Our Client is seeking an experienced Cybersecurity Governance, Risk & Compliance (GRC) Manager to lead enterprise cybersecurity risk management, compliance initiatives, and governance programs. This individual will play a key role in strengthening the organization’s security posture by overseeing risk assessments, policy development, regulatory compliance efforts, vendor security reviews, security awareness programs, and cybersecurity reporting.
Key Responsibilities:
- Lead enterprise cybersecurity governance and risk management initiatives
- Conduct ongoing risk assessments to identify threats, vulnerabilities, and emerging cybersecurity concerns
- Develop, maintain, and execute risk treatment and mitigation plans aligned with business objectives
- Monitor organizational risk exposure and communicate risk findings to leadership and stakeholders
- Ensure alignment with industry standards, regulatory requirements, and internal controls
- Develop and maintain cybersecurity policies, standards, procedures, and governance frameworks
- Evaluate and update security documentation to align with evolving threats, business needs, and regulatory expectations
- Partner with business units to drive policy adoption, awareness, and compliance throughout the organization
- Design and manage enterprise-wide cybersecurity awareness programs
- Deliver training initiatives focused on security best practices, compliance obligations, and emerging cyber threats
- Measure program effectiveness and continuously improve awareness efforts based on risk trends and organizational needs
- Serve as a primary cybersecurity contact for internal and external audit activities
- Coordinate audit responses, remediation efforts, and compliance reporting
- Support payment card industry (PCI) compliance programs and ensure ongoing adherence to applicable requirements
Requirements
Preferred Certifications:
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CRISC (Certified in Risk and Information Systems Control)
- CDPSE (Certified Data Privacy Solutions Engineer)
- 5+ years of experience in cybersecurity governance, risk management, compliance, or information security leadership
- Experience conducting enterprise risk assessments and developing risk mitigation strategies
- Proven success creating and maintaining cybersecurity policies, standards, and governance frameworks
- Experience managing security awareness and training programs
- Strong understanding of audit processes and regulatory compliance requirements
- Experience supporting compliance efforts related to PCI-DSS, GDPR, CCPA, SOX, or similar frameworks
Desired:
- Strong knowledge of cybersecurity control frameworks including NIST CSF, NIST 800-series, ISO 27001, and PCI-DSS
- Expertise in cybersecurity risk identification, assessment, reporting, and remediation planning
- Experience managing third-party and vendor cybersecurity risk programs
- Familiarity with AI governance, emerging technology risks, and security implications of AI adoption
- Knowledge of privacy regulations and data protection standards
- Strong analytical, organizational, and problem-solving capabilities
- Excellent verbal and written communication skills with the ability to engage both technical and non-technical stakeholders
- Ability to build relationships and influence cross-functional teams across technology, legal, privacy, audit, and business functions
Preferred:
- Experience leading enterprise GRC programs, partnering with audit and compliance organizations, and operating within regulated environments will be highly successful in this role
- Experience developing cybersecurity metrics, vendor risk programs, and privacy-focused security initiatives is strongly preferred
-
Are you interested in this position?
Apply by clicking on the “Apply Now” button below!
#AlbionarcJobs#FintechJobs
#AsiaJobs#MiddleEastCareers
#TechTalent#FintechRecruitment
#FinanceOpportunities#
