ActiveFence is now Alice
x

Cyber GRC Lead

About the Position

We are seeking a skilled and experienced Cyber GRC Lead to join Alice (Formerly ActiveFence) CISO team. The ideal candidate will be responsible for driving the security initiatives.

Key Responsibilities:

  • Third-Party Risk Management (TPRM) & Supply Chain Security:
  • Lead the end to end Operational TPRM lifecycle, assessing and continuously monitoring the security postures of vendors, SaaS platforms, AI tool providers.
  • Establish risk criteria for third party tools, ensuring third party AI integrations do not introduce data leakage, or intellectual property risks.
  • Security Awareness & Culture & Behavioral Programs:
  • Design and manage the enterprise wide security awareness and training program using modern platforms.
  • Conduct targeted phishing simulations, role based security training and specialized training among others on GenAI risks (prompt injection, shadow AI, data exposure).
  • Customer Due Diligence (DDQs) & Sales Enablement:
  • Manage and streamline the end to end customer security assessment process (DDQs, RFPs, Security Questionnaires, customer audits).
  • Build and maintain a centralized, automated knowledge base to expedite responses, directly removing friction from sales velocity and supporting enterprise revenue goals.
  • Risk Management Frameworks & Risk Advisory:
  • Lead ongoing security risk assessments, maintaining a dynamic Risk Register mapped to real world business impacts.
  • Provide continuous risk advisory services across business units, establishing risk treatment and mitigation plans that balance operational agility with guardrails.
  • GRC Automation & Continuous Compliance:
  • Architect and leverage high-level GRC automation tools to move from point in time audits to continuous control monitoring.
  • Drive process automation for evidence collection, vendor assessments, and policy management to reduce manual overhead across technical teams.
  • Compliance, Frameworks & AI Governance:
  • Maintain core information security certifications (ISO 27001, SOC 2 Type II, etc)
  • Build, operationalize, scale the organization's AI Governance Framework, referencing established benchmarks (NIST AI RMF, ISO/IEC 42001).
  • Lead internal and external audit readiness, acting as the primary liaison for independent auditors.
  • Close Collaboration with Legal, Privacy & DPO:
  • Partner directly with Legal and Privacy teams to operationalize global data protection standards (GDPR, CCPA, EU AI Act) align security controls with contractual commitments.

Requirements

Professional Experience:

  • 4+ years of hands on experience in Cyber GRC, IT audit, or security consulting within global, fast paced technology companies.
  • Proven track record of owning SOC 2 Type II and ISO 27001 compliance lifecycles.
  • Direct experience partnering with Legal and Privacy teams on GDPR compliance and privacy risk assessments.
  • Demonstrated track record handling customer DDQs, vendor security reviews (TPRM), and managing security awareness platforms.
  • Technical, Automation & AI Capabilities:
  • Strong technical proficiency in utilizing GRC automation platforms to automate control testing, evidence gathering, and vendor workflows.
  • Working knowledge of cloud security (AWS/GCP/Azure), AI/ML operational risks
  • Deep familiarity with core frameworks: NIST CSF, ISO 27001, NIST AI RMF, ISO 42001.
  • Leadership & Stakeholder Management:
  • Exceptional communication and negotiation skills, capable of translating complex security and compliance demands into clear business terms
  • A pragmatic, business first mindset focused on designing guardrails that empower teams rather than introducing operational roadblocks.
  • Fluent in professional English (written and verbal).

Preferred Qualifications (Pluses):

  • Industry certifications: CISA, CRISC, CISM, CISSP, CIPP/E, or IAPP AIGP.
  • Experience with automated TPRM and vendor intelligence solutions
  • Practical scripting capabilities to custom build or tie together GRC automation workflows.

About Alice

THE CHALLENGES ALONG THE WAY

1. Being Both Strategist and Executioner

One of the hardest parts of this role is that you’re both the visionary and the builder;  the one drawing the map and paving the road.
That means switching between high-level strategy and hands-on experimentation daily, and doing it while bringing others along with you. There’s no playbook for this kind of work. You’re paving an unpaved road, one small experiment at a time.

2. Balancing Security and Innovation

ActiveFence is the leading provider of security and safety solutions for online experiences, safeguarding more than 3 billion users, top foundation models, and the world’s largest enterprises and tech platforms every day. 
As a trusted ally to major technology firms and Fortune 500 brands that build user-generated and GenAI products, ActiveFence empowers security, AI, and policy teams with low-latency Real-Time Guardrails and a continuous Red Teaming program that pressure-tests systems with adversarial prompts and emerging threat techniques. Powered by deep threat intelligence, unmatched harmful-content detection, and coverage of 117+ languages, ActiveFence enables organizations to deliver engaging and trustworthy experiences at global scale while operating safely and responsibly across all threat landscapes.

Share