RennerBrown · 22 hours ago
GRC and Application Security Manager
RennerBrown is seeking a forward-thinking Manager, GRC, Security Awareness & Application Security to join their Global Information Security team. This role leads an integrated program that embeds governance, risk management, security awareness, and application security into daily business and development practices.
Responsibilities
Lead the North America GRC program aligned to global frameworks and enterprise risk appetite
Develop and operationalize security policies, standards, and GRC workflows
Design and deliver data-driven, behavior-based security awareness programs
Partner with engineering teams to embed secure-by-design and DevSecOps practices into SDLC and CI/CD pipelines
Oversee third-party and vendor security risk management
Advance application security through SAST, DAST, and SCA implementation
Build dashboards and KRIs to communicate risk, awareness effectiveness, and AppSec maturity to leadership
Support audits and compliance efforts across GxP, HIPAA, and data protection frameworks
Qualification
Required
7+ years of cybersecurity experience across GRC, security awareness, and application security
Strong knowledge of NIST CSF, ISO 27001, secure SDLC, and DevSecOps
Experience in regulated environments (pharma, biotech, healthcare, or manufacturing)
Hands-on experience with AppSec tooling (SAST, DAST, SCA) and vendor risk management
Bachelor's degree required
Preferred
Relevant certifications (CISSP, CRISC, CISM, CSSLP)
Familiarity with cloud and identity security (AWS/Azure/GCP, IAM, Zero Trust)