|
This role supports governance, risk, regulatory compliance, and quality assurance activities for Infor's software products and enterprise operations. The Specialist, GRC & Quality Compliance is a senior individual contributor and program leader who owns Infor's risk register, drives internal and external audit readiness, supports regulatory compliance across a global framework landscape, and supports the Infor Quality Management System (QMS). The role sits at the intersection of the Quality, Regulatory & Audit (QRA) function and the emerging Risk Program, and serves as a key coordinator between Legal, Compliance, IT, ISO, and internal stakeholders (i.e. development, sales, SaaS, support).
A Typical Day in the Life Includes:
- Maintain and evolve Infor's policy and standards aligned to NIST CSF 2.0, CIS Controls, and SSDF; drive adoption across engineering, IT, and business units.
- Define ownership, accountability, and decision rights for risks across the business; serve as primary coordinator between Legal, Compliance, IT, and ISO on governance matters.
- Support the Infor Quality Management System (QMS): create, maintain, and continuously improve policies, procedures, and templates under strict document control.
- Participate in risk assessments and lead gap analyses for new or changed regulatory requirements; translate technical findings into clear, decision-ready business-impact communications for leadership.
- Identify AI and emerging-technology risk and governance reviews; align AI risk posture with NIST AI RMF, ISO/IEC 42001, and the EU AI Act.
- Support external certifications (SOC 1/2, ISO 27001/42001); maintain audit-ready evidence and documentation to reduce business disruption.
- Serve as the regulatory point of contact for contract negotiations, bids, and customer inquiries; ensure regulatory requirements are consistently embedded into contracts, supplier expectations, and subcontractor oversight.
- Partner with internal stakeholders to support customer trust programs - RFPs, security questionnaires, trust portals, and executive engagements in regulated sectors (healthcare, financial services, automotive).
Basic Qualifications:
- Proven experience supporting enterprise Risk Programs, ideally at a Tech or SaaS company.
- Demonstrated experience conducting and leading internal audits against ISO 27001, ISO 9001, and/or SSDLC standards.
- Working knowledge of major compliance frameworks: ISO 27001, SOC 2, NIS2, and emerging AI governance standards (EU AI Act, NIST AI RMF).
- Control-framework knowledge and documentation skills; ability to own and manage a policy and standards in a compliance management platform end to end
- Ability to manage a compliance risk register and drive findings through remediation.
- Familiarity with AI technologies and GRC platform automation tools (e.g., OneTrust, Navex IRM); ability to leverage AI tools to improve efficiency and quality outcomes.
- Track record leading cross-functional initiatives
Preferred Qualifications:
- Industry-specific regulatory compliance experience in EU MDR, HDS, CMMC or DORA.
- ISO 9001/27001 lead auditor certification or equivalent; project management certification (PMP or equivalent).
- Experience with risk quantification methodologies (FAIR or equivalent) and translating quantified risk into executive reporting.
- Knowledge of software validation methodologies, FDA regulations (21 CFR Part 11), or equivalent life sciences/healthcare IT standards.
- Experience with multi-cloud environments (Azure, AWS, GCP) and compliance automation within those ecosystems.
- Managing complex external audit programs at scale.
|