Spectrum Labs logo

Cyber GRC Lead

Spectrum Labs

Ramat Gan, Tel Aviv District, IsraelJobNo compensation foundPosted 1w agoVerified open 4 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
No compensation found
Location
Ramat Gan, Tel Aviv District, Israel
Work Authorization
Not specified

Job overview

Spectrum Labs is hiring a Cyber GRC Lead. Spectrum Labs seeks a skilled Cyber GRC Lead to join Alice’s CISO team, responsible for driving security initiatives across third‑party risk, awareness programs, customer due diligence, risk management, GRC automation, compliance, AI governance, and close collaboration with legal and privacy functions.

Key focus areas include Lead end‑to‑end operational TPRM lifecycle, assessing and continuously monitoring vendor security postures., Establish risk criteria for third‑party AI integrations to prevent data leakage and IP risks., and Design and manage enterprise‑wide security awareness and training program using modern platforms..

Important skills include Third-Party Risk Management, GRC Automation Platforms, Cloud Security, AWS, GCP, and Azure.

Skills & qualifications

RequiredNice to have

Skills

Third-Party Risk ManagementGRC Automation PlatformsCloud SecurityAWSGCPAzureNIST CSFISO 27001NIST AI RMFISO 42001SOC 2 Type IIGDPRCCPAEU AI ActSecurity Awareness PlatformsPhishing SimulationsScriptingCommunicationNegotiation

Qualifications

4+ Years Cyber GRC ExperienceIT Audit ExperienceSecurity Consulting ExperienceProven Track Record Owning SOC 2 Type II Compliance LifecyclesProven Track Record Owning ISO 27001 Compliance LifecyclesDirect Experience Partnering With Legal and Privacy Teams on GDPR ComplianceExperience Handling Customer DDQsExperience Vendor Security Reviews (TPRM)Experience Managing Security Awareness PlatformsFluent Professional EnglishCISA CertificationCRISC Certification

Full job description

Description We are seeking a skilled and experienced Cyber GRC Lead to join Alice (Formerly ActiveFence) CISO team. The ideal candidate will be responsible for driving the security initiatives.

Key Responsibilities:

  • Third-Party Risk Management (TPRM) & Supply Chain Security:

  • Lead the end to end Operational TPRM lifecycle, assessing and continuously monitoring the security postures of vendors, SaaS platforms, AI tool providers.

  • Establish risk criteria for third party tools, ensuring third party AI integrations do not introduce data leakage, or intellectual property risks.

  • Security Awareness & Culture & Behavioral Programs:

  • Design and manage the enterprise wide security awareness and training program using modern platforms.

  • Conduct targeted phishing simulations, role based security training and specialized training among others on GenAI risks (prompt injection, shadow AI, data exposure).

  • Customer Due Diligence (DDQs) & Sales Enablement:

  • Manage and streamline the end to end customer security assessment process (DDQs, RFPs, Security Questionnaires, customer audits).

  • Build and maintain a centralized, automated knowledge base to expedite responses, directly removing friction from sales velocity and supporting enterprise revenue goals.

  • Risk Management Frameworks & Risk Advisory:

  • Lead ongoing security risk assessments, maintaining a dynamic Risk Register mapped to real world business impacts.

  • Provide continuous risk advisory services across business units, establishing risk treatment and mitigation plans that balance operational agility with guardrails.

  • GRC Automation & Continuous Compliance:

  • Architect and leverage high-level GRC automation tools to move from point in time audits to continuous control monitoring.

  • Drive process automation for evidence collection, vendor assessments, and policy management to reduce manual overhead across technical teams.

  • Compliance, Frameworks & AI Governance:

  • Maintain core information security certifications (ISO 27001, SOC 2 Type II, etc)

  • Build, operationalize, scale the organization's AI Governance Framework, referencing established benchmarks (NIST AI RMF, ISO/IEC 42001).

  • Lead internal and external audit readiness, acting as the primary liaison for independent auditors.

  • Close Collaboration with Legal, Privacy & DPO:

  • Partner directly with Legal and Privacy teams to operationalize global data protection standards (GDPR, CCPA, EU AI Act) align security controls with contractual commitments. Requirements Professional Experience:

  • 4+ years of hands on experience in Cyber GRC, IT audit, or security consulting within global, fast paced technology companies.

  • Proven track record of owning SOC 2 Type II and ISO 27001 compliance lifecycles.

  • Direct experience partnering with Legal and Privacy teams on GDPR compliance and privacy risk assessments.

  • Demonstrated track record handling customer DDQs, vendor security reviews (TPRM), and managing security awareness platforms.

  • Technical, Automation & AI Capabilities:

  • Strong technical proficiency in utilizing GRC automation platforms to automate control testing, evidence gathering, and vendor workflows.

  • Working knowledge of cloud security (AWS/GCP/Azure), AI/ML operational risks

  • Deep familiarity with core frameworks: NIST CSF, ISO 27001, NIST AI RMF, ISO 42001.

  • Leadership & Stakeholder Management:

  • Exceptional communication and negotiation skills, capable of translating complex security and compliance demands into clear business terms

  • A pragmatic, business first mindset focused on designing guardrails that empower teams rather than introducing operational roadblocks.

  • Fluent in professional English (written and verbal). Preferred Qualifications (Pluses):

  • Industry certifications: CISA, CRISC, CISM, CISSP, CIPP/E, or IAPP AIGP.

  • Experience with automated TPRM and vendor intelligence solutions

  • Practical scripting capabilities to custom build or tie together GRC automation workflows. About Alice Alice is a trust, safety, and security company built for the AI era. We safeguard the communicative technologies people use to create, collaborate, and interact—whether with each other or with machines.

In a world where AI has fundamentally changed the nature of risk, Alice provides end-to-end coverage across the entire AI lifecycle. We support frontier model labs, enterprises, and UGC platforms with a comprehensive suite of solutions: from model hardening evaluations and pre-deployment red-teaming to runtime guardrails and ongoing drift detection.

You've read the whole posting — now see how you match it.