bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesCareers Gbrx Icims ComSr. Security GRC Solutions Architect

Sr. Security GRC Solutions Architect

Careers Gbrx Icims Com · OR-Lake Oswego US-TX-Home Office, UNAVAILABLE, US; Home Office, TX, US · Remote · Active · iCIMS

Job facts

FieldValue
CompanyCareers Gbrx Icims Com
TitleSr. Security GRC Solutions Architect
Normalized title-
Department / teamInformation Technology
LocationOR-Lake Oswego US-TX-Home, UNAVAILABLE, United States
Work modelRemote / Remote
Employment typeFull Time
Salary-
Statusactive
ATS provideriCIMS
Posted / first seen2026-05-23 / 2026-05-31
Changed / last seen2026-06-06 / 2026-06-06

Related slices

PageWhat it containsOpen
Company jobsActive postings from Careers Gbrx Icims Com.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through iCIMS.Open
Provider filtered searchThe same provider as a filtered job collection.Open
City jobsActive postings in OR-Lake Oswego US-TX-Home.Open
Department jobsActive postings in Information Technology.Open
Work model jobsActive Remote postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyCareers Gbrx Icims Com
Source82274f7b-7eb0-4a6b-9faf-c3177b94130c
ATS provideriCIMS

Description

At Greenbrier, we do the hard work that matters. The Greenbrier Companies (NYSE:GBX) is powering the movement of products around the world as a leading designer, manufacturer and supplier of freight rail transportation equipment and services. Greenbrier’s heritage of hard work and industrial innovation is celebrated at every level of our organization. We structure our business to support teams that deliver innovative solutions for our customers while positively impacting the world around us. Greenbrier’s success begins with people. We believe in supporting our global workforce through our unwavering attention to Safety, Quality, Respect for People and Customer Satisfaction. Our Inclusion, Diversity, Engagement, Access and Leadership (IDEAL) commitment is rooted in these values, which lead to a culture where employees are engaged and feel good about coming to work every day. Summary The Sr. Security GRC Solutions Architect is rooted in IT SOX, SOC-1/2, NIST CSF 2.0, CIS and ISO compliance, the objective is automation. Microsoft E5 licensing is fully deployed, and Sentinel is enabled across the environment. Control evidence is tracked in spreadsheets. The Sr. Security GRC Solutions Architect will be the 1st line of defense who understands the audit requirements deeply but possesses the technical acumen to leverage Sentinel, KQL, Logic Apps, and AuditBoard to automate evidence collection and near real-time monitoring. They will work directly with the Sr. Manager - GRC and CISO to support the compliance program and IT organization during audits. Working with cross-functional, global teams and communicating with stakeholders at all levels across the company is a regular part of the position. Responsible for supporting IT control requirements and/or IT audit activities, including the development, implementation, and maintenance of processes, procedures, and operational structure. Requires strong attention to detail and the ability to work within established compliance and control frameworks. Duties and Responsibilities To perform this job successfully an individual must be able to perform the following essential duties satisfactorily. Other duties may be assigned to address business needs and changing business practices. Audit Preparations and Auditor Access: Bulk upload SOX/SOC audit requests to centralized tool during interim and roll-forward testing periods. Coordinate auditor access to Greenbrier systems, as needed. Audit Evidence Request Monitoring: Monitor audit evidence request tickets in centralized tool to ensure responses to auditors meet agreed upon milestones. Facilitate evidence request issues and coordinate meetings between IT stakeholders and relevant auditors. Compliance Liaison: Liaison between control owners and auditors/assessors for the evidence collection process and audit testing follow-ups. Assist Control Owners with evidence requests from auditors. Schedule meetings as needed. Control Automations: Facilitate and drive progress on control automation efforts, coordinating with subject matter experts, control owners, and automation teams. Control Changes: Ensure control description and design changes and relevant procedure documentation get updated into the GRC tool master control list in a timely manner. Control Failure Triage: Work with control owners/performers to perform root cause analyses on control issues and deficiencies, initiate risk-based remediation plans, and follow escalation procedures. May facilitate control remediation execution. Control Improvements: Support and implement control improvements, automation, and update relevant documentation, at the direction of management Control Monitoring: Using GRC Tool, monitor SOX/SOC controls for adequate completion by Control Owners and performers and secondary reviewers. Create dashboards for monitoring metrics by global region (U.S. vs. Europe) Control Remediations: Design and track all assigned remediation plans through to timely completion. Provide status updates of remediation plans to key stakeholders within the organization. Document as needed. Escalations: Proactively monitor audit follow-ups to identify potential control issues or failures, and missing or unavailable evidence, and follow internal escalation protocols immediately so GRC can triage. GRC Consultations: Provide audit, control, and evidence guidance to internal security and IT teams; Partner with internal and external stakeholders to assist the IT organization during audits. Automated Control Monitoring: Replace manual spreadsheet tracking by architecting and deploying Sentinel Analytics Rules and KQL queries that monitor controls (e.g., terminated user access, privileged account activity, and unauthorized changes). Evidence Orchestration (The "Vault" Strategy): Build and maintain Logic App Playbooks to automatically generate "Auditor-Ready" evidence packs upon