
HiQ · Linköping
Nu söker vi en Team Lead till vårt växande Cyber Security-team på HiQ! Den här rollen är för dig som har lång erfarenhet och djup kompetens inom GRC-området. Nu...
Nu söker vi en Team Lead till vårt växande Cyber Security-team på HiQ! Den här rollen är för dig som har lång erfarenhet och djup
kompetens inom GRC-området. Nu finns en unik möjlighet för dig att vara med och leda, utveckla och stötta kollegor och kunder i
utmanade uppdrag som ställer stora krav på så väl kompetens, som ansvar och kreativ lösningsförmåga.
Hos oss finns möjlighet att vara med och bygga något stort! Det är en lärorik och rolig resa vi har framför oss där vår spelplan
är enorm och du kan göra ordentliga avtryck i massor av olika bolag och branscher. Vi kommer värdera din erfarenhet och dina
tankar om hur vi på bästa sätt kan bygga vidare området.
Vi har en bred kundbas där du får möjlighet att verka i olika branscher och få uppdrag hos kunder med både ett väletablerat
cybersäkerhetsarbete samt hos kunder i kritiska faser där vår erfarenhet är helt avgörande.
Om HiQ
På HiQ välkomnar vi alla typer av kollegor – det viktigaste är att du gillar utmaningar och är en schysst lagspelare. Vi består av
utvecklare, arkitekter, agila projektledare, UX/UI-designers, cyberspecialister m.fl. – en härlig mix av kompetenser, perspektiv
och personligheter som stärker oss varje dag. Vi växer ständigt med ny energi, och här får du både utveckla och utvecklas. Du får
förtroendet att prova först och lära sedan, och vi bygger HiQ tillsammans – ett bolag vi själva vill jobba på.
Vi tror på att vara riktigt bra på det vi gör, men också på att ha jäkligt kul längs vägen. Vår kultur är drivande – inte styrande
– vilket gör att du kan vara dig själv till 100%. Det gör att vi tar vårt jobb seriöst, men inte alltid oss själva. Och vi menar
det när vi säger att bra stämning leder till bra resultat.
Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether you're brainstorming, creating a prototype, translating designs into code, or iterating with AI. From idea to product, Figma empowers teams to streamline workflows, move faster, and work together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us! Figma's GRC team helps build and maintain trust with our users, regulators, business partners, and the organizations that rely on Figma every day. We partner across the company to strengthen security, manage risk, maintain compliance, and scale the programs that support our continued growth. We're growing our team and looking for security, risk, and compliance professionals across several disciplines. Whether your expertise is in compliance, risk management, governance, GRC tooling, or customer trust, you'll have the opportunity to build programs, improve processes, and help shape how Figma scales security and trust. Roles we hire for on this team: * Compliance Management * Lead compliance and certification programs across security and regulatory frameworks * Manage audit cycles, partner with external assessors, and drive audit readiness initiatives * Improve controls, processes, and evidence management practices across the organization * Security Risk Management * Build and maintain risk and controls frameworks that support Figma's security posture * Assess, prioritize, and communicate security risks across the business * Develop third-party risk management strategies and enterprise risk reporting programs * Policy & Governance * Manage the lifecycle of organizational security policies, standards, and procedures * Drive policy awareness and stakeholder engagement across the company * Ensure governance practices align with regulatory requirements and business objectives * GRC Platforms & Enablement * Select, implement, and optimize GRC platforms and supporting workflows * Scale evidence collection, reporting, and program management capabilities * Identify opportunities to automate and streamline GRC operations * Customer Trust * Support customer trust and business enablement activities across the sales lifecycle * Manage security knowledge bases, customer-facing documentation, and trust publications * Respond to customer security inquiries, audits, and questionnaires This is a full time role that can be held from one of our US hubs or remotely in the United States. WHAT YOU'LL DO AT FIGMA: * Lead compliance programs across frameworks such as SOC 2, ISO 27001, FedRAMP, SOX ITGC, GDPR, and NIS2 * Manage external audits and certification activities while partnering with auditors and assessors * Build and maintain risk and controls frameworks, including common control frameworks that support multiple certifications * Conduct risk and gap assessments and drive remediation efforts across technical and business stakeholders * Improve control effectiveness and operational efficiency through rationalization and process optimization * Implement and optimize