SecOps GRC Analyst at Perion Network Ltd
Tel Aviv, Tel-Aviv District, Israel -
Full Time


Start Date

Immediate

Expiry Date

13 Jun, 26

Salary

0.0

Posted On

15 Mar, 26

Experience

2 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Third-Party Risk Management, GRC Platform, SOC 2, SOX ITGCs, Privacy Engineering, GDPR, CCPA, Risk Assessment, Vendor Onboarding, Control Library, Policy Lifecycle, Threat Landscape Monitoring, Supply Chain Risk, Auditor Liaison, Data Processing Agreements, Security Questionnaires

Industry

technology;Information and Internet

Description
Perion is a global advertising technology company delivering solutions to the biggest brands and publishers around the globe across search, social media and display, video, CTV, and programmatic DOOH. Home to an award-winning technology solution –– with our unique data-driven AI/ML based technologies, we deliver and optimize hundreds of terabytes of data and billions of events per day. We’re working with dozens of sources to provide a superior experience across screens and platforms, including mobile, video, social and native. Perion is seeking a SecOps GRC Analyst to own our third-party risk management program and drive compliance across key regulatory and audit frameworks. This role sits at the intersection of security operations, risk governance, and privacy engineering, and requires someone who can translate complex compliance requirements into practical, scalable controls in a fast-moving adtech environment. Key Responsibilities Own and mature the Third-Party / Supply Chain Risk Management (TPRM) program - including vendor onboarding assessments, ongoing monitoring, and contractual security requirements Lead SOC 1 and SOC 2 Type II audit readiness, evidence collection, and liaison with external auditors Support SOX IT General Controls (ITGCs) - including access management, change management, and financial system controls in coordination with Finance and Internal Audit Drive privacy engineering initiatives aligned with GDPR, CCPA, and other privacy frameworks Maintain and continuously improve the GRC platform, including the risk register, control library, policy lifecycle, and exception management Conduct security risk assessments for new products, vendors, and infrastructure changes Partner with Legal, Finance, R&D, and IT on compliance obligations, data processing agreements (DPAs), and security questionnaires Monitor the threat landscape for supply chain vulnerabilities (e.g., software dependencies, SaaS integrations) and escalate material risks Required Qualifications 4+ years in a GRC, security compliance, or risk management role Hands-on experience with SOC 2 and/or SOX ITGC audits including evidence preparation and auditor management Demonstrated ownership of a TPRM or vendor risk program Familiarity with privacy regulations (GDPR, CCPA) and their application to data-driven or adtech products Strong written communication skills - able to produce clear policies, risk reports, and audit artifacts Experience with GRC tooling (e.g., Panorays, Drata, OneTrust, or equivalent) Relevant certifications a plus: CISA, CRISC, CIPP, or SOC 2 Lead Auditor
Responsibilities
The analyst will own and mature the Third-Party/Supply Chain Risk Management program, leading SOC 1 and SOC 2 Type II audit readiness, and supporting SOX IT General Controls. This role also involves driving privacy engineering initiatives and maintaining the GRC platform.
Loading...