Pax8 Logo

Pax8

Director of Security GRC

Sorry, this job was removed at 02:38 p.m. (MST) on Tuesday, Jun 04, 2024
Be an Early Applicant
Remote
8 Locations
150K Annually
Remote
8 Locations
150K Annually

Pax8 is the leading cloud-based technology marketplace, simplifying the cloud journey for our partners by integrating technology, business intelligence and proactive service to deliver an unparalleled experience. Serving thousands of partners through the indirect sales channel, our mission is to be the world’s favorite place to buy cloud products. We are a fast-growing, dynamic and  high-energy startup organization, allowing you to make a meaningful impact on the business. Culture is important to us, and at Pax8, it’s business, and it IS personal. We are passionate, creative and humorously offbeat. We work hard, keep it fun, and expect the best. 

 

We Elev8 each other. We Advoc8 for our partners. We Innov8 continuously. We Celebr8 life.

No matter who you are, Pax8 is a place you can call home. We know there’s no such thing as a “perfect" candidate, so we don’t look for the right "fit" – instead, we look for the add. We encourage you to apply for a role at Pax8 even if you don’t meet 100% of the bullet points. We believe in cultivating an environment with a diversity of perspectives, in hopes that we can all thrive in an inclusive environment. 

We are only as great as our people. And we have great people all over the world. No matter where you live and work, you’re a part of the Pax8 team. This means embracing hybrid- and remote-work whenever possible.  

Position Summary:

The Director of Security Governance, Risk, and Compliance (GRC) is focused on ensuring Pax8’s security policy framework, exception management, risk assessment, and compliance efforts are operating effectively. They oversee the delivery of the security policy and standards, including management, tracking, and remediation of deviations from the security policies. Additionally, the Director supports the efforts of measuring the control effectiveness through risk assessment efforts to promote further maturity of the security program. They are a key member of the GRC team, providing guidance and direction to GRC professionals and collaborating with other departments across our organization.

Essential Responsibilities:

  • Manage inquiries and requests to update the security policy and standards through cross-functional team coordination.
  • Establish, implement, and manage requests for policy exceptions evaluating based on a risk model and promoting policy adherence and remediation.
  • Oversee control effectiveness and program maturity assessment efforts to support security program prioritization.
  • Participate in security automation and tool selection efforts aligned with the security policies and standards.
  • Develop and maintain security procedures including defining and documenting security best practices for managing a risk-based process.
  • Stay up to date on industry trends and best practices including continuously learning and adapting the security program to address evolving threats.
  • Collaborate with other departments including IT, engineering, legal, data management office, HR, and other departments to ensure security considerations are integrated into all business processes.
  • Measure and report on security performance by tracking key metrics (KPIs/KRIs), identifying areas for improvement, and reporting to the GRC leader and other stakeholders.

Ideal Skills, Experience, and Competencies:

  • At least (10) years of experience in an IT security GRC role.
  • Proven experience in policy management, exception management, remediation tracking, risk assessment, and risk-based prioritization efforts (e.g., asset criticality, data classification, BIA).
  • Understanding of public cloud deployments and associated security risks and controls.
  • Experience working in a Zero Trust focused security program,
  • Strong understanding of security best practices and frameworks (e.g., MITRE ATT&CK, NIST Cybersecurity Framework, ISO 27001:2022, SOC2 audit efforts).
  • Experience with incident management and response planning efforts.
  • Excellent communication, interpersonal, and leadership skills.
  • Ability to perform risk assessment efforts and deliver on security program initiatives.

Required Education & Certifications:

  • B.A./B.S. in related field or equivalent work experience.
  • Risk-focused certifications (e.g., CISA, CRISC, CISSP) preferred.

Compensation:

  • Qualified candidates can expect a salary beginning at $150,000 or more depending on experience

Expected Closing Date: 5/31/24

#LI-Remote #LI-AG1 #BI-Remote #DICE-A

*** Colorado law requires an estimated closing date for job postings. Please don't be discouraged from applying if you see this date has passed ***

 

*Note: Compensation is benchmarked on local Denver Metro area market rates. Qualified candidates in other locations can expect a salary package that may be adjusted based off applicable cost of wages in their respective location.

At Pax8 we believe that your Total Rewards should include a benefits package that shows how much we value our greatest assets. All FTE Pax8 people enjoy the following benefits:

  • Non-Commissioned Bonus Plans or Variable Commission
  • 401(k) plan with employer match
  • Medical, Dental & Vision Insurance
  • Employee Assistance Program
  • Employer Paid Short & Long Term Disability, Life and AD&D Insurance
  • Flexible, Open Vacation
  • Paid Sick Time Off
  • Extended Leave for Life events
  • RTD Eco Pass (For local Colorado Employees)
  • Career Development Programs
  • Stock Option Eligibility
  • Employee-led Resource Groups

 Pax8 is an EEOC Employer.

HQ

Pax8 Greenwood Village, Colorado, USA Office

The Landmark features an array of restaurants, entertainment & retail. Life in this district comes with access to some of the finest retailers in Denver. At the center of everything, The Landmark is a comfortable & connected community.

Similar Jobs

3 Hours Ago
Remote
Bengaluru, Karnataka, IND
Senior level
Senior level
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
The Principal Security Engineer leads penetration testing and code review, builds teams, mentors talent, and improves security processes at Atlassian.
Top Skills: AWSAzureGCPJava
2 Days Ago
Remote
Pune, Maharashtra, IND
Senior level
Senior level
Big Data • Cloud • Healthtech • Software • Big Data Analytics
The Senior Migration Consultant leads migration implementations for Veeva Vault R&D applications, providing expertise in data migration and advising customers on ETL processes.
Top Skills: JavaPythonRest ApisSQLVault ApiVeeva Vault R&D
2 Days Ago
Remote
Chennai, Tamil Nadu, IND
Senior level
Senior level
Big Data • Cloud • Healthtech • Software • Big Data Analytics
Lead customer migration implementations for Veeva's Vault R&D applications, providing expertise in data migration, mentoring, and project scoping support.
Top Skills: Etl ToolsJavaPythonRest ApisSQLVault PlatformVault R&D Applications

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account