GRC platforms that scale evidence collection and program management * Maintain security policies and governance processes that align with organizational risk objectives * Support customer trust initiatives, including security questionnaires, audits, and customer-facing security communications We’d love to hear from you if you have: * 4+ years of experience in information security, compliance, risk management, or a related field * Hands-on experience supporting security and compliance frameworks such as SOC 2, ISO 27001, FedRAMP, PCI-DSS, or SOX ITGC * Experience leading or supporting audits and partnering with external assessors * Demonstrated ability to conduct assessments, drive remediation efforts, and manage cross-functional initiatives * Exceptional written and verbal communication skills across technical, business, and executive audiences * Demonstrated ability to improve processes, manage competing priorities, and build strong cross-functional partnerships While it’s not required, it’s an added plus if you also have: * Operated in a public company environment with SOX ITGC requirements * Supported FedRAMP authorization, SSP development, 3PAO coordination, or continuous monitoring activities * Earned security or risk certifications such as CISA, CISSP, CISM, or CRISC * Implemented or administered GRC platforms such as Vanta, Drata, or similar tools * Scaled security, compliance, or risk programs in a high-growth environment At Figma, one of our values is Grow as you go. We believe in hiring smart, curious people who are excited to learn and develop their skills. If you’re excited about this role but your past experience doesn’t align perfectly with the points outlined in the job description, we encourage you to apply anyways. You may be just the right candidate for this or other roles. Pay Transparency Disclosure If based in Figma’s San Francisco or New York hub offices, this role has the annual base salary range stated below. Job level and actual compensation will be decided based on factors including, but not limited to, individual qualifications objectively assessed during the interview process (including skills and prior relevant experience, potential impact, and scope of role), market demands, and specific work location. The listed range is a guideline, and the range for this role may be modified. For roles that are available to be filled remotely, the pay range is localized according to employee work location by a factor of between 80% and 100% of range. Please discuss your specific work location with your recruiter for more information. Figma offers equity to employees, as well a competitive package of additional benefits, including health, dental & vision, retirement with company contribution, parental leave & reproductive or family planning support, mental health & wellness benefits, generous PTO, company recharge days, a learning & development stipend, a work from home stipend, and cell phone reimbursement. Figma also offers sales incentive pay for most sales roles and an annual bonus plan for eligible non-sales roles. Figma’s compensation and benefits are subject to change and may be modified in the future. Annual Base Salary Range: $153,000—$296,000 USD At Figma we celebrate and support our differences. We know employing a team rich in diverse thoughts, experiences, and opinions allows our employees, our product and our community to flourish. Figma is an equal opportunity workplace - we are dedicated to equal employment opportunities regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity/expression, veteran status, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. We will work to ensure individuals with disabilities are provided reasonable accommodation to apply for a role, participate in the interview process, perform essential job functions, and receive other benefits and privileges of employment. If you require accommodation, please reach out to accommodations-ext@figma.com. These modifications enable an individual with a disability to have an equal opportunity not only to get a job, but successfully perform their job tasks to the same extent as people without disabilities. Examples of accommodations include but are not limited to: * Holding interviews in an accessible location * Enabling closed captioning on video conferencing * Ensuring all written communication be compatible with screen readers * Changing the mode or format of interviews To ensure the integrity of our hiring process and facilitate a more personal connection, we require all candidates keep their cameras on during video interviews. Additionally, if hired you will be required to attend in person onboarding. By applying for this job, the candidate acknowledges and agrees that any personal data contained in their application or supporting materials will be processed in accordance with Figma's Candidate Privacy Notice.
