Vendor risk management (TPRM): Own end-to-end vendor security assessment process across all risk tiers, covering software, AI capabilities, service providers and external workforce. This includes conducting a kick-off meeting with the business stakeholder to understand the use case and exposure, assigning a risk rating, managing security questionnaires, evaluating vendor responses using AI-powered security tools, reviewing security exhibits and contractual requirements, consolidating findings, and driving each review to a clear decision and remediation plan.
● Compliance and certifications: Manage external & internal security audits end-to-end and ongoing compliance maintenance for frameworks such as ISO 27001 and SOC 2, including control mapping, evidence collection, stakeholder coordination, auditor reporting and remediations supervision.
● Policies and Procedures: Drive the annual review and update of security policies based on audit findings, regulatory changes and existing processes. Manage policy exceptions and recommend corrective actions.
● Governance: Own governance actions across assigned security domains - identifying risks, aligning controls, and driving decisions end-to-end. Lead security routine weeks across the organization. Serve as the go-to person for employees on security and compliance matters.
● Awareness and education: Lead security awareness and training activities, including phishing simulations, online training programs, and company-wide security events using AI-powered security tools.
2-5+ years in GRC, information security, or compliance - preferably in a SaaS company.
● Strong working knowledge of security and privacy frameworks: ISO 27001, SOC 2, GDPR, HIPAA, and NIST.
● Proven ability to run TPRM independently: assess vendors, rate risk, and drive reviews to a clear decision and remediation plan.
● AI-native working style. Use AI tools to accelerate your work: drafting policies, summarizing vendor responses, researching frameworks, and structuring audit evidence.
● Comfortable working across technical and non-technical stakeholders - translating security requirements into language that lands.
● Strong sense of ownership, responsibility, and problem-solving approach.
● Ability to manage multiple active workstreams without losing detail.
● Excellent written and verbal communication in Hebrew and English.