The Information Security GRC Manager will be responsible for overseeing and managing the governance, risk, and compliance functions within client organizations. This individual will play a key role in ensuring the company's information security practices adhere to legal, regulatory, and industry standards while helping senior leadership mitigate risks and improve overall security posture. The role will involve working closely with senior stakeholders, advising them on risk-related issues, and implementing strategies that align with business goals and regulatory requirements.
Governance & Risk Management:
* Lead and oversee the organization's information security governance framework, ensuring compliance with relevant standards such as ISO 27001, NIST, and GDPR.
* Identify, assess, and monitor security risks and ensure proper risk management strategies are implemented.
* Develop and maintain risk registers and facilitate risk assessments across the organization.
* Advise senior stakeholders (C-suite, department heads) on the potential impact of security risks and recommend appropriate mitigation strategies.
Compliance Management:
* Manage the organization's compliance with legal, regulatory, and contractual obligations related to information security (eg, GDPR, CCPA, HIPAA, SOX).
* Ensure that appropriate internal controls, audits, and assessments are conducted regularly to verify compliance with external regulations and internal policies.
* Lead and coordinate internal and external audits to validate compliance and identify areas for improvement.
Stakeholder Management & Reporting:
* Regularly engage with senior stakeholders to communicate risk exposure, provide recommendations, and report on the status of the security program.
* Prepare and deliver executive-level reports and presentations on security risks, compliance status, and mitigation efforts to the Board of Directors and C-suite.
* Act as a liaison between technical teams, management, and external parties (eg, regulators, auditors) on matters related to security governance, risk, and compliance.
Policy & Procedure Development:
* Develop, implement, and update information security policies, procedures, and guidelines to align with industry best practices and regulatory requirements.
* Promote a culture of security awareness across the organization, ensuring policies are understood and adhered to at all levels.
Incident & Crisis Management:
* Collaborate with the incident response team to ensure that information security incidents are properly managed, documented, and reported in line with governance frameworks.
* Assist in the identification of vulnerabilities and develop strategies for responding to and recovering from security incidents.
* Stay abreast of the latest information security threats, trends, and compliance requirements.
* Identify areas for continuous improvement in governance, risk management, and compliance processes and implement appropriate changes.
As an ideal candidate, you will have an industry certification such as CISSP/CISM/CRISC. You will also have a proven track record of delivering in a similar role.
Please note: This role is based in Belfast.
Seniority level
Mid-Senior level
Employment type
Contract
Job function
Management
Industries
Computer and Network Security and Professional Services
#J-18808-Ljbffr