What are the responsibilities and job description for the Governance Risk And Compliance And Integrated Risk Management Specialist position at DigitalXForce?
Company Description DigitalXForce is a Unified Enterprise Security Risk Posture Management (ESRPM) SaaS platform focused on delivering digital trust for the new era. Through a cybersecurity mesh architecture, it enables real-time, continuous, and automated governance, risk, and compliance (GRC) for modern organizations. The platform leverages data-driven insights, security blueprints, and regulatory control mapping to optimize and automate digital risk posture. DigitalXForce offers solutions such as attack surface management, risk quantification, automated audit and compliance, and third-party risk management. Its innovative approach helps organizations strengthen their security posture while maximizing the value of their digital transformation investments.
Role Description The Governance Risk and Compliance and Integrated Risk Management Specialist is a full-time hybrid role based in West New York, NJ, with flexibility for partial work from home. This role is responsible for designing, implementing, and maintaining GRC and integrated risk management frameworks aligned with industry standards and regulatory requirements. Day-to-day activities include assessing enterprise risks, mapping controls, monitoring compliance, and preparing reports and dashboards for leadership and stakeholders. The specialist collaborates with security, IT, and business teams to support automated audit workflows, third-party risk assessments, and continuous control monitoring across the DigitalXForce platform. The role also involves improving processes, documenting policies and procedures, and contributing to the development of security blueprints and regulatory mappings that enhance the platform’s capabilities.
Qualifications
Role Description The Governance Risk and Compliance and Integrated Risk Management Specialist is a full-time hybrid role based in West New York, NJ, with flexibility for partial work from home. This role is responsible for designing, implementing, and maintaining GRC and integrated risk management frameworks aligned with industry standards and regulatory requirements. Day-to-day activities include assessing enterprise risks, mapping controls, monitoring compliance, and preparing reports and dashboards for leadership and stakeholders. The specialist collaborates with security, IT, and business teams to support automated audit workflows, third-party risk assessments, and continuous control monitoring across the DigitalXForce platform. The role also involves improving processes, documenting policies and procedures, and contributing to the development of security blueprints and regulatory mappings that enhance the platform’s capabilities.
Qualifications
- Strong knowledge of governance, risk, and compliance (GRC) frameworks and integrated risk management practices, including experience with regulatory and industry standards (e.g., ISO 27001, NIST, SOC, PCI, HIPAA).
- Experience in cybersecurity risk management, including attack surface management, risk assessment, risk quantification, and continuous control monitoring.
- Ability to design, document, and implement policies, procedures, and control mappings, with solid skills in audit readiness, compliance testing, and evidence collection.
- Proficiency in using SaaS-based security or GRC platforms, with data analysis skills to interpret metrics, build dashboards, and generate actionable insights.
- Excellent written and verbal communication skills, including the ability to present complex risk and compliance topics clearly to technical and non-technical stakeholders.
- Collaborative working style with cross-functional teams, strong organizational skills, and the ability to manage multiple projects and deadlines in a hybrid work environment.
- Bachelor’s degree in information security, information systems, business, or a related field; professional certifications such as CISA, CISSP, CRISC, CGEIT, or similar are a plus.
- Prior experience in enterprise security, GRC consulting, or working in a SaaS or cybersecurity product company