Sr Manager, InfoSec Governance Risk and Compliance (GRC) (San Francisco Bay Area, California, United States) Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions. COMPANY OVERVIEW At Ivalua we are a global community of exceptional professionals, who believe that digital transformation revolutionizes supply chain sustainability and resiliency to unlock the power of supplier collaboration. We achieve this through our leading cloud-based spend management platform that empowers hundreds of the world's most admired brands to effectively manage all categories of spend and all suppliers to increase profitability, improve ESG (environmental, social, and corporate governance) performance, lower risk, and improve productivity. Driven by our passions and fueled by our shared ambitions, we empower and challenge each other to create meaningful experiences for our colleagues, customers, partners, and communities. Learn more at www.ivalua.com. Follow us on LinkedIn and Twitter. THE OPPORTUNITY CONTEXT: Our InfoSec team is dedicated to building, maintaining, and continuously improving Ivalua’s Information Security program globally. We provide peace of mind and assurance of protection and safety to our customers. In this fast-growing environment, the GRC program is critical to ensuring compliance with industry standards and certifications, managing risks, and supporting business growth. ROLE: We are currently looking for an experienced InfoSec Governance Risk and Compliance (GRC) Sr Manager to lead a global team and own the GRC program worldwide. Reporting to the InfoSec leadership, you will manage and develop a high-performing team, drive compliance efforts, and serve as a subject matter expert on security frameworks and standards. WHAT YOU WILL DO WITH US * Lead and own the Governance, Risk, and Compliance (GRC) program globally, managing and developing a high-performing team. * Manage and drive compliance efforts and audits for certifications such as FedRAMP, IRAP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, and others. * Serve as the subject matter expert (SME) on security frameworks and standards including NIST SP 800-53 Rev 5, NIST 800-171, ITAR, FedRAMP, PCI DSS, SOC2, etc., providing guidance to internal stakeholders. * Efficiently manage and respond to customer security audit and compliance requests in a timely manner. * Maintain continuous compliance and monitoring of security controls to ensure ongoing adherence to standards. * Collaborate closely with Sales, Marketing, and Customer Success teams to effectively communicate Ivalua’s security posture to prospects and customers. * Review and negotiate information security exhibits and contractual terms in partnership with the legal team. * Lead the Security Awareness and Training program to promote a culture of security across the organization. * Track, manage, and drive remediation efforts for control deficiencies and gaps identified through internal and external audits. * Oversee the Third Party Risk and Vendor Security Assessment program to mitigate supply chain risks. * Develop, maintain, and enforce InfoSec policies, standards, and plans. YOUR PROFILE If you have the below experience and strengths this role could be for you: Skills and Experience: * At least 7+ years of proven experience leading GRC programs and managing compliance certifications and audits (FedRAMP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, IRAP, etc.). * At least 3+ years experience as a direct leader, managing a team. The position will be part of an established global team with opportunity to grow the team * Strong knowledge of security frameworks such as NIST SP 800-53, NIST 800-171, ITAR, PCI DSS, SOC2, and FedRAMP. * Demonstrated ability to manage and influence stakeholders across multiple departments and time zones. * Excellent project management, analytical, and problem-solving skills with keen attention to detail. * Strong interpersonal and communication skills, capable of building trust and managing conflicts effectively. * Self-motivated with a high degree of initiative and ability to work independently. * Ability to handle multiple competing priorities and deadlines efficiently. * Bachelor’s degree in related field preferred or equivalent experience with proven skills Soft Skills: * Excellent interpersonal, communication, and organizational skills. * Team player with the ability to interface effectively with a broad range of individuals and roles, including IT and vendors. * High degree of initiative, dependable, and able to work well with limited supervision. WHAT HAPPENS NEXT If your application fits this specific position’s needs, our skilled Talent team will reach out to schedule an initial screening call. Get one step closer to achieving your goals – apply today! Our Talent team will guide you through every step of the interview process - from preparation to completion. They're here to support you! Our recruitment process is designed to assess your competencies through a series of personalized interviews with internal stakeholders relevant to the role. Interviews will