JFrog logo

JFrog

GRC Specialist at JFrog

Tel Aviv/ Netanya, IsraelFull-timeITPosted about 1 month ago
Apply with Pipeline

About the Role

<p>At JFrog, we’re reinventing DevSecOps to help the world’s greatest companies innovate. Our team of industry-leading software security experts is a true pioneer, constantly pushing the boundaries with original research and technological innovation. JFrog is a special place with a unique combination of brilliance, spirit, and just all-around great people. Thousands of customers, including the majority of the Fortune 100, trust JFrog to manage, accelerate, and secure their software delivery from code to production – a concept we call “liquid software”. Wouldn't it be amazing if you could join us on our journey?</p> <p>We are seeking a GRC Specialist (Governance, Risk, and Compliance) to join our growing GRC Team. This is a fantastic opportunity to be part of a growing team and support the company as it grows and matures. If you're a team player, self-driven, creative thinker, passionate about cybersecurity, and capable of blending a process-oriented mindset with a tech-oriented outlook, we are looking for you!</p> <h5><strong>As a GRC specialist at JFrog you will...</strong></h5> <ul> <li>Maintain internal and external trust platforms, supporting ongoing customer due diligence activities including audits, questionnaires, and reviewing security contractual requirements.</li> <li>Provide training and guidance to sales teams on compliance-related matters and develop tools and resources to enable the Sales Team to efficiently respond to compliance inquiries from prospective and existing customers.</li> <li>Collaborate with cross-functional teams to support and enhance the overall GRC program.</li> <li>Ensure company policies, procedures, and controls are aligned with regulatory requirements and industry standards.</li> <li>Proactively gather customer feedback and stay abreast of industry trends to adapt and mature the GRC program accordingly.</li> <li>Implement improvements and updates to the program, based on regulatory changes and customer requirements.</li> <li>Participate in risk assessment and risk management processes.&nbsp;</li> </ul> <h5><strong>To be a GRC specialist at JFrog you need...</strong></h5> <ul> <li>Minimum 1-2 years as a cyber security / GRC specialist, expert, or consultant</li> <li>Strong knowledge and hands-on experience with ISO 27001 and SOC 2 Type II&nbsp;</li> <li>Familiarity with additional security frameworks as well as privacy regulations and standards (NIST, CSA, CAIQ, SIG, GDPR, CCPA, ISO 27701) is an advantage.</li> <li>An excellent ability to communicate verbally and in writing</li> <li>Ability to work on multiple projects simultaneously</li> <li>Project management skills</li> <li>Self-driven and fast learner with a can-do approach</li> <li>Passionate about the team and responsibilities</li> <li>Experience with auditing cloud environments</li> <li>Experience in working with regulators and auditors</li> <li>Experience in working with GRC tools</li> </ul> <p><br><br></p>