yandex
smartsheet
Страна
США
Зарплата
235 000 $ – 315 000 $
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
DirectorУдалённоПолная занятость

Director, GRC, Engineering (Remote Eligible)

Оценка ИИ

Отличная вакансия с высокой прозрачной зарплатой, удаленным форматом работы и сильным социальным пакетом. Позиция уровня Director с прямым влиянием на стратегию компании и возможностью внедрять передовые технологии (AI, GRC-as-Code).


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Высокая сложность обусловлена требованием сочетания 10-летнего опыта в GRC с глубокими техническими знаниями (AWS, Terraform, CI/CD) и навыками ведения переговоров по контрактам. Роль подразумевает прямое подчинение CISO и управление сложными комлпаенс-процессами вроде FedRAMP.

Анализ зарплаты

Медиана260 000 $
Рынок210 000 $ – 320 000 $
Оценка ИИ

Предлагаемый диапазон $235k – $315k полностью соответствует и даже несколько превышает рыночные стандарты для позиции Директора по GRC в технологических компаниях США, особенно с учетом удаленного формата.

Сопроводительное письмо

I am writing to express my strong interest in the Director, GRC Engineering position at Smartsheet. With over a decade of experience in governance, risk, and compliance, coupled with a deep technical background in AWS and infrastructure-as-code, I am excited about the opportunity to lead your GRC function toward a more automated, 'policy-as-code' future. My experience in managing complex audits like FedRAMP and SOC2, while maintaining a customer-centric approach during contract redlining, aligns perfectly with the requirements of this role.

Throughout my career, I have focused on bridging the gap between rigid compliance frameworks and agile engineering practices. I am particularly drawn to Smartsheet's vision of deploying AI into GRC processes and building automation into every layer of the security program. I am confident that my leadership style—fostering a culture of continuous learning and technical excellence—will help scale your GRC team and further strengthen the trust your customers place in Smartsheet's platform.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в smartsheet уже сейчас

Присоединяйтесь к Smartsheet в качестве директора по GRC и внедряйте инновации в области безопасности и автоматизации на глобальном уровне!

Описание вакансии

For over 20 years, Smartsheet has helped people and teams achieve–well, anything. From seamless work management to smart, scalable solutions, we’ve always worked with flow. We’re building tools that empower teams to automate the manual, uncover insights, and scale smarter. But more than that, we’re creating space– space to think big, take action, and unlock the kind of work that truly matters. Because when challenge meets purpose, and passion turns into progress, that’s magic at work, and it’s what we show up for everyday.

We are looking for an experienced GRC leader with a strong engineering background. Governance, risk and compliance is key to ensuring the cybersecurity program we’ve built is continuously improving. This leader will be responsible for maintaining a high level of trust with our customers through our GRC program. You will also be able to interact with customers and auditors on a regular basis to build and maintain that trust directly. You’ll also ensure our numerous annual audits are completed on time and minimal impact to the rest of the business.

You’ll lead our existing GRC team members and support their continued growth to achieve the vision you set for GRC at Smartsheet. You will also collaborate across the entire business and be a customer minded champion for cyber compliance. You’ll also partner closely with our Privacy and Legal team. This role reports directly to our CISO.

Responsibilities:

  • Build automation into GRC
  • Deploy GRC-as-Code / Policy-as-Code
  • Deploy AI into our GRC processes where appropriate
  • Own, manage and be accountable for supporting our revenue team by reviewing contracts both on net new deals as well as renewals.
  • Lead and build a high performing team
  • Maintain a high level of customer service for both internal and external stakeholders and customers.
  • Lead our annual external audits such as SOC2, ISO 27001, ISO 27701, FedRAMP and others and serve as primary point of contact for external auditors.
  • Lead our internal audits and readiness assessments
  • Work closely with procurement teams and manage vendor security reviews
  • Manage all cybersecurity related policies, procedures, and standards.
  • Partner closely with Product Security & Privacy, Engineering and Product teams on security reviews and evidence collection for audits
  • Define and track key performance indicators (KPIs) and key risk indicators (KRIs) from engineering and cloud telemetry data to provide measurable, risk-based insights to leadership

Skills Required:

  • Leadership & Management:
  • 5+ years of people leadership experience
  • 10+ years general GRC experience
  • Ability to delegate and dive deep with your team to solve problems quickly
  • Define and execute the multi-year vision, strategy, and  roadmap for the GRC Engineering function, aligning it with overall business objectives and the security program's evolution.
  • Mentor and coach team members, fostering a culture of continuous learning, automation-first thinking, and professional growth in both GRC and technical engineering skills.
  • Manage the GRC Engineering budget, external vendor relationships, and resource allocation to ensure optimal efficiency and effectiveness of the compliance program.
  • Drive a proactive, security-minded, and compliance-aware culture across the entire engineering and product organization.
  • Technical Expertise:
  • Strong experience in reviewing and redlining contracts
  • Ability to strike a balance between customer requirements and organizational risk when considering contracting
  • Strong negotiation skills when managing vendor and supply chain risks
  • Proven ability to to build business-centric Third Party Risk programs
  • Experience with and deep knowledge of NIST 800-53
  • Understanding of product development, SDLC and CI/CD
  • Deep knowledge of AWS and container architecture
  • Familiarity with tools like Terraform or CloudFormation for managing and auditing infrastructure configuration as code.
  • Experience integrating GRC processes with vulnerability management and security configuration tools to track remediation and ensure control coverage.
  • Operational & Collaboration Skills:
  • Strong communication (written and verbal) and diplomatic skills in building consensus from dispersed teams with competing priorities.
  • Build and nurture strong cross-business relationships with Engineering, IT, Product, Legal, Sales and the broader cybersecurity team.

