
How your CV stacks up
Upload your CV to see how well it fits this job role
?%
ABOUT AVID
Avid makes technology and collaborative tools so creators can entertain, inform, educate and enlighten the world. Our customers are the visionaries behind the most inspiring feature films, television programs, news broadcasts, televised sporting events, music recording and live concerts.
To learn how Avid powers greater creators or for more information, visit www.avid.com.
JOB SUMMARY
Come and join our team as a GRC Specialist — driving compliance, risk management, and security assurance.
The subject matter expert on various compliance and risk management topics; GRC Specialist supporting Avid's security team with customer and partner security questionnaire responses, primary ownership of third-party risk management (TPRM), NIST/SSDF self-assessment and evidence collection, and audits.
This role is based in the Philippines and follows a remote work setup with a scheduled shift from 6:00 PM to 3:00 AM (Manila Time).
WHAT YOU WILL DO
- Respond to and maintain customer and partner security questionnaires.
- Own Avid's third-party risk management (TPRM) program: vendor and third-party risk intake, assessment, and risk determination in partnership with security leadership.
- Perform Vendor Security Assessments for new and existing third-party relationships.
- Maintain the Risk Register: log new risk acceptances, track renewal dates, and keep the register current.
- Run self-assessment worksheets against NIST 800-53 and NIST CSF control families.
- Map security pipeline evidence to NIST SSDF and OWASP control practices.
- Complete periodic data security reviews and help track remediation of findings.
- Maintain and review Security Policy documentation and other compliance records and documentation.
- Own coordination of Avid's current security audit efforts (auditor liaison, evidence collection, remediation tracking) and any future third-party compliance audits.
- Support Legal with technical security input for contract and data protection reviews.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
WHO YOU ARE
- 2-3+ years of experience in security compliance, audit support, or GRC-adjacent work.
- Familiarity with NIST 800-53, NIST CSF, or SSDF (exposure through coursework, certification study, or prior role experience).
- Exposure to SOC 2 or similar third-party audit processes preferred; hands-on audit coordination experience not required.
- Comfortable working with AI agents, spreadsheets, and collaboration tools for tracking and documentation.
- Strong English written/verbal communication skills, able to draft accurate questionnaire responses with minimal editing.
- Able to manage multiple parallel workstreams and coordinate with both technical and non-technical stakeholders.
- Preferred certifications: ISC2 Certified in Cybersecurity (CC), CompTIA Security+, ISO/IEC 27001 Foundation, GIAC GSEC, CCSK, or AWS Cloud Practitioner.
- Certifications such as CISSP, CISM, CISA, CRISC, CGEIT, CGRC, GRCP, or ISO 27001 Lead Auditor/Implementer are a plus.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
What to look forward to?
- Join a global team and experience a dynamic, collaborative work environment that fosters innovation and growth.
- Remote work model offering flexibility to balance work and life.
- Access to development programs with strong support and mentoring to help you grow and advance within the company.
- Equal opportunity employer committed to diversity, inclusivity, and creating a welcoming environment for all employees.
- Attractive benefits package including health & life insurance, referral rewards, and generous leave policies to ensure a healthy work-life balance.
Avid is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
#LI-Remote, LI-NR1
If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location