Jobiglo

Aucun resultat.

GRC Lead

salmon-group

Nouveau Remote
Remote 🇬🇧 English
IAM endpoint security monitoring vulnerability management data protection secure development ISO 27001 GRC platforms

Description du poste

About the role

As a GRC Lead you will own information security risk management, control assurance, and ISO 27001 ISMS governance for a regulated banking and fintech group. You will work directly with the Group CISO to shape security risk strategy and ensure controls are effective across the organization.

Key responsibilities

  • Form an independent view of security risk, challenge proposed controls, and assess control design and operating effectiveness across IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure development.
  • Maintain the security risk process end‑to‑end, including assessment, treatment, acceptance, monitoring, and reporting, while keeping the risk register current.
  • Maintain the security control framework, test controls using evidence, data sampling or technical validation, and drive remediation with control owners.
  • Own the ISO 27001 ISMS, including policies, standards, Statement of Applicability, risk records, control evidence, exceptions, and key security registers.
  • Track control deficiencies, findings, exceptions, and remediation actions, defining KRIs and control metrics to flag needed escalations.
  • Turn risk and control data into clear, decision‑ready reporting for governance forums.

Required profile

  • Strong practical experience in information security risk management, including inherent and residual risk, treatment, acceptance, and control effectiveness.
  • Technical depth to critically assess controls across IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure development.
  • Hands‑on experience reviewing or testing controls and distinguishing documented controls from effective ones.
  • Working knowledge of ISO 27001 and ability to translate complex risk information into concise management reporting.
  • Comfort with GRC platforms, structured risk and control registers, and evidence management.

What we offer

  • Fully remote work with core collaboration hours from 12:00 PM to 6:00 PM Manila time (UTC+8).
  • Company‑provided tools and equipment.
  • Medical insurance support for you and your family through co‑funding or reimbursement.
  • 22 vacation days, Philippine public holidays, and 15 sick days.
  • Opportunities for learning, speaking at conferences, and publishing industry articles.
  • Company‑sponsored trips to Manila to meet the team in person.
  • Potential to earn a dedicated beach‑house week in Southeast Asia for high‑performing teams.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec salmon-group.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.
Source : ats:ashby

Pourquoi signalez-vous cette offre ?

Merci pour votre signalement. Nous allons examiner cette offre.

Aller plus loin

Salaires, guides et recherches en Serbie.

Postulez en 30 secondes

Entrez votre email pour postuler. Un compte sera cree automatiquement.

En continuant, vous acceptez nos conditions d'utilisation.

Deja un compte ? Connexion

💬 Contactez-nous sur Telegram Discuter sur WhatsApp

Publie il y a 7 heures

Expire dans 1 mois

2 vues · 0 interesses

Boostez vos chances

Importez votre CV : nous vous proposons les offres qui matchent votre profil.

Analyse de votre CV en cours...

salmon-group