control triggers, ensuring data is captured and preserved before log retention periods expire. AuditBoard & ServiceNow Integration: Optimize the integration between our GRC tool (AuditBoard) and our ITSM (ServiceNow) to automate task routing, remediation tracking, and evidence uploads. Root Cause Automation: Develop "SLA Breach" logic to detect process lags (e.g., HR termination vs. actual AD disablement) to provide GRC with immediate visibility into control failures before auditors find them. Continuous Compliance Liaison: Act as the technical bridge between IT Stakeholders and Auditors. Instead of manual follow-ups, you will build AuditBoard dashboards that provide stakeholders with real-time status of their compliance posture. Control Triage & Remediation: Work with control owners to perform root cause analysis on failures. If a control fails, you don't just document it; you help architect the technical fix or automation to prevent recurrence. Third-Party Risk (UpGuard): Leverage UpGuard to streamline the assessment of 3rd-party SOC reports and security postures, integrating these findings into our centralized risk register. Procedure Modernization: Update and maintain SOX/SOC Control Procedures to reflect automated workflows, ensuring that how we work matches how we are audited Qualifications The following generally describes requirements to successfully perform the assigned duties. Minimum Qualifications Bachelor’s degree in Information Systems or a related field required. 5+ years of IT audit experience at professional CPA firm, experienced at testing ITGCs for SOX Compliance and/or IT Controls for SOC-1 and SOC-2 compliance or other. OR 8+ years in an IT GRC function, performing and/or implementing ITGCs for SOX Compliance and/or IT Controls for SOC-1 and SOC-2 Compliance. Proficiency in Excel (performing data manipulations such as pivots and macros, familiar with special formulas) Deep experience with Microsoft Sentinel and writing KQL (Kusto Query Language). Automation: Proven ability to build Azure Logic Apps or Power Automate workflows. E5 Stack: Expert-level understanding of the Microsoft E5 Security suite (Entra ID, Purview, Defender for Cloud). Proficiency in Microsoft Word and Excel is a must. Strong understanding of IT control requirements for IT SOX ITGC and SOC-1 and SOC-2 compliance. Excellent technical writing; hands on experience with documenting for audit purposes and procedure writing. Auditor Interactions: Negotiation with auditors, issue management, productive and constructive communication with auditors. Communicative: Highly responsive and collaborative. Skilled at conflict resolution. Problem Solving: Think strategically and solve problems effectively, partner with specialists to design effective, reliable controls, as much as possible. Ability to ask the right questions and understand complex technical topics. Task Management: Ability to prioritize and track multiple projects in parallel. Manage the micro projects and push tasks forward assigned to you utilizing Greenbrier tasking tools available Proactively communicate task blockers and project issues Identify tasks needed, self-prioritize based on goals of the team, and proactively seek information to keep projects moving with ease Trust Building: Excellent cross-cultural relationship and trust building, superb communication, and strong organizational skills. Preferred Qualifications CISA, CISSP, CPA, or other relevant certifications are preferred. 1+ years experience performing 3rd Party SOC Report Reviews, or performing SOC examinations and SOC reporting Experience performing or facilitating risk management and/or vendor risk assessment processes Bilingual in English and Spanish Understanding of security frameworks such as NIST CSF, ISO 27001. Ability to work on-site at our Lake Oswego, Oregon office; remote work from other locations may be considered based on business needs. Work Environment and Physical Requirements Work Environment The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. In office environment, with some travel Physical Activities and Requirements Frequency Key Not Applicable: Activity is not applicable to this occupation Occasionally: Occupation requires this activity up to 33% of the time (0- 2.5+ hours/day) Frequently: Occupation requires this activity from 33% - 66% of the time (2.5- 5.5+ hours/day) Constantly: Occupation requires this activity more than 66% of the time (5.5+ hours/day) Working Postures Sit: Not Applicable Stand: Occasionally Walk: Occasionally Bend: Occasionally Kneel/Squat: Not Applicable Crawl: Not Applicable Climb: Not Applicable Reach Forward: Occasionally Reach Upward: Not Applicable Handling/Fingering: Constantly Lift / Carry Requirements 5-10 lbs: Occasionally 10-25 lbs: Not Applicable 25-50 lbs: Not Applicable 50-75 lbs: Not Applicable 75+ lbs: Not Applicable Push / Pull Requirements Up to 10 lbs: Occasionally 10-25 lbs: Not Applicable 25-50 lbs: Not Applicable 50-75 lbs: Not Applicable 75+ lbs: Not Applicable EOE including Vet/Disability Click here for more information: Know Your Rights Greenbrier makes reasonable accommodations in the application and hiring process for individuals with known disabilities, unless providing accommodation would result in an undue hardship. Any applicant believing that he or she may need reasonable accommodation for any part of the application and hiring process should contact Greenbrier Human Resources at [email protected] or call us at 503-684-7000. ----------------------------------------------------------------- Email communication from The Greenbrier Companies (Greenbrier) will always come from a corporate email address that ends in @gbrx.com or from our applicant tracking system, iCIMS, after you have created a secure account and submitted your application. During the application process, you will create a secure account in our secure applicant tracking site that ends with “-gbrx.icims.com”. In this portal, we will ask you to provide your contact information, past employment history, education history and other job-related information.

