Roles & Responsibilities
IT Security - GRC Manager
Position Overview
We are seeking a seasoned professional to lead and manage security governance initiatives, ensuring robust protection of organizational information and systems. The role encompasses compliance oversight, risk management, security audits, data loss prevention, DevSecOps release management, and security architecture consultation. This position involves close collaboration with multiple stakeholders and reports directly to the Head of IT Security.