work experience of a minimum of 3-5 years as an information security risk management practitioner, preferably in the financial, consulting, and/or global organizations
  • Prior work experience of risk management disciplines, security policies and standards, technology risk assessment, and third party supplier risk process and requirements
  • Current or previous experience with risk assessment methodologies and conducting risk analysis in a regulated environment or related IT audit background
  • Knowledge of security and control frameworks, such as ISO 27002, NIST, CobiT, COSO and ITIL
  • Experience with implementation of information security best practices for key areas such as access control, data protection, systems development life cycle, PCI DSS, and cloud services
  • Professional certification in risk management, and/or audit is preferred (e.g., CISSP, CRISC, CISA, or CISM)

Business Experience:-

  • Proven ability to work with and across all levels of the organizations and navigate organizational boundaries
  • Excellent organizational, interpersonal and communication skills with strong written, oral, and presentation skills; both delivery and creation of power points (must be able to distil complex topics into simple concepts)
  • Ability to effectively communicate with technical and executive audiences and develop and maintain strong peer/client/customer relationships underpinned by a service oriented approach to work
  • Adept at time management, tasks and projects prioritization, and multi-tasking
  • High level of personal integrity, and the ability to professionally handle confidential matters and exude the appropriate level of judgment and maturity
  • High degree of initiative, attention to detail, follow-up skills, deliver on commitments, dependability, and ability to work with little supervision
  • Demonstrated problem-solving skills and capability to drive process improvements
  • Highly proficient with Microsoft Office Suite especially Excel and PowerPoint; and SharePoint administration.

Wants:-

Demonstrate broad competency and understanding in a variety of IT security areas:

  • Security Policy Development and Management
    • Assist with documenting security policies, standards, standard operating procedures and guidelines based on the organization's requirements, maturity level, and compliance objectives.
  • · Risk Management
    • Perform risk assessments, generate risk reports/updates, tracking progress of remediation efforts.
  • Security Awareness
    • Facilitate and distribute communications to various audiences to promote about GRC Unit's objectives and goals.
  • Information security risk management, risk assessments, reporting, tracking and strong interpersonal and communication skills.

Connect with me at https://www.linkedin.com/in/mir-hasham-ali/ (For Direct Clients Requirements)

** U.S. Citizens and those who are authorized to work independently in the United States are encouraged to apply. We are unable to sponsor at this time.

Note:-

  • This is aContract job opportunity for you.
  • OnlyUS Citizen,Green Card Holder,GC-EAD,H4-EAD & L2-EAD can apply.
  • NoOPT-EAD, H1B & TNcandidates, please.
  • Please mention yourVisa Status in youremail orresume.

** All your information will be kept confidential according to EEO guidelines.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Marysville
$83k – $166k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Singapore
Python
DevOps
Splunk
Cybersecurity
PCI DSS
Apply
$17k – $44k per year (Estimated) • In office • Full-Time • 3+ years exp • Moscow
PowerShell
Python
JavaScript
Cybersecurity
PCI DSS
SOC 2
Apply
$140k – $266k per year (Estimated) • Remote/Hybrid • Full-Time • 12+ years exp • Bachelor's Degree • Atlanta
AI/ML
RAG
AI Agents
Feature Store
LLM Guardrails
LLMOps
DevOps
AWS
Azure
GCP
Platform Engineering
Cybersecurity
PCI DSS
Apply
Remote/Hybrid • Internship • Carmel
Cybersecurity
HIPAA
PCI DSS
Apply
$160k – $180k per year • Equity • In office • Full-Time • 3+ years exp • New York
JavaScript
Python
AI/ML
AI Agents
Cybersecurity
Crowdstrike
GDPR
Okta
PCI DSS
SOC 2
Management
Google Workspace
Slack
Apply
$155k – $261k per year (Estimated) • Remote • Full-Time • 12+ years exp • Bachelor's Degree
Java
Scala
AI/ML
Hadoop
Apply
$100k – $182k per year (Estimated) • Remote • Full-Time • 4+ years exp • Bachelor's Degree
JavaScript
Frontend
Bootstrap
JQuery
Apply
$128k – $261k per year (Estimated) • In office • Contractor • Austin
JavaScript
Frontend
Chart.js
Apply
$160k – $299k per year (Estimated) • In office • Full-Time • 11+ years exp • Saint Paul
Java
Apply
ReactJS(USC&GC) 9 years ago
$76k – $186k per year (Estimated) • In office • Full-Time • 4+ years exp • Milwaukee
JavaScript
Node JS
TypeScript
Frontend
Angular
Bootstrap
JQuery
React.js
Redux
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.