Full job record

Job ID2411006b2ee94e2a728e762d986233589336b994
Org ID049de514-e193-4a59-a60f-e0d41fd605da
Source ID82274f7b-7eb0-4a6b-9faf-c3177b94130c
Board ID82274f7b-7eb0-4a6b-9faf-c3177b94130c
Providericims
Provider Job Key4294
TitleSr. Security GRC Solutions Architect
Normalized Title
Statusactive
Activeyes
Location TextOR-Lake Oswego US-TX-Home Office, UNAVAILABLE, US; Home Office, TX, US
DepartmentInformation Technology
Team
Employment Typefull_time
Workplace Typeremote
Remote Policyremote
CountryUnited States
RegionUNAVAILABLE
CityOR-Lake Oswego US-TX-Home
Salary RawAt Greenbrier, we do the hard work that matters. The Greenbrier Companies (NYSE:GBX) is powering the movement of products around the world as a leading designer, manufacturer and supplier of freight rail transportation equipment and services. Greenbrier’s heritage of hard work and industrial innovation is celebrated at every level of our organization. We structure our business to support teams that deliver innovative solutions for our customers while positively impacting the world around us. Greenbrier’s success begins with people. We believe in supporting our global workforce through our unwavering attention to Safety, Quality, Respect for People and Customer Satisfaction. Our Inclusion, Diversity, Engagement, Access and Leadership (IDEAL) commitment is rooted in these values, which lead to a culture where employees are engaged and feel good about coming to work every day. Summary The Sr. Security GRC Solutions Architect is rooted in IT SOX, SOC-1/2, NIST CSF 2.0, CIS and ISO compliance, the objective is automation. Microsoft E5 licensing is fully deployed, and Sentinel is enabled across the environment. Control evidence is tracked in spreadsheets. The Sr. Security GRC Solutions Architect will be the 1st line of defense who understands the audit requirements deeply but possesses the technical acumen to leverage Sentinel, KQL, Logic Apps, and AuditBoard to automate evidence collection and near real-time monitoring. They will work directly with the Sr. Manager - GRC and CISO to support the compliance program and IT organization during audits. Working with cross-functional, global teams and communicating with stakeholders at all levels across the company is a regular part of the position. Responsible for supporting IT control requirements and/or IT audit activities, including the development, implementation, and maintenance of processes, procedures, and operational structure. Requires strong attention to detail and the ability to work within established compliance and control frameworks. Duties and Responsibilities To perform this job successfully an individual must be able to perform the following essential duties satisfactorily. Other duties may be assigned to address business needs and changing business practices. Audit Preparations and Auditor Access: Bulk upload SOX/SOC audit requests to centralized tool during interim and roll-forward testing periods. Coordinate auditor access to Greenbrier systems, as needed. Audit Evidence Request Monitoring: Monitor audit evidence request tickets in centralized tool to ensure responses to auditors meet agreed upon milestones. Facilitate evidence request issues and coordinate meetings between IT stakeholders and relevant auditors. Compliance Liaison: Liaison between control owners and auditors/assessors for the evidence collection process and audit testing follow-ups. Assist Control Owners with evidence requests from auditors. Schedule meetings as needed. Control Automations: Facilitate and drive progress on control automation efforts, coordinating with subject matter experts, control owners, and automation teams. Control Changes: Ensure control description and design changes and relevant procedure documentation get updated into the GRC tool master control list in a timely manner. Control Failure Triage: Work with control owners/performers to perform root cause analyses on control issues and deficiencies, initiate risk-based remediation plans, and follow escalation procedures. May facilitate control remediation execution. Control Improvements: Support and implement control improvements, automation, and update relevant documentation, at the direction of management Control Monitoring: Using GRC Tool, monitor SOX/SOC controls for adequate completion by Control Owners and performers and secondary reviewers. Create dashboards for monitoring metrics by global region (U.S. vs. Europe) Control Remediations: Design and track all assigned remediation plans through to timely completion. Provide status updates of remediation plans to key stakeholders within the organization. Document as