GRC Lead

Posted Sep 18

This is a fully remote position, open to applicants in Serbia, +3 more countries.

πŸ“‹ Description

β€’ Take charge of information security risk management, control assurance, and ISO 27001 ISMS governance across a regulated group that includes banking, consumer finance, and technology sectors.

β€’ Develop an independent perspective on security risk and evaluate whether proposed controls effectively address it, collaborating closely with the Group CISO.

β€’ Evaluate the design and operational effectiveness of controls across IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure development.

β€’ Transform risk and control data into clear, actionable reports for governance forums.

β€’ Manage the security risk process comprehensively, encompassing assessment, treatment, acceptance, monitoring, and reporting.

β€’ Oversee the risk register and critically assess risk evaluations and treatment strategies.

β€’ Maintain the security control framework and validate controls using evidence, data, sampling, or technical assessment.

β€’ Propel remediation efforts in collaboration with control owners.

β€’ Sustain the ISO 27001 ISMS, which includes policies and standards, Statement of Applicability, risk records, control evidence, exceptions, and key security registers.

β€’ Monitor control deficiencies, findings, exceptions, and remediation activities.

β€’ Establish KRIs and control metrics and identify when management decisions or escalations are necessary.


⛳️ Requirements

β€’ Substantial hands-on experience in information security risk management, covering inherent and residual risk, treatment, acceptance, control effectiveness, and risk appetite.

β€’ Technical expertise to thoroughly evaluate controls across IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure development.

β€’ Practical experience in reviewing or testing controls.

β€’ Familiarity with ISO 27001.

β€’ Capability to distill complex risk and control information into succinct management reports.

β€’ Comfortable utilizing GRC platforms, structured risk and control registers, and evidence management systems.

β€’ Availability to work core collaboration hours from 12:00 to 6:00 PM Manila time (UTC+8).

β€’ Proficiency in English is required as part of the application process.


🏝️ Benefits

β€’ Fully remote work arrangement with core collaboration hours from 12:00 to 6:00 PM Manila time (UTC+8).

β€’ Provision of company tools and equipment.

β€’ Medical insurance support for you and your family through co-funding or reimbursement, depending on your location and subject to policy limits.

β€’ Access to an internal mental health support specialist.

β€’ 22 vacation days.

β€’ Philippine public holidays.

β€’ 15 sick days.

β€’ Opportunities for learning and sharing expertise through internal expert meetups, external conferences, speaking engagements, and industry publications.

β€’ Company-sponsored trips to Manila for in-person team collaboration.

β€’ High-performing teams can earn a dedicated beach house week in Southeast Asia.

People also viewed

LabConnect22 hours ago

Head of IT Governance, Risk, Compliance

US flagTennessee OnlyFull-timeCompliance
ApplyView job
Ripple Effect1 day ago

Compliance Analyst

US flagMaryland OnlyFull-timeCompliance$85.3k – $98.1k/year
ApplyView job
Binance1 day ago

Team Lead – Compliance Monitoring, Assurance & Testing

AE flagUnited Arab Emirates (UAE) OnlyFull-timeCompliance
ApplyView job
biBerk Business Insurance1 day ago

Claims Compliance Analyst – Workers' Compensation

US flagUnited States OnlyFull-timeCompliance$77k – $96.5k/year
ApplyView job
Doppel1 day ago

Director, Governance, Risk & Compliance

US flagUnited States OnlyFull-timeCompliance
ApplyView job
PingWind Inc. (SDVOSB)1 day ago

Risk and Compliance Analyst

US flagUnited States OnlyFull-timeCompliance
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers