The mission of the Governance, Risk, and Compliance (GRC) team is to provide assurance and consulting services designed to improve the security posture of Verisign and its business partners by:
Helping employees and business partners understand and comply with applicable policies, standards, and regulatory requirements;
Identifying, developing, and implementing solutions to avoid deviations from policies and standards; and
Promoting secure practices that protect Verisign.
The Senior Engineer – Information Security Governance, Risk, and Compliance is supporting an enterprise-wide information security governance, risk, and compliance program and will provide leadership for a variety of high-visibility initiatives.
Lead efforts to manage internal information-security controls that includes: documenting, providing recommendations for, analyzing, and assessing technical and management security control narratives and controls across the enterprise based on the latest AICPA Trust Services Criteria. Required to provide expert-level input and recommendations for process and control changes to meet external audit and operational requirements
Provide leadership in audit liaison activities for a variety of external assessments against various compliance frameworks. Provide expert-level advice and guidance to a variety of control owners
Report to senior management about the effectiveness of data security, and make recommendations for the adoption of new procedures, controls, and/or technologies
Manage less experienced team members to foster professional development and promote internal knowledge sharing
10+ years progressively responsible experience in information security audit, compliance, risk, and project management required
4+ years of experience leading teams in a matrixed environment highly preferred
Subject matter expertise in translating applicable security frameworks, industry best practices, and international laws and regulations into control requirements
Serve as a subject matter expert to internal security, privacy, and compliance stakeholders on specific topics/issues to enhance the establishment of the overall security control framework
An ability to quickly complete assigned tasks from senior management with little or no supervision
Manage multiple projects simultaneously across many areas related to information security
Thorough understanding and knowledge of SOC Audits and associated AICPA Trust Services Criteria and NIST SP 800-53 Controls (latest revision)
Experience with, and strong understanding of, most of the following security compliance frameworks, controls, and best practices: SOC Audits and AICPA Trust Principals, NIST SP 800-53 Controls (latest revision)
Professional security management certification in one or more of the following areas: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA)
Certified Cloud Security Professional (CCSP), Certified Authorization Professional (CAP), systems (Windows/Linux/Unix) security engineering, and/or network security engineering experience preferred
Internal Number: 5279
Verisign, a global leader in domain name registry services and internet infrastructure, enables internet navigation for many of the world’s most recognized domain names. Verisign enables the security, stability, and resiliency of key internet infrastructure and services, including providing root zone maintainer services, operating two of the 13 global internet root servers, and providing registration services and authoritative resolution for the .com and .net top-level domains, which support the majority of global e-commerce.
For more than 21 years, the Verisign DNS has maintained 100 percent operational accuracy and stability for .com and .net. Verisign manages and protects the DNS infrastructure for over 151.7 million .com and .net domain names and processes more than 152 billion queries daily.