ActiveFence

Cyber GRC Lead

ActiveFence  •  Ramat Gan, IL (Remote)  •  2 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

We are seeking a skilled and experienced Cyber GRC Lead to join Alice (Formerly ActiveFence) CISO team. The ideal candidate will be responsible for driving the security initiatives.

Key Responsibilities:

  • Third-Party Risk Management (TPRM) & Supply Chain Security:
  • Lead the end to end Operational TPRM lifecycle, assessing and continuously monitoring the security postures of vendors, SaaS platforms, AI tool providers.
  • Establish risk criteria for third party tools, ensuring third party AI integrations do not introduce data leakage, or intellectual property risks.
  • Security Awareness & Culture & Behavioral Programs:
  • Design and manage the enterprise wide security awareness and training program using modern platforms.
  • Conduct targeted phishing simulations, role based security training and specialized training among others on GenAI risks (prompt injection, shadow AI, data exposure).
  • Customer Due Diligence (DDQs) & Sales Enablement:
  • Manage and streamline the end to end customer security assessment process (DDQs, RFPs, Security Questionnaires, customer audits).
  • Build and maintain a centralized, automated knowledge base to expedite responses, directly removing friction from sales velocity and supporting enterprise revenue goals.
  • Risk Management Frameworks & Risk Advisory:
  • Lead ongoing security risk assessments, maintaining a dynamic Risk Register mapped to real world business impacts.
  • Provide continuous risk advisory services across business units, establishing risk treatment and mitigation plans that balance operational agility with guardrails.
  • GRC Automation & Continuous Compliance:
  • Architect and leverage high-level GRC automation tools to move from point in time audits to continuous control monitoring.
  • Drive process automation for evidence collection, vendor assessments, and policy management to reduce manual overhead across technical teams.
  • Compliance, Frameworks & AI Governance:
  • Maintain core information security certifications (ISO 27001, SOC 2 Type II, etc)
  • Build, operationalize, scale the organization's AI Governance Framework, referencing established benchmarks (NIST AI RMF, ISO/IEC 42001).
  • Lead internal and external audit readiness, acting as the primary liaison for independent auditors.
  • Close Collaboration with Legal, Privacy & DPO:
  • Partner directly with Legal and Privacy teams to operationalize global data protection standards (GDPR, CCPA, EU AI Act) align security controls with contractual commitments.

Requirements

Professional Experience:

  • 4+ years of hands on experience in Cyber GRC, IT audit, or security consulting within global, fast paced technology companies.
  • Proven track record of owning SOC 2 Type II and ISO 27001 compliance lifecycles.
  • Direct experience partnering with Legal and Privacy teams on GDPR compliance and privacy risk assessments.
  • Demonstrated track record handling customer DDQs, vendor security reviews (TPRM), and managing security awareness platforms.
  • Technical, Automation & AI Capabilities:
  • Strong technical proficiency in utilizing GRC automation platforms to automate control testing, evidence gathering, and vendor workflows.
  • Working knowledge of cloud security (AWS/GCP/Azure), AI/ML operational risks
  • Deep familiarity with core frameworks: NIST CSF, ISO 27001, NIST AI RMF, ISO 42001.
  • Leadership & Stakeholder Management:
  • Exceptional communication and negotiation skills, capable of translating complex security and compliance demands into clear business terms
  • A pragmatic, business first mindset focused on designing guardrails that empower teams rather than introducing operational roadblocks.
  • Fluent in professional English (written and verbal).

Preferred Qualifications (Pluses):

  • Industry certifications: CISA, CRISC, CISM, CISSP, CIPP/E, or IAPP AIGP.
  • Experience with automated TPRM and vendor intelligence solutions
  • Practical scripting capabilities to custom build or tie together GRC automation workflows.

About Alice

Alice is a trust, safety, and security company built for the AI era. We safeguard the communicative technologies people use to create, collaborate, and interact—whether with each other or with machines.

In a world where AI has fundamentally changed the nature of risk, Alice provides end-to-end coverage across the entire AI lifecycle. We support frontier model labs, enterprises, and UGC platforms with a comprehensive suite of solutions: from model hardening evaluations and pre-deployment red-teaming to runtime guardrails and ongoing drift detection.

ActiveFence

About ActiveFence

ActiveFence is the leading provider of AI security and safety solutions, protecting online experiences and AI applications for over 3 billion users, top foundation models, and the world’s largest enterprises and tech platforms.

As a trusted partner to major technology companies and Fortune 500 brands, we secure user-generated and GenAI products against prompt injection, adversarial attacks, and harmful content through Real-Time Guardrails, continuous Red Teaming, and the industry’s most advanced threat intelligence.

With unmatched detection capabilities in 117+ languages, ActiveFence empowers organizations to deliver engaging, safe, and trustworthy experiences globally, helping them innovate responsibly while staying ahead of emerging threats.

Industry
IT & Software
Company Size
201-500 employees
Headquarters
New York
Year Founded
2018
Social Media