GRC Specialist
About this role
Miovision is hiring a GRC Specialist, full-time, remote, in the INFRASTRUCTURE sector.
About Miovision:
At Miovision, we’re unlocking transportation networks that move you. Our vision and mission is to enable smart, fast, safe communities that simply flow, as we drive the Intelligent Mobility Revolution. Backed by the world’s most advanced traffic AI, Miovision’s innovations in traffic signal planning and operations are making it possible for cities to improve the transportation experience for drivers, cyclists and pedestrians.
Our values drive us. They’re at the core of everything we do. If they align with yours, proceed through the GREEN light!
All in to win: We're driven by a winning mindset, approaching every challenge with intensity, clarity, and speed.
One Miovision: We succeed as one team, uniting diverse talents, building on trust, and putting our shared mission before ego.
Be better every day: We're committed to continuous growth, staying curious, building mastery, and embracing challenges as learning opportunities.
Make it happen: We are proactive and results-driven, taking ownership, acting with urgency, and focusing on solutions that deliver real impact.
Earn the customer: We are deeply customer-centric, focused on earning our customers' partnership every day by delivering exceptional experiences that drive their success.
Position Summary:
At Miovision, we are engineering the future of smart transportation, but keeping our massive data highways safe requires serious guardrails. We are looking for a GRC Specialist to act as our ultimate risk traffic controller. Sitting within the Office of Cybersecurity, you will operationalize our Unified Risk Management Framework, ensuring our products, cloud platforms, and enterprise systems navigate the complex intersections of global industry standards without ever hitting a compliance roadblock. If you are ready to steer our risk registers, keep our audit readiness cruising in the fast lane, and ensure security is a green light for business growth rather than a bottleneck, buckle up and merge into our team!
Objectives and Responsibilities:
Risk & Control Execution
Identify, assess, and track enterprise, cyber, product, and third-party risks, actively expanding our cybersecurity risk universe.
Maintain risk scoring, treatment plans, and evidence in strict alignment with frameworks like ISO 27001, SOC 2, and NIST.
Drive risk remediation and manage risk acceptance workflows, ensuring clear justifications and proper executive approvals.
Governance, Risk & Compliance (GRC) Program Operations
Drive day-to-day GRC operations across ISO 27001, SOC 2, and NIST, intelligently mapping controls to eliminate duplication and boost efficiency.
Collect and validate rock-solid evidence for internal assessments while managing the lifecycle of our security policies and standards.
Proactively research, recommend, and implement high-impact process improvements to streamline compliance efforts.
Audit & Assurance Support
Bridge the gap between theoretical certification requirements and operational reality by building robust audit playbooks and practical controls.
Serve as a key player during critical external audits, coordinating with internal control owners to ensure lightning-fast, highly accurate evidence submission.
Craft accurate, confident responses to customer security questionnaires, RFPs, and due-diligence requests to accelerate sales.
Cross-Functional Enablement
Partner with Engineering, Cloud Ops, IT, and Product to seamlessly embed risk considerations into development, operations, and vendor onboarding.
Act as a key risk gatekeeper for product releases and major delivery milestones, operationalizing highly scalable security controls.
Drive highly engaging security awareness training and clear risk communications across the entire business.
Risk Culture & Cross-Functional Engagement
Champion security best practices and act as an approachable advocate to non-technical, cross-departmental teams.
Spearhead engaging initiatives that build and reinforce a highly resilient, company-wide security culture.
Actively participate in cross-functional risk forums and working groups to keep security top-of-mind across the organization.
Emerging Leadership & Development
Take total ownership of key GRC components (like third-party risk or policy governance) to continuously hone your skills as an independent practitioner.
Drive process automation and program maturity, securely leveraging AI tooling to accelerate and optimize your workflows.
Partner directly with the GRC Manager to support executive reporting and execute high-level strategic initiatives.
The Ideal Profile:
The Compliance Veteran: Experience in GRC, cyber risk, compliance, or information security, ideally within SaaS, cloud, or critical-infrastructure environments.
The Framework Guru: You possess deep, practical working knowledge of at least three major frameworks (ISO 27001, SOC 2, NIST, FedRAMP, FAIR, or COSO).
The Persuasive Diplomat: You know exactly how to explain a control gap to an engineer who passionately disagrees—and successfully get it fixed without causing friction.
The Independent Executor: You are a proactive self-starter who has independently taught yourself new frameworks, tools, or systems just to solve a complex problem you uncovered.
The Auditor's Best Friend: You are highly proficient with modern GRC platforms and have a proven, hands-on ability to build and operate bulletproof risk registers and control frameworks.
The AI Adopter: You are highly effective at using AI to speed up your workflows and ensure accuracy, but you possess the sharp judgment to immediately spot when the machine is wrong.
The Public-Sector Navigator: You bring valuable exposure to the strict, high-stakes requirements of public-sector or highly regulated customers (federal, state, municipal, or transportation agencies).
Your Rewards & Well-being:
We invest in our team with benefits designed for modern life and true work-life balance.
Comprehensive Coverage: Your well-being is covered from day one with comprehensive health benefits, 24/7 virtual healthcare access, and dedicated wellness programs.
Financial Future: Build for tomorrow with our RRSP/401K Matching Plan and share in the company's success through our Variable Incentive Plan.
Time to Recharge: Truly unplug with our unique Mio-Days and flexible vacation policy.
Work & Life Support: We support you with flexible work options, an internet subsidy, a remote work allowance, and enhanced leave for new parents.
Sound like your next adventure? Apply now and let's start building together!
<Description from Miovision's official posting. Always confirm details on the company careers page.
About Miovision
Miovision
Company in the mobility sector tracked nightly on the Mobility Jobs board.
Not the one? Get new INFRASTRUCTURE roles by email, weekday mornings, only when something new lands.
About Larry Sherwood Jr.
Talent Acquisition Leader specializing in mobility, EV, and frontier tech. 1,000+ hires across roles ranging from production technicians to VPs, including 48 hires for the AFEELA U.S. launch at Sony Honda Mobility (98% offer acceptance, $1.5M+ agency savings). SHRM-CP certified. Build recruiting functions from scratch, no agencies.
Currently open to senior TA leadership roles in the United States. larrysherwoodjr.com · Resume (PDF)
Read Larry's guides →Curated by Larry Sherwood Jr. on the free Mobility Jobs board. Pulled nightly from company applicant tracking systems. Apply directly on the source link above to be considered.