Experienced GRC Cybersecurity Professional – Third Party Risk Management & Compliance (Remote)

Posted 2026-05-05
Remote, USA Full-time Immediate Start
  • --

About arenaflex

Welcome to arenaflex, where innovation meets imagination! We are a dynamic organization at the forefront of technology and entertainment, committed to creating magical experiences while maintaining the highest standards of cybersecurity and governance. Our mission is to deliver exceptional value to our stakeholders while protecting our digital landscape from evolving cyber threats.

At arenaflex, we believe that great security is the foundation of great experiences. Our Cybersecurity team plays a critical role in safeguarding our organization's assets, reputation, and the trust of our millions of customers worldwide. We are seeking a talented and experienced GRC (Governance, Risk, and Compliance) Professional to join our Cybersecurity crew and help us maintain our robust security posture.

This is a remote position offering flexibility in both part-time and full-time arrangements, allowing you to contribute to our mission from the comfort of your own home. If you are passionate about cybersecurity, thrive in a collaborative environment, and want to make a meaningful impact, we invite you to join our team.

Position Overview

We are looking for an experienced GRC Professional specializing in Cyber Protection to guide governance, risk, and compliance activities and ensure seamless daily execution of various tasks within our Cybersecurity crew. In this role, you will be responsible for managing our Third Party/Internal Threat Control Software while overseeing internal safety compliance requirements and implementing regulations, tactics, and frameworks across the organization.

You will report to the Manager of Governance, Threat and Compliance within our Cyber and Data Safety department. This is a fantastic opportunity for a cybersecurity professional who wants to advance their career in a fast-paced, innovative environment while working with cutting-edge technologies and methodologies.

Key Responsibilities

Third Party Risk Management (TPRM)



  • Manage and administer the Third Party/Internal Risk Management Software platform

  • Support arenaflex's global third-party/internal risk methodology for conducting cyber risk-related due diligence assessments

  • Validate incoming third-party and internal risk assessment requests, working with business stakeholders to confirm request details and engagement scope

  • Conduct kick-off sessions with business stakeholders and relevant third parties for assessments

  • Coordinate the distribution of due diligence questionnaires to internal stakeholders and third parties

  • Review submitted questionnaires for completeness and identify risks arising from the design and operational effectiveness of internal/third parties' security controls

  • Document responses, associated findings, and remediation plans in arenaflex systems

  • Draft and review assessment reports, ensuring respective business stakeholders finalize reviews

  • Serve as a strong liaison to address queries concerning risk control techniques and evaluations for business or third parties as required

  • Perform continuous tracking of third parties via arenaflex systems for current and new findings and monitor findings to closure

  • Identify opportunities for improvement within arenaflex systems and strategies

  • Work closely with Risk Lead/Supervisor to schedule and execute a range of supporting activities related to the risk management program

Governance, Threat and Compliance



  • Lead and support the development of cybersecurity risk and compliance-related strategies to ensure treatment of cybersecurity risk consistent with the organization's risk appetite

  • Maintain and document compliance with information safety related guidelines and processes through planning, testing, remediating, tracking, and reporting on control reviews and risk assessments

  • Lead development and delivery of compliance and risk education and ongoing communications that help power a culture of protection and compliance

  • Stay abreast of regulatory changes, new guidelines, technology, and internal policy modifications to further identify new key risk areas

  • Lead activities to maintain and guide ISO 27001 certification

Essential Qualifications & Experience


  • Education: Relevant Bachelor's/Master's degree from an accredited university or equivalent experience

  • Experience: Minimum 4 years of experience in Third Party Risk Control, Information Security, and Audit & Compliance Tracking (with at least 2-3 years in TPRM/Internal Audit)

  • Preferred Background: Experience working with a large enterprise and/or major consulting firm is highly desirable

  • Certifications: One or more of the following certifications preferred: CISA, CRISC, ISO27001 Lead Auditor/Lead Implementer, CISSP

  • Technical Skills: Experience with AI/ML technologies is a plus

Required Skills & Competencies

Technical Knowledge



  • Working understanding of information security related best practices and requirements including ISO 2700x, SOC 2 Requirements, SSAE 16/18 Requirements, and others

  • Experience in the management of risk, controls, and compliance

  • Knowledge of risk assessment methodologies – both qualitative and quantitative

Professional Attributes



  • Outstanding stakeholder management skills

  • Strong analytical and problem-solving abilities

  • Excellent presentation making and delivery abilities

  • Robust interpersonal skills with the ability to build relationships across departments

  • Excellent communication skills, both verbal and written

  • Ability to navigate fast-paced environments and be flexible with working hours

  • Adapt quickly to changing conditions and drive quality change

What We Offer

At arenaflex, we value our employees and are committed to providing a comprehensive benefits package that supports your professional growth and personal well-being:


  • Competitive Compensation: Annual salary of $80,000 with performance-based bonuses

  • Flexible Work Arrangements: Remote work options with flexible scheduling

  • Health & Wellness: Comprehensive health insurance, dental, and vision coverage

  • Retirement Plans: 401(k) matching and retirement savings programs

  • Professional Development: Continuous learning opportunities, certifications support, and career advancement programs

  • Work-Life Balance: Generous paid time off, parental leave, and employee assistance programs

  • Innovative Culture: Work with cutting-edge technologies and be part of a team that values innovation and creativity

  • Global Exposure: Collaborate with teams across the globe and gain international experience

Career Growth Opportunities

Joining arenaflex means becoming part of a team that invests in your future. We offer numerous pathways for career advancement, including:



  • Leadership roles within the GRC function

  • Specialization in emerging cybersecurity domains such as AI/ML security

  • Cross-functional exposure to different areas of cybersecurity and risk management

  • Mentorship programs with industry experts

  • Internal mobility opportunities to explore different roles within the organization

Work Environment & Culture

Our Cybersecurity crew consists of talented cybersecurity specialists who formulate and implement techniques and recommendations to help the organization align with its commercial enterprise goals while managing threats correctly and meeting industry guidelines and standards. The team works on slicing edge technology and toward new innovations in the area of cybersecurity to deliver magic to our stakeholders.

At arenaflex, we foster an inclusive, collaborative, and innovative work environment where every team member's contributions are valued. We believe in maintaining a healthy work-life balance and encourage open communication across all levels of the organization.

How to Apply

If you are ready to take the next step in your career and contribute to arenaflex's mission of delivering exceptional experiences while maintaining robust cybersecurity, we want to hear from you!

To apply, please submit your resume and a compelling cover letter that highlights your relevant experience and passion for cybersecurity governance, risk, and compliance. Our hiring team will review applications and reach out to qualified candidates for further discussion.

arenaflex is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate based on race, color, religion, national origin, sex, age, disability, genetic information, or any other protected characteristic.

Join Our Team

Don't miss this exciting opportunity to grow your career with arenaflex! Apply now and become part of a team that's shaping the future of cybersecurity in the entertainment and technology industry. We can't wait to welcome you aboard!

Apply Today!

Similar Jobs

Back to Job Board