needed. Escalations: Proactively monitor audit follow-ups to identify potential control issues or failures, and missing or unavailable evidence, and follow internal escalation protocols immediately so GRC can triage. GRC Consultations: Provide audit, control, and evidence guidance to internal security and IT teams; Partner with internal and external stakeholders to assist the IT organization during audits. Automated Control Monitoring: Replace manual spreadsheet tracking by architecting and deploying Sentinel Analytics Rules and KQL queries that monitor controls (e.g., terminated user access, privileged account activity, and unauthorized changes). Evidence Orchestration (The "Vault" Strategy): Build and maintain Logic App Playbooks to automatically generate "Auditor-Ready" evidence packs upon control triggers, ensuring data is captured and preserved before log retention periods expire. AuditBoard & ServiceNow Integration: Optimize the integration between our GRC tool (AuditBoard) and our ITSM (ServiceNow) to automate task routing, remediation tracking, and evidence uploads. Root Cause Automation: Develop "SLA Breach" logic to detect process lags (e.g., HR termination vs. actual AD disablement) to provide GRC with immediate visibility into control failures before auditors find them. Continuous Compliance Liaison: Act as the technical bridge between IT Stakeholders and Auditors. Instead of manual follow-ups, you will build AuditBoard dashboards that provide stakeholders with real-time status of their compliance posture. Control Triage & Remediation: Work with control owners to perform root cause analysis on failures. If a control fails, you don't just document it; you help architect the technical fix or automation to prevent recurrence. Third-Party Risk (UpGuard): Leverage UpGuard to streamline the assessment of 3rd-party SOC reports and security postures, integrating these findings into our centralized risk register. Procedure Modernization: Update and maintain SOX/SOC Control Procedures to reflect automated workflows, ensuring that how we work matches how we are audited Qualifications The following generally describes requirements to successfully perform the assigned duties. Minimum Qualifications Bachelor’s degree in Information Systems or a related field required. 5+ years of IT audit experience at professional CPA firm, experienced at testing ITGCs for SOX Compliance and/or IT Controls for SOC-1 and SOC-2 compliance or other. OR 8+ years in an IT GRC function, performing and/or implementing ITGCs for SOX Compliance and/or IT Controls for SOC-1 and SOC-2 Compliance. Proficiency in Excel (performing data manipulations such as pivots and macros, familiar with special formulas) Deep experience with Microsoft Sentinel and writing KQL (Kusto Query Language). Automation: Proven ability to build Azure Logic Apps or Power Automate workflows. E5 Stack: Expert-level understanding of the Microsoft E5 Security suite (Entra ID, Purview, Defender for Cloud). Proficiency in Microsoft Word and Excel is a must. Strong understanding of IT control requirements for IT SOX ITGC and SOC-1 and SOC-2 compliance. Excellent technical writing; hands on experience with documenting for audit purposes and procedure writing. Auditor Interactions: Negotiation with auditors, issue management, productive and constructive communication with auditors. Communicative: Highly responsive and collaborative. Skilled at conflict resolution. Problem Solving: Think strategically and solve problems effectively, partner with specialists to design effective, reliable controls, as much as possible. Ability to ask the right questions and understand complex technical topics. Task Management: Ability to prioritize and track multiple projects in parallel. Manage the micro projects and push tasks forward assigned to you utilizing Greenbrier tasking tools available Proactively communicate task blockers and project issues Identify tasks needed, self-prioritize based on goals of the team, and proactively seek information to keep projects moving with ease Trust Building: Excellent cross-cultural relationship and trust building, superb communication, and strong organizational skills. Preferred Qualifications CISA, CISSP, CPA, or other relevant certifications are preferred. 