be conducted virtually via video or on-site with face-to-face meetings. LIFE AT IVALUA * Hybrid working model (3 days in the office per week) * We're a team dedicated to pushing the boundaries of product innovation and technology * Sustainable Growth, Privately Held * A stable and cash-flow positive Company since 10 years * Snacks and weekly lunches in the office * Feel empowered to pursue your goals with improved team collaboration and increased creativity/productivity * Unlock and unleash your full professional potential with our exceptional training and career development program * Join a dynamic and international team of top-notch professionals who are experts in their respective fields. Collaborate with like-minded individuals who are deeply passionate and highly motivated about their work. Experience a truly diverse and inclusive work environment where your unique contributions are highly valued * Regular social events, competitive outings, team running events, and musical activities, * Comparably recognized Ivalua for the following (https://www.comparably.com/companies/ivalua) : Powered by People - Powered by You! United by our values we embrace diversity and equity in the broadest possible sense to create an inclusive workplace. To help our customers make supply chains more efficient, sustainable and resilient, we rely on a global team with a variety of backgrounds, skills and views. We believe in equal opportunity and in diversity as a driver of innovation that cultivates a spirit of inclusiveness, creates a productive and fun place to work, and provides fulfilling career opportunities for all Ivaluans. https://www.linkedin.com/company/ivalua/about/ Experience life at Ivalua - check out our captivating video! Gain insight into our unique company culture and get a glimpse of what it's like to work with us. Ivalua’s core values include a priority on Care & Grow People. We take matters like pay equity very seriously and strive to reward our employees appropriately and fairly for their talents. The compensation range for this position reflects the cost of labor across our US locations and is based upon careful and continual market research. In addition to location, compensation may also vary based upon job-related knowledge, skills, and experience. Title: Manager, InfoSec Governance Risk and Compliance (GRC) Range minimum: USD 112000 Range maximum: USD 208000 Additional compensation / rewards: Ivalua also offers exceptional benefits including medical, dental, vision and transportation. #LI-SG1 #LI-HYBRID #LI-DNI
Sr Manager, InfoSec Governance Risk and Compliance (GRC)(New York City, New York, United States) Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions. COMPANY OVERVIEW At Ivalua we are a global community of exceptional professionals, who believe that digital transformation revolutionizes supply chain sustainability and resiliency to unlock the power of supplier collaboration. We achieve this through our leading cloud-based spend management platform that empowers hundreds of the world's most admired brands to effectively manage all categories of spend and all suppliers to increase profitability, improve ESG (environmental, social, and corporate governance) performance, lower risk, and improve productivity. Driven by our passions and fueled by our shared ambitions, we empower and challenge each other to create meaningful experiences for our colleagues, customers, partners, and communities. Learn more at www.ivalua.com. Follow us on LinkedIn and Twitter. THE OPPORTUNITY CONTEXT: Our InfoSec team is dedicated to building, maintaining, and continuously improving Ivalua’s Information Security program globally. We provide peace of mind and assurance of protection and safety to our customers. In this fast-growing environment, the GRC program is critical to ensuring compliance with industry standards and certifications, managing risks, and supporting business growth. ROLE: We are currently looking for an experienced InfoSec Governance Risk and Compliance (GRC) Sr Manager to lead a global team and own the GRC program worldwide. Reporting to the InfoSec leadership, you will manage and develop a high-performing team, drive compliance efforts, and serve as a subject matter expert on security frameworks and standards. WHAT YOU WILL DO WITH US * Lead and own the Governance, Risk, and Compliance (GRC) program globally, managing and developing a high-performing team. * Manage and drive compliance efforts and audits for certifications such as FedRAMP, IRAP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, and others. * Serve as the subject matter expert (SME) on security frameworks and standards including NIST SP 800-53 Rev 5, NIST 800-171, ITAR, FedRAMP, PCI DSS, SOC2, etc., providing guidance to internal stakeholders. * Efficiently manage and respond to customer security audit and compliance requests in a timely manner. * Maintain continuous compliance and monitoring of security controls to ensure ongoing adherence to standards. * Collaborate closely with Sales, Marketing, and Customer Success teams to effectively