
GRC Lead
Posted Sep 18

Posted Sep 18
This is a fully remote position, open to applicants in Serbia, +3 more countries.
β’ Take charge of information security risk management, control assurance, and ISO 27001 ISMS governance across a regulated group that includes banking, consumer finance, and technology sectors.
β’ Develop an independent perspective on security risk and evaluate whether proposed controls effectively address it, collaborating closely with the Group CISO.
β’ Evaluate the design and operational effectiveness of controls across IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure development.
β’ Transform risk and control data into clear, actionable reports for governance forums.
β’ Manage the security risk process comprehensively, encompassing assessment, treatment, acceptance, monitoring, and reporting.
β’ Oversee the risk register and critically assess risk evaluations and treatment strategies.
β’ Maintain the security control framework and validate controls using evidence, data, sampling, or technical assessment.
β’ Propel remediation efforts in collaboration with control owners.
β’ Sustain the ISO 27001 ISMS, which includes policies and standards, Statement of Applicability, risk records, control evidence, exceptions, and key security registers.
β’ Monitor control deficiencies, findings, exceptions, and remediation activities.
β’ Establish KRIs and control metrics and identify when management decisions or escalations are necessary.
β’ Substantial hands-on experience in information security risk management, covering inherent and residual risk, treatment, acceptance, control effectiveness, and risk appetite.
β’ Technical expertise to thoroughly evaluate controls across IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure development.
β’ Practical experience in reviewing or testing controls.
β’ Familiarity with ISO 27001.
β’ Capability to distill complex risk and control information into succinct management reports.
β’ Comfortable utilizing GRC platforms, structured risk and control registers, and evidence management systems.
β’ Availability to work core collaboration hours from 12:00 to 6:00 PM Manila time (UTC+8).
β’ Proficiency in English is required as part of the application process.
β’ Fully remote work arrangement with core collaboration hours from 12:00 to 6:00 PM Manila time (UTC+8).
β’ Provision of company tools and equipment.
β’ Medical insurance support for you and your family through co-funding or reimbursement, depending on your location and subject to policy limits.
β’ Access to an internal mental health support specialist.
β’ 22 vacation days.
β’ Philippine public holidays.
β’ 15 sick days.
β’ Opportunities for learning and sharing expertise through internal expert meetups, external conferences, speaking engagements, and industry publications.
β’ Company-sponsored trips to Manila for in-person team collaboration.
β’ High-performing teams can earn a dedicated beach house week in Southeast Asia.
LabConnect
Ripple Effect
Binance
biBerk Business Insurance
Get handpicked remote jobs straight to your inbox weekly.