1+ years experience performing 3rd Party SOC Report Reviews, or performing SOC examinations and SOC reporting Experience performing or facilitating risk management and/or vendor risk assessment processes Bilingual in English and Spanish Understanding of security frameworks such as NIST CSF, ISO 27001. Ability to work on-site at our Lake Oswego, Oregon office; remote work from other locations may be considered based on business needs. Work Environment and Physical Requirements Work Environment The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. In office environment, with some travel Physical Activities and Requirements Frequency Key Not Applicable: Activity is not applicable to this occupation Occasionally: Occupation requires this activity up to 33% of the time (0- 2.5+ hours/day) Frequently: Occupation requires this activity from 33% - 66% of the time (2.5- 5.5+ hours/day) Constantly: Occupation requires this activity more than 66% of the time (5.5+ hours/day) Working Postures Sit: Not Applicable Stand: Occasionally Walk: Occasionally Bend: Occasionally Kneel/Squat: Not Applicable Crawl: Not Applicable Climb: Not Applicable Reach Forward: Occasionally Reach Upward: Not Applicable Handling/Fingering: Constantly Lift / Carry Requirements 5-10 lbs: Occasionally 10-25 lbs: Not Applicable 25-50 lbs: Not Applicable 50-75 lbs: Not Applicable 75+ lbs: Not Applicable Push / Pull Requirements Up to 10 lbs: Occasionally 10-25 lbs: Not Applicable 25-50 lbs: Not Applicable 50-75 lbs: Not Applicable 75+ lbs: Not Applicable EOE including Vet/Disability Click here for more information: Know Your Rights Greenbrier makes reasonable accommodations in the application and hiring process for individuals with known disabilities, unless providing accommodation would result in an undue hardship. Any applicant believing that he or she may need reasonable accommodation for any part of the application and hiring process should contact Greenbrier Human Resources at [email protected] or call us at 503-684-7000. ----------------------------------------------------------------- Email communication from The Greenbrier Companies (Greenbrier) will always come from a corporate email address that ends in @gbrx.com or from our applicant tracking system, iCIMS, after you have created a secure account and submitted your application. During the application process, you will create a secure account in our secure applicant tracking site that ends with “-gbrx.icims.com”. In this portal, we will ask you to provide your contact information, past employment history, education history and other job-related information.
Salary Min
Salary Max
Salary Currency
Salary Periodhour
Source URLhttps://careers-gbrx.icims.com/jobs/4294/sr.-security-grc-solutions-architect/job
Apply URLhttps://careers-gbrx.icims.com/jobs/4294/sr.-security-grc-solutions-architect/job
First Seen At2026-05-31 18:43:17Z
Last Seen At2026-06-06 08:27:36Z
Last Checked At2026-06-06 08:27:36Z
Last Changed At2026-06-06 08:27:36Z
Inactive At
Source Posted At2026-05-23 04:00:00Z
Source Updated At2026-06-05 08:47:33Z
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=icims/board=careers-gbrx.icims.com/date=2026-06-06/2026-06-06T08-27-35-351Z-a2ba3745e526d149cb6efe6a7d06881c3dc76b44bb3800d24799e5ad6a2eefe7.json
Event Fields
{
  "content_hash": "53aa2c86095e36b8aabc6aa06c4628bcf10db8a9e0efcf4935f43ef0ad11ab6f",
  "source_hash": "deba94db2b2d1a7baad6936991d30d70c15e1dbcf3fa62af77a4fd85c1076da6",
  "last_changed_at": "2026-06-06T08:27:36.811Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "OR-Lake Oswego\nUS-TX-Home Office, UNAVAILABLE, US",
    "city": "OR-Lake Oswego US-TX-Home",
    "region": "UNAVAILABLE",
    "country": "United States",
    "is_remote": false,
    "confidence": 0.8
  },
  "salary_max": null,
  "salary_min": null,
  "inferred_at": "2026-06-06T08:27:36.801Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "OR-Lake Oswego\nUS-TX-Home Office, UNAVAILABLE, US",
      "city": "OR-Lake Oswego US-TX-Home",
      "region": "UNAVAILABLE",
      "country": "United States",
      "is_remote": false,
      "confidence": 0.8
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": "remote",
  "salary_period": "hour",
  "workplace_type": "remote",
  "salary_currency": null
}
Extensions
{}
Native Structured
{
  "json_ld": {
    "url": "https://careers-gbrx.icims.com/jobs/4294/sr.-security-grc-solutions-architect/job",
    "@type": "JobPosting",
    "title": "Sr. Security GRC Solutions Architect",
    "@context": "http://schema.org",
    "datePosted": "2026-05-23T04:00:00.000Z",
