Information Security Governance, Risk & Compliance Manager
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked 2d ago — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 5d ago
The date the source published, not the day we noticed it (2026-09-10). Last seen at its source just now.
Is it remote?
The listing says yes
The location field doesn't say remote, so our assessment is based on the title or the description. Read the listing before applying.
Who may apply?
Europe
The description states no restriction of its own. This is the source's own tag.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
greenhouse employer's own board first seen 5d ago · last seen just now
The listing
We are looking for an experienced Information Security GRC Manager to lead and develop our Information Security Governance, Risk & Compliance function.
This is a hands-on leadership role with the opportunity to shape the GRC operating model, roadmap, team, and core processes in a growing international FinTech environment.
You will work directly with the CISO and collaborate closely with Security, Legal, Risk, Procurement, IT, Engineering, Product, Platform, HR, and business teams.
The role combines security governance, cyber risk, regulatory assurance, third-party risk, policy management, and security awareness, with a strong focus on building practical controls and processes that support business growth.
Requirements
- Strong practical experience in Information Security GRC, cyber/technology risk, security compliance, or assurance
- Hands-on experience with recognized frameworks such as SOC 2, ISO 27001, DORA, PCI DSS, NIST CSF, COBIT, or similar
- Experience establishing or operating security controls, risk registers, exception processes, and assurance programs
- Strong understanding of control design, operating effectiveness, evidence quality, findings, and remediation
- Experience coordinating internal or external audits and regulatory or assurance activities
- Practical experience with cyber risk assessment, risk treatment, risk acceptance, and escalation
- Understanding of third-party and ICT supplier security risk
- Ability to translate regulatory and security requirements into practical controls and processes
- Strong stakeholder management skills and ability to work effectively with technical, business, and executive audiences
- Sufficient technical understanding of cloud, infrastructure, identity, IT operations, and product development to work effectively with technical teams
- Experience leading a team, function, program, or complex cross-functional initiatives
- Strong ownership, prioritization, and decision-making skills
Responsibilities
- Own and develop the Information Security GRC strategy, roadmap, operating model, and governance cadence
- Lead security governance, regulatory assurance, cyber risk, third-party security risk, policy lifecycle, and security-awareness oversight
- Establish clear ownership for security controls, risks, exceptions, evidence, and remediation actions
- Coordinate SOC 2, DORA/CySEC-related assurance, internal and external audits, and regulatory requests
- Maintain cyber-risk and exception registers and ensure material risks are treated, accepted, or escalated
- Lead security aspects of ICT supplier tiering, due diligence, reassessment, and high-risk supplier decisions
- Develop practical security policies, standards, controls, and guidance
- Ensure audit and assurance evidence is reliable, traceable, and reusable
- Track control gaps, findings, and remediation commitments and escalate material risks
- Partner with Security, IT, Engineering, Product, Platform, Legal, and business teams on control design and risk-based decisions
- Prepare concise GRC and risk reporting for the CISO and executive stakeholders
- Build, develop, and manage the GRC team, including responsibilities, goals, and performance expectations
- Improve GRC efficiency through automation, reusable evidence, better data quality, and responsible AI-assisted workflows
We Offer
- 20 paid vacation days per year
- 10 paid sick leave days per year
- Public holidays according to company policy
- Medical budget
- Remote work opportunity
- Professional education budget
- Language learning budget
- Wellness budget (gym membership, sports gear, etc.)
Role mission
Build and lead a pragmatic, risk-driven Information Security GRC capability that turns regulatory, audit, policy, cyber and third-party risk obligations into owned controls, credible evidence and timely business decisions, without creating unnecessary bureaucracy.
Requirements hard skills
Strong practical knowledge of information security governance, cyber or technology risk management, security compliance and control frameworks.
Experience establishing or operating security controls, risk registers, exception processes, policy frameworks or assurance programs.
Hands-on experience with at least one recognized framework or regulatory regime, such as SOC 2, ISO 27001, DORA, PCI DSS, NIST CSF, COBIT or an equivalent framework.
Ability to map obligations across multiple frameworks without creating duplicate control structures.
Experience coordinating internal or external audits, regulatory reviews, customer assurance or control assessments.
Understanding of control design and operating effectiveness, evidence quality, remediation tracking and issue closure.
Experience with cyber-risk assessments, risk treatment, risk acceptance and executive escalation.
Understanding of third-party and ICT supplier risk, including tiering, due diligence, reassessment and remediation.
Experience developing practical policies, standards and guidance for technology and business teams.
Ability to create decision-ready management reporting, risk summaries, control dashboards and remediation reporting.
Sufficient technical understanding of cloud services, IT operations, identity, infrastructure, product development and security operations to challenge control owners constructively.
Experience leading a team, program, function or complex cross-functional delivery.
Requirements soft skills
Pragmatic and business-oriented approach to security, risk and compliance.
Ability to influence senior stakeholders and control owners without relying only on formal authority.
Strong ownership, follow-through and escalation discipline.
Ability to create structure in an evolving environment with incomplete processes or data.
Clear written and verbal communication for technical, business, audit and executive audiences.
Ability to distinguish material risk from low-value compliance activity.
Strong prioritization and risk-based decision-making.
Collaborative working style with the confidence to challenge decisions constructively.
Ability to coach, develop and hold team members accountable.
Comfortable remaining hands-on while the function and team are being built.
Curiosity and willingness to improve GRC workflows through automation and responsible use of AI.
Responsibilities
Own the Information Security GRC strategy, roadmap, operating model and management cadence.
Lead security governance, regulatory assurance, cyber risk, third-party security risk, policy lifecycle and security-awareness oversight.
Establish and maintain clear ownership for security controls, risks, exceptions, evidence and remediation actions.
Coordinate SOC 2, DORA/CySEC-relevant assurance, internal and external audits, regulatory requests and customer or partner security reviews.
Maintain decision-ready cyber-risk and exception registers and ensure material items are treated, accepted or escalated.
Lead the security portion of ICT supplier tiering, due diligence, reassessment and high-risk supplier decisions.
Oversee the development and maintenance of usable security policies, standards, control requirements and guidance.
Validate the quality, traceability and sustainability of evidence used for audits and management assurance.
Track control gaps, findings and remediation commitments and escalate unresolved material exposure.
Provide practical guidance to Security, IT, Engineering, Product, Platform and business teams on control design and risk-based trade-offs.
Prepare concise reporting for the CISO and executive stakeholders covering top risks, control posture, audit readiness, supplier exposure and overdue decisions.
Build, develop and manage the GRC team, including clear responsibilities, goals, performance expectations and succession planning.
Improve GRC efficiency through reusable evidence, workflow automation, better data quality and approved AI-assisted processes.
Will be a plus
Experience in fintech, payments, brokerage, trading, banking or another regulated financial-services environment.
Experience preparing an organization for SOC 2, ISO 27001, DORA, CySEC or PCI DSS assurance.
Experience building a GRC function or operating model in a scaling or high-growth organization.
Experience implementing or improving a GRC platform, automated evidence collection or compliance workflows.
Experience working closely with cloud, platform, product or engineering teams.
Experience with ICT supplier concentration risk, exit planning or operational resilience.
CISM, CRISC, CISA, CISSP, ISO 27001 Lead Implementer/Auditor or similar certification.
Practical experience using automation or AI to improve evidence review, risk analysis, questionnaires or reporting.