Manage audit engagements (e.g. SOX, ISO 27001, C5 PCI-DSS, SOC 2, HIPAA), the audit request lists and ensure requests are being fulfilled appropriately by stakeholder management;
Coordinate and collate required evidence for external and internal audit support;
Managing the control and process libraries, and assisting the business in implementing internal controls;
Contribute to meetings by preparing agendas, document meeting minutes, and help track the completion of follow up;
Lead junior staff to ensure critical tasks are completed on time and per requirements;
Lead Internal/External Audits as it relates to documenting or evidencing control management practices;
Lead/participate in Risk Assessments and documenting risks within the risk register, and identifying and documenting the risk treatment;
Assist the business to document, assess, and remediate any issues raised during audit examinations and risk assessments;
Assist in management of Sprinklr security standards and policies;
Update and maintain the GRC Confluence and share drives;
Assist with management of risks, controls and requests in the GRC tool; and other duties or tasks as assigned by management
As this is a global organization, the GRC Lead may occasionally be asked to attend conference call meetings outside of normal respective office hours.
Requirements
A Bachelor's degree in a technical/security field or a non-technical degree with combination of governance, risk and compliance-related work experience;
At least 5-7+ years of experience in risk, compliance management or in an Information Security environment;
Knowledge of security controls frameworks such as ISO 27001/27002 and NIST 800-53;
Generally adept at picking up new technologies and experience working with a GRC tool;
Excellent interpersonal communication, teamwork and project management skills;
Strong written and verbal communication skills;
Strong sense of accountability with the ability to work independently with minimal direction and follow-up;
Demonstrated ability to perform process analysis and experience in documenting controls;
Proven analytical and troubleshooting skills;
A broad understanding of information security risk and controls;
Personal integrity, accountability, and the ability to take ownership of specific tasks and activities; and
Able to foster a collaborative working relationship with multiple areas and complex business lines, globally and remotely.
Lead a new category of enterprise software that we call Unified-CXM.
Empower companies to deliver next generation, unified engagement journeys that reimagine the customer experience.
Create a culture of customer obsession, with trust, teamwork, and accountability.
Benefits
Vision insuranceRemote work options
Additional Information
Sprinklr is the definitive, AI-native platform for Unified Customer Experience Management (Unified-CXM), empowering brands to deliver extraordinary experiences at scale - across every customer touchpoint.
By combining human instinct with the speed and efficiency of AI, Sprinklr helps brands earn trust and loyalty through personalized, seamless, and efficient customer interactions. Sprinklr's unified platform provides powerful solutions for every customer-facing team - spanning social media management, marketing, advertising, customer feedback, and omnichannel contact center management - enabling enterprises to unify data, break down silos, and act on real-time insights.
Today, 1,900+ enterprises and 60% of the Fortune 100 rely on Sprinklr to help them deliver consistent, trusted customer experiences worldwide.
Job Description
The GRC Lead is a position within the Sprinklr Security Governance, Risk, and Compliance (GRC) team, reporting to the Director, GRC. The role will be responsible for assisting the GRC team in the planning and delivery of critical compliance reports and certificates, including SOC 2, ISO 27001, C5, SOX ITGCs, PCI-DSS and other relevant programs. They will also assist the team in documenting, assessing, and tracking the remediation of any issues and risks raised during audit examinations and risk assessments.