SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Alice (formerly ActiveFence) is seeking an experienced Cyber GRC Lead to join the CISO team and drive comprehensive security and governance initiatives across the organization.
The role encompasses multiple critical areas: Third-Party Risk Management & Supply Chain Security, where you'll lead the end-to-end operational TPRM lifecycle, assess and continuously monitor vendor and SaaS platform security postures, and establish risk criteria for third-party tools—particularly AI integrations—to prevent data leakage and IP risks.
You'll design and manage enterprise-wide security awareness and training programs using modern platforms, conducting targeted phishing simulations, role-based training, and specialized GenAI risk training covering prompt injection, shadow AI, and data exposure.
The role includes managing customer due diligence processes (DDQs, RFPs, security questionnaires, audits) and building automated knowledge bases to streamline sales enablement and revenue goals. You'll lead ongoing security risk assessments, maintain a dynamic Risk Register mapped to business impacts, and provide continuous risk advisory services across business units.
You'll architect GRC automation tools to transition from point-in-time audits to continuous control monitoring, drive process automation for evidence collection and vendor assessments, and maintain core information security certifications (ISO 27001, SOC 2 Type II). A key responsibility is building and operationalizing the organization's AI Governance Framework referencing NIST AI RMF and ISO/IEC 42001 standards.
You'll collaborate closely with Legal and Privacy teams to operationalize global data protection standards (GDPR, CCPA, EU AI Act) and align security controls with contractual commitments. You'll serve as the primary liaison for independent auditors and internal/external audit readiness.
Required: 4+ years hands-on experience in Cyber GRC, IT audit, or security consulting at global, fast-paced technology companies. Proven track record owning SOC 2 Type II and ISO 27001 compliance lifecycles. Direct experience with customer DDQs, vendor security reviews, and security awareness platforms. Strong technical proficiency in GRC automation platforms, working knowledge of cloud security (AWS/GCP/Azure), and deep familiarity with NIST CSF, ISO 27001, NIST AI RMF, and ISO 42001. Exceptional communication and negotiation skills with a pragmatic, business-first mindset. Fluent in professional English.
Preferred: Industry certifications (CISA, CRISC, CISM, CISSP, CIPP/E, IAPP AIGP), experience with automated TPRM solutions, and practical scripting capabilities.