    "description": "<h2></h2>\n<p><strong>At Greenbrier, we do the hard work that matters.</strong> The Greenbrier Companies (NYSE:GBX) is powering the movement of products around the world as a leading designer, manufacturer and supplier of freight rail transportation equipment and services.</p>\n<p> </p>\n<p><strong>Greenbrier’s heritage of hard work and industrial innovation is celebrated at every level of our organization. </strong>We structure our business to support teams that deliver innovative solutions for our customers while positively impacting the world around us.</p>\n<p> </p>\n<p><strong>Greenbrier’s success begins with people.</strong> We believe in supporting our global workforce through our unwavering attention to Safety, Quality, Respect for People and Customer Satisfaction. Our Inclusion, Diversity, Engagement, Access and Leadership (IDEAL) commitment is rooted in these values, which lead to a culture where employees are engaged and feel good about coming to work every day.</p>\n<h2></h2>\n<p><strong>Summary</strong></p>\n<p>The Sr. Security GRC Solutions Architect is rooted in IT SOX, SOC-1/2, NIST CSF 2.0, CIS and ISO compliance, the objective is automation. Microsoft E5 licensing is fully deployed, and Sentinel is enabled across the environment. Control evidence is tracked in spreadsheets.</p>\n<p> </p>\n<p>The Sr. Security GRC Solutions Architect will be the 1st line of defense who understands the audit requirements deeply but possesses the technical acumen to leverage Sentinel, KQL, Logic Apps, and AuditBoard to automate evidence collection and near real-time monitoring.</p>\n<p> </p>\n<p>They will work directly with the Sr. Manager - GRC and CISO to support the compliance program and IT organization during audits. Working with cross-functional, global teams and communicating with stakeholders at all levels across the company is a regular part of the position. Responsible for supporting IT control requirements and/or IT audit activities, including the development, implementation, and maintenance of processes, procedures, and operational structure. Requires strong attention to detail and the ability to work within established compliance and control frameworks.</p>\n<p> </p>\n<p><strong>Duties and Responsibilities</strong></p>\n<p><em>To perform this job successfully an individual must be able to perform the following essential duties satisfactorily. Other duties may be assigned to address business needs and changing business practices.</em></p>\n<ul>\n <li>Audit Preparations and Auditor Access: Bulk upload SOX/SOC audit requests to centralized tool during interim and roll-forward testing periods. Coordinate auditor access to Greenbrier systems, as needed.</li>\n <li>Audit Evidence Request Monitoring: Monitor audit evidence request tickets in centralized tool to ensure responses to auditors meet agreed upon milestones. Facilitate evidence request issues and coordinate meetings between IT stakeholders and relevant auditors.</li>\n <li>Compliance Liaison: Liaison between control owners and auditors/assessors for the evidence collection process and audit testing follow-ups. Assist Control Owners with evidence requests from auditors. Schedule meetings as needed.</li>\n <li>Control Automations: Facilitate and drive progress on control automation efforts, coordinating with subject matter experts, control owners, and automation teams.</li>\n <li>Control Changes: Ensure control description and design changes and relevant procedure documentation get updated into the GRC tool master control list in a timely manner.</li>\n <li>Control Failure Triage: Work with control owners/performers to perform root cause analyses on control issues and deficiencies, initiate risk-based remediation plans, and follow escalation procedures. May facilitate control remediation execution.</li>\n <li>Control Improvements: Support and implement control improvements, automation, and update relevant documentation, at the direction of management</li>\n <li>Control Monitoring: Using GRC Tool, monitor SOX/SOC controls for adequate completion by Control Owners and performers and secondary reviewers. Create dashboards for monitoring metrics by global region (U.S. vs. Europe)</li>\n <li>Control Remediations: Design and track all assigned remediation plans through to timely completion. Provide status updates of remediation plans to key stakeholders within the organization. Document as needed.</li>\n <li>Escalations: Proactively monitor audit follow-ups to identify potential control issues or failures, and missing or unavailable evidence, and follow internal escalation protocols immediately so GRC can triage.</li>\n <li>GRC Consultations: Provide audit, control, and evidence guidance to internal security and IT teams; Partner with internal and external stakeholders to assist the IT organization during audits.</li>\n <li>Automated Control Monitoring: Replace manual spreadsheet tracking by architecting and deploying Sentinel Analytics Rules and KQL queries that monitor controls (e.g., terminated user access, privileged account activity, and unauthorized changes).