Lead client-facing security consulting engagements across a variety of domains - security project management, risk assessments, and end-to-end compliance programs.
- Drive ISO and framework compliance (ISO 27001, NIST CSF, SOC 2, CIS Controls, GDPR,חוק הגנת הפרטיות ותיקון 13 ;and similar), owning control matrices, evidence repositories, and audit readiness from kick-off to certification.
- Validate controls hands-on, not just on paper - assess cloud environments (AWS/Azure/GCP), IAM configurations, logging/monitoring setups, and general network and application security posture to confirm real-world control effectiveness.
- Champion AI-driven GRC automation - build and deploy AI/LLM-enabled workflows for risk assessment, control testing, evidence collection, and policy generation, and help clients establish safe frameworks for adopting Generative AI internally.
Requirements: Experience Certifications
- 5+ years of experience in GRC, Information Security, or a related governance, risk, or compliance role.
- Certified in at least one of: CISM, CISSP, CRISC, CISA.
Cloud security certification (AWS, Azure, or GCP) is a plus, or equivalent hands-on experience.
GRC Compliance
- Deep experience with major frameworks and standards implementations.
- Control ownership and audit readiness - you can run an audit, not just prepare for one.
DPO Certification is advantage.
This position is open to all candidates.