communicate Ivalua’s security posture to prospects and customers. * Review and negotiate information security exhibits and contractual terms in partnership with the legal team. * Lead the Security Awareness and Training program to promote a culture of security across the organization. * Track, manage, and drive remediation efforts for control deficiencies and gaps identified through internal and external audits. * Oversee the Third Party Risk and Vendor Security Assessment program to mitigate supply chain risks. * Develop, maintain, and enforce InfoSec policies, standards, and plans. YOUR PROFILE If you have the below experience and strengths this role could be for you: Skills and Experience: * At least 7+ years of proven experience leading GRC programs and managing compliance certifications and audits (FedRAMP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, IRAP, etc.). * At least 3+ years experience as a direct leader, managing a team. The position will be part of an established global team with opportunity to grow the team * Strong knowledge of security frameworks such as NIST SP 800-53, NIST 800-171, ITAR, PCI DSS, SOC2, and FedRAMP. * Demonstrated ability to manage and influence stakeholders across multiple departments and time zones. * Excellent project management, analytical, and problem-solving skills with keen attention to detail. * Strong interpersonal and communication skills, capable of building trust and managing conflicts effectively. * Self-motivated with a high degree of initiative and ability to work independently. * Ability to handle multiple competing priorities and deadlines efficiently. * Bachelor’s degree in related field preferred or equivalent experience with proven skills Soft Skills: * Excellent interpersonal, communication, and organizational skills. * Team player with the ability to interface effectively with a broad range of individuals and roles, including IT and vendors. * High degree of initiative, dependable, and able to work well with limited supervision. WHAT HAPPENS NEXT If your application fits this specific position’s needs, our skilled Talent team will reach out to schedule an initial screening call. Get one step closer to achieving your goals – apply today! Our Talent team will guide you through every step of the interview process - from preparation to completion. They're here to support you! Our recruitment process is designed to assess your competencies through a series of personalized interviews with internal stakeholders relevant to the role. Interviews will be conducted virtually via video or on-site with face-to-face meetings. LIFE AT IVALUA * Hybrid working model (3 days in the office per week) * We're a team dedicated to pushing the boundaries of product innovation and technology * Sustainable Growth, Privately Held * A stable and cash-flow positive Company since 10 years * Snacks and weekly lunches in the office * Feel empowered to pursue your goals with improved team collaboration and increased creativity/productivity * Unlock and unleash your full professional potential with our exceptional training and career development program * Join a dynamic and international team of top-notch professionals who are experts in their respective fields. Collaborate with like-minded individuals who are deeply passionate and highly motivated about their work. Experience a truly diverse and inclusive work environment where your unique contributions are highly valued * Regular social events, competitive outings, team running events, and musical activities, * Comparably recognized Ivalua for the following (https://www.comparably.com/companies/ivalua) : Powered by People - Powered by You! United by our values we embrace diversity and equity in the broadest possible sense to create an inclusive workplace. To help our customers make supply chains more efficient, sustainable and resilient, we rely on a global team with a variety of backgrounds, skills and views. We believe in equal opportunity and in diversity as a driver of innovation that cultivates a spirit of inclusiveness, creates a productive and fun place to work, and provides fulfilling career opportunities for all Ivaluans. https://www.linkedin.com/company/ivalua/about/ Experience life at Ivalua - check out our captivating video! Gain insight into our unique company culture and get a glimpse of what it's like to work with us. Ivalua’s core values include a priority on Care & Grow People. We take matters like pay equity very seriously and strive to reward our employees appropriately and fairly for their talents. The compensation range for this position reflects the cost of labor across our US locations and is based upon careful and continual market research. In addition to location, compensation may also vary based upon job-related knowledge, skills, and experience. Title: Manager, InfoSec Governance Risk and Compliance (GRC) Range minimum: USD 112000 Range maximum: USD 208000 Additional compensation / rewards: Ivalua also offers exceptional benefits including medical, dental, vision and transportation. #LI-SG1 #LI-HYBRID #LI-DNI