</li>\n <li>Evidence Orchestration (The \"Vault\" Strategy): Build and maintain Logic App Playbooks to automatically generate \"Auditor-Ready\" evidence packs upon control triggers, ensuring data is captured and preserved before log retention periods expire.</li>\n <li>AuditBoard & ServiceNow Integration: Optimize the integration between our GRC tool (AuditBoard) and our ITSM (ServiceNow) to automate task routing, remediation tracking, and evidence uploads.</li>\n <li>Root Cause Automation: Develop \"SLA Breach\" logic to detect process lags (e.g., HR termination vs. actual AD disablement) to provide GRC with immediate visibility into control failures before auditors find them.</li>\n <li>Continuous Compliance Liaison: Act as the technical bridge between IT Stakeholders and Auditors. Instead of manual follow-ups, you will build AuditBoard dashboards that provide stakeholders with real-time status of their compliance posture.</li>\n <li>Control Triage & Remediation: Work with control owners to perform root cause analysis on failures. If a control fails, you don't just document it; you help architect the technical fix or automation to prevent recurrence.</li>\n <li>Third-Party Risk (UpGuard): Leverage UpGuard to streamline the assessment of 3rd-party SOC reports and security postures, integrating these findings into our centralized risk register.</li>\n <li>Procedure Modernization: Update and maintain SOX/SOC Control Procedures to reflect automated workflows, ensuring that how we work matches how we are audited</li>\n</ul>\n<p><strong>Qualifications</strong></p>\n<p><em>The following generally describes requirements to successfully perform the assigned duties.</em></p>\n<p> </p>\n<p><strong>Minimum Qualifications</strong></p>\n<ul>\n <li>Bachelor’s degree in Information Systems or a related field required.</li>\n <li>5+ years of IT audit experience at professional CPA firm, experienced at testing ITGCs for SOX Compliance and/or IT Controls for SOC-1 and SOC-2 compliance or other. OR</li>\n <li>8+ years in an IT GRC function, performing and/or implementing ITGCs for SOX Compliance and/or IT Controls for SOC-1 and SOC-2 Compliance.</li>\n <li>Proficiency in Excel (performing data manipulations such as pivots and macros, familiar with special formulas)</li>\n <li>Deep experience with Microsoft Sentinel and writing KQL (Kusto Query Language).</li>\n <li>Automation: Proven ability to build Azure Logic Apps or Power Automate workflows.</li>\n <li>E5 Stack: Expert-level understanding of the Microsoft E5 Security suite (Entra ID, Purview, Defender for Cloud).</li>\n <li>Proficiency in Microsoft Word and Excel is a must.</li>\n <li>Strong understanding of IT control requirements for IT SOX ITGC and SOC-1 and SOC-2 compliance.</li>\n <li>Excellent technical writing; hands on experience with documenting for audit purposes and procedure writing.</li>\n <li>Auditor Interactions: Negotiation with auditors, issue management, productive and constructive communication with auditors.</li>\n <li>Communicative: Highly responsive and collaborative. Skilled at conflict resolution.</li>\n <li>Problem Solving: Think strategically and solve problems effectively, partner with specialists to design effective, reliable controls, as much as possible. Ability to ask the right questions and understand complex technical topics.</li>\n <li>Task Management: Ability to prioritize and track multiple projects in parallel.</li>\n <li>Manage the micro projects and push tasks forward assigned to you utilizing Greenbrier tasking tools available</li>\n <li>Proactively communicate task blockers and project issues</li>\n <li>Identify tasks needed, self-prioritize based on goals of the team, and proactively seek information to keep projects moving with ease</li>\n <li>Trust Building: Excellent cross-cultural relationship and trust building, superb communication, and strong organizational skills.</li>\n</ul>\n<p><strong>Preferred Qualifications</strong></p>\n<ul>\n <li>CISA, CISSP, CPA, or other relevant certifications are preferred.</li>\n <li>1+ years experience performing 3rd Party SOC Report Reviews, or performing SOC examinations and SOC reporting</li>\n <li>Experience performing or facilitating risk management and/or vendor risk assessment processes</li>\n <li>Bilingual in English and Spanish</li>\n <li>Understanding of security frameworks such as NIST CSF, ISO 27001.</li>\n <li>Ability to work on-site at our Lake Oswego, Oregon office; remote work from other locations may be considered based on business needs.</li>\n</ul>\n<p><strong>Work Environment and Physical Requirements</strong></p>\n<p><strong>Work Environment</strong></p>\n<p><em>The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.</em></p>\n<ul>\n <li>In office environment, with some travel</li>\n</ul>\n<p><strong>Physical Activities and Requirements </strong></p>\n<p><em>Frequency Key</em></p>\n<p>Not Applicable: Activity is not applicable to this occupation</p>\n<p>Occasionally: Occupation requires this activity up to 33% of the time (0- 2.5+ hours/day)</p>\n<p>Frequently: Occupation requires this activity from 33% - 66% of the time (2.5- 5.5+ hours/day)</p>\n<p>Constantly: Occupation requires this activity more than 66% of the time (5.5+ hours/day)</p>\n<p> </p>\n<p><strong>Working Postures</strong></p>\n<ul>\n <li>Sit: Not Applicable</li>\n <li>Stand: Occasionally</li>\n <li>Walk: Occasionally</li>\n <li>Bend: Occasionally</li>\n <li>Kneel/Squat: Not Applicable</li>\n <li>Crawl: Not Applicable</li>\n <li>Climb: Not Applicable</li>\n <li>Reach Forward: Occasionally</li>\n <li>Reach Upward: Not Applicable</li>\n <li>Handling/Fingering: Constantly</li>\n</ul>\n<p><strong>Lift / Carry Requirements</strong></p>\n<ul>\n <li>5-10 lbs: Occasionally</li>\n <li>10-25 lbs: Not Applicable</li>\n <li>25-50 lbs: Not Applicable</li>\n <li>50-75 lbs: Not Applicable</li>\n <li>75+ lbs: Not Applicable</li>\n</ul>\n<p><strong>Push / Pull Requirements</strong></p>\n<ul>\n <li>Up to 10 lbs: Occasionally</li>\n <li>10-25 lbs: Not Applicable</li>\n <li>25-50 lbs: Not Applicable</li>\n <li>50-75 lbs: Not Applicable</li>\n <li>75+ lbs: Not Applicable</li>\n</ul>\n<h2></h2>\n<p><strong>EOE including Vet/Disability</strong></p>\n<p> </p>\n<p>Click here for more information: Know Your Rights</p>\n<p> </p>\n<p>Greenbrier makes reasonable accommodations in the application and hiring process for individuals with known disabilities, unless providing accommodation would result in an undue hardship. Any applicant believing that he or she may need reasonable accommodation for any part of the application and hiring process should contact Greenbrier Human Resources at [email protected] or call us at 503-684-7000. ----------------------------------------------------------------- Email communication from The Greenbrier Companies (Greenbrier) will always come from a corporate email address that ends in @gbrx.com or from our applicant tracking system, iCIMS, after you have created a secure account and submitted your application. During the application process, you will create a secure account in our secure applicant tracking site that ends with “-gbrx.icims.com”. In this portal, we will ask you to provide your contact information, past employment history, education history and other job-related information.</p>",
    "directApply": true,
    "jobLocation": [
      {
        "@type": "Place",
        "address": {
          "@type": "PostalAddress",
          "postalCode": "97035",
          "addressRegion": "UNAVAILABLE",
          "streetAddress": "UNAVAILABLE",
          "addressCountry": "US",
          "addressLocality": "OR-Lake Oswego\nUS-TX-Home Office",
          "postOfficeBoxNumber": "UNAVAILABLE"
        }
      },
      {
        "@type": "Place",
        "address": {
          "@type": "PostalAddress",
          "postalCode": "UNAVAILABLE",
          "addressRegion": "TX",
          "streetAddress": "UNAVAILABLE",
          "addressCountry": "US",
          "addressLocality": "Home Office",
          "postOfficeBoxNumber": "UNAVAILABLE"
        }
      }
    ],
    "validThrough": "2027-05-23T04:00:00.000Z",
    "employmentType": "FULL_TIME",
    "jobLocationType": "TELECOMMUTE",
    "hiringOrganization": {
      "name": "The Greenbrier Companies",
      "@type": "Organization",
      "sameAs": "http://www.gbrx.com"
    },
    "occupationalCategory": "Information Technology"
  },
  "detail_meta": {
    "url": "https://careers-gbrx.icims.com/jobs/4294/sr.-security-grc-solutions-architect/job?in_iframe=1",
    "http_status": 200,
    "content_type": "text/html;charset=UTF-8",
    "response_bytes": 55707,
    "compact_response_bytes": 14118,
    "original_response_bytes": 55707
  },
  "sitemap_job": {
    "id": "4294",
    "url": "https://careers-gbrx.icims.com/jobs/4294/sr.-security-grc-solutions-architect/job",
    "slug": "sr.-security-grc-solutions-architect",
    "lastmod": "2026-06-05T04:47:33-04:00"
  },
  "detail_errors": []
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/2411006b2ee94e2a728e762d986233589336b994?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/049de514-e193-4a59-a60f-e0d41fd605daJSON
GET https://api.bluedoor.sh/job-postings/v1/sources/82274f7b-7eb0-4a6b-9faf-c3177b94130cJSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/2411006b2ee94e2a728e762d986233589336b994/eventsJSON