Overview
In this role, you will lead and continually enhance Cirrus Logic’s ISO 27001-aligned ISMS and GRC program, focusing on integrated and third-party risk, AI governance, and security controls. You’ll partner across Legal, IT, and engineering to embed security into AI solutions and business initiatives. Expect collaboration with a global team to drive risk-informed decisions and enable secure, compliant product and services. This is a hands‑on, governance‑driven role with significant impact on enterprise security posture and AI risk management.
Responsibilities
- Lead day-to-day operation and continuous improvement of ISO 27001–aligned ISMS, including policies, standards, and control procedures
- Develop, maintain, and socialize information security policies, standards, and guidelines; manage risk-based exceptions
- Lead Integrated Risk Management for new systems and initiatives, including AI/ML use case risk assessments
- Plan and execute Third-Party Risk Management activities, including security questionnaires and remediation
- Analyze risk across technologies and processes; produce risk and control status reports for leadership
- Configure and optimize GRC tooling (ServiceNow GRC or OneTrust GRC) for risk, control, assessments, exceptions, and third-party workflows
- Coordinate internal and external audits, and support customer security assessments and certifications
- Partner with Legal and HR to manage privacy and regulatory obligations; assess AI privacy implications
- Define AI risk governance guardrails, acceptable-use guidelines, and review processes for AI use cases and vendors
- Act as trusted advisor to IT and business teams to embed security and governance into AI solution design and operations
- Communicate risk, control, and program status clearly to technical and non-technical stakeholders; contribute to awareness and training
Key requirements
- Proven experience in Information Security with a strong focus on GRC, risk management, and/or security compliance in a global environment
- Bachelor’s degree in cybersecurity, information systems, or related field, or demonstrated equivalent experience
- Hands-on experience with ISO/IEC 27001 and related frameworks (NIST CSF, ISO 27000, TISAX)
- Experience with Integrated Risk Management and Third-Party Risk Management
- Technical fluency across core IT and security domains; able to collaborate with Security Engineering and IT teams
- Experience configuring enterprise GRC platforms (preferably ServiceNow GRC; OneTrust a plus)
- Strong analytical and problem-solving skills; ability to balance security, compliance, and business needs
- Excellent written and verbal communication; able to present to technical teams and executives
- Proven ability to work independently and manage multiple initiatives in a fast-paced environment
- Experience in high-tech/engineering or semiconductor environments is beneficial
- Relevant certifications (ISO 27001 Lead/Implementer, CISSP, CISM, CISA, CRISC) preferred but not required
- Strong communication and executive-level presentation skills
- Collaborative and advisory mindset
- Ability to translate complex risk into practical solutions
- ISO/IEC 27001 ISMS lifecycle
- NIST CSF
- GRC platforms (ServiceNow GRC, OneTrust)
…