Current US Perks & Benefits:

  • Medical/vision and dental coverage options for full-time employees
  • 401k Match to help you save for your future (50% of your contribution up to the first 6% of your eligible pay)
  • Monthly stipend to support your work and productivity
  • Flexible Time Away Program, plus Sick Time Off
  • US employees are automatically covered under Smartsheet-sponsored life insurance, short-term, and long-term disability plans
  • US employees receive 12 paid holidays per year
  • Up to 24 weeks of Parental Leave
  • Personal paid Volunteer Day to support our community
  • Opportunities for professional growth and development including access to Udemy online courses
  • Company Funded Perks, including a counseling membership, local retail discounts, and your own personal Smartsheet account
  • Teleworking options from any registered location in the U.S. (role specific)

Smartsheet provides a competitive base salary range for roles that may be hired in different geographic areas we are licensed to operate our business from. Actual compensation is determined by several factors including, but not limited to, level of professional, educational experience, skills, and specific candidate location. In addition, this role will be eligible for a market competitive incentive opportunity.

US Base Salary Pay Range

$235,000—$315,000 USD

Get to Know Us:

At Smartsheet, your ideas are heard, your potential is supported, and your contributions have real impact. You’ll have the freedom to explore, push boundaries, and grow beyond your role. We welcome diverse perspectives and nontraditional paths—because we know that impact comes from individuals who care deeply and challenge thoughtfully. When you’re doing work that stretches you, excites you, and connects you to something bigger, that’s magic at work. Let’s build what’s next, together.

Equal Opportunity Employer:

Smartsheet is an Equal Opportunity (EEO) employer committed to fostering an inclusive environment with the best employees. It is our policy to provide equal employment opportunities to all qualified applicants in accordance with applicable laws in the US, UK, Australia, Germany, Costa Rica, Japan, Bulgaria, and India. All qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.

If there are preparations we can make to help ensure you have a comfortable and positive interview experience, please let us know.

#LI-Remote

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • GRC
  • AWS
  • NIST 800-53
  • SOC2
  • ISO 27001
  • FedRAMP
  • Terraform
  • CloudFormation
  • CI/CD
  • SDLC
  • Kubernetes
  • Risk Management
  • Contract Negotiation

Возможные вопросы на собеседовании

Проверка видения кандидата относительно автоматизации GRC, что является ключевым требованием вакансии.

Как бы вы реализовали концепцию 'Policy-as-Code' в нашей текущей инфраструктуре AWS и Terraform?

Роль требует активного участия в продажах и работе с клиентами.

Расскажите о вашем опыте согласования условий безопасности в контрактах (redlining). Как вы находите баланс между требованиями клиента и рисками компании?

Smartsheet работает с государственными и международными стандартами.

Каков ваш опыт прохождения аудитов FedRAMP и какие основные сложности вы видите в поддержании этого статуса?

Оценка лидерских качеств и умения развивать команду.

Как вы подходите к обучению GRC-специалистов техническим навыкам (например, облачной архитектуре или кодингу)?

Проверка умения работать с данными для отчетности перед руководством.

Какие KPI и KRI вы считаете наиболее важными для оценки эффективности программы GRC в инженерной организации?

Похожие вакансии

fieldwire
220 000 $ – 300 000 $

Director, Information & Application Security

DirectorГибридКанада
Information Security · Application Security · SOC2 · ISO 27001 · NIST · Cloud Security · AI Security · Risk Management · DevSecOps · SDLC · CISSP · CISM · CISA · IAM · Endpoint Security
+15 навыков
accenturefederalservices
186 300 $ – 360 800 $

IAM Configurator/Administrator Associate Director

DirectorГибридСША
IAM · Active Directory · LDAP · PAM · RBAC · SIEM · SOAR · Splunk · QRadar · LogRhythm · ArcSight · Sentinel · Cortex XSOAR · Python · PowerShell · NIST · ISO 27001 · CISSP · CISM · CISA · CompTIA Security+ · Okta · SailPoint
+23 навыков
accenturefederalservices
186 300 $ – 360 800 $

SIEM/SOAR Administrator/Assessor Associate Director

DirectorВ офисеСША
SIEM · SOAR · Splunk · QRadar · LogRhythm · ArcSight · Sentinel · Cortex XSOAR · Python · PowerShell · NIST · ISO 27001 · CISSP · CISM · CEH · GIAC
+16 навыков
mongodb
160 000 $ – 314 000 $

Director, Identity & Security Product Management

DirectorУдалённоСША
IAM · Cloud Security · AWS · Azure · Google Cloud Platform · Cryptography · Jira · Aha! · Okta · Network Security · Database Security · Microservices · Risk Management
+13 навыков
mongodb
118 000 ₽ – 148 000 ₽

Director, Identity & Security Product Management

DirectorГибридКанада
IAM · Cybersecurity Engineering · Cloud Security · Cryptography · AWS · Google Cloud Platform · Azure · Okta · Jira · Product Strategy · Risk Management · Microservices
+12 навыков
mongodb
168 000 $ – 330 000 $

Director, Cybersecurity Incident Response

DirectorГибридСША
Cybersecurity · Incident Response · CISSP · Digital Forensics · Security Information and Event Management · SOAR · Security Operations · Leadership · Risk Management
+9 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

smartsheet
Страна
США
Зарплата
235 000 $ – 315 000 $