GRC Manager
We are seeking a highly skilled and detail-orientated Information Security GRC (Governance, Risk, and Compliance) Manager to manage our security framework, ensuring our organisation stays ahead of emerging threats while maintaining world-class compliance standards. In this role, you will be the bridge between technical security requirements and business objectives, fostering a culture of security through training, rigorous auditing, and strategic risk management.
The core responsibilities for the job include the following:
Governance and Policy Management:
- Security Policy Lifecycle: Lead the review and update of security policies to ensure alignment with emerging threats and risks. Work closely with technology and business stakeholders to ensure policies are practical and effective.
- Exception Management and Governance: Manage the end-to-end security policy exception process, ensuring risks are documented, signed off by stakeholders, and reviewed periodically.
Risk Management:
- Enterprise Risk Assessment: Perform comprehensive information security risk assessments, identifying emerging threats and vulnerabilities and tracking the closure of identified gaps.
- Third-Party Risk Management (TPRM): Undertake security risk assessments for third-party vendors and partners to ensure they meet our internal security standards.
- Risk Mitigation: Ensure that all identified security risks are managed and tracked appropriately, with robust controls in place to mitigate potential impact.
Compliance and Auditing:
- PCI-DSS Implementation: Oversee the implementation of PCI-DSS controls and coordinate with internal stakeholders and with the Qualified Security Assessor (QSA) for zero observations.
- ISO 27001:2022 Sustenance: Maintain the ISO 27001:2022 framework, driving continuous improvement and ensuring zero observations during surveillance and recertification audits.
- Internal and ITGC Audits: Perform internal security audits and coordinate IT General Controls (ITGC) audits, managing the remediation of any findings to ensure a strong control environment.
- AI Security Governance (ISO 42001) - Conduct AI security governance reviews and recommend controls aligned with ISO 42001 to ensure framework compliance.
Security Awareness and Training:
- Educational Programmes: Design and deliver security awareness training for new joiners and contractors and annual refresher courses for all staff.
- Phishing Simulations: Execute regular phishing simulation programmes. Analyse results and provide targeted training for employees who fail the simulations to improve the organisation's human firewall.
Reporting and MIS:
- Data-Driven Insights: Maintain and update accurate management information systems (MIS).
- Provide regular reports to leadership on risk posture, training completion rates, audit findings, and remediation timelines.
Requirements:
- Basic Qualification: Graduate in Technology Stream.
- Experience: A minimum of 6 years of direct experience in information security governance, risk, and compliance.
- Certifications: Must possess at least two (or more) of the following: CISA (Certified Information Systems Auditor), CISM (Certified Information Security Manager), CISSP (Certified Information Systems Security Professional), ISO 27001 Lead Auditor/Lead Implementer.
- Certified in Risk and Information Systems Control (CRISC).
- Technical Knowledge: Deep understanding of ITGC, PCI-DSS, ISO 27001:2022 AI Governance, Unified Controls Framework, and NIST standards.
- Soft Skills: Exceptional stakeholder management skills and the ability to translate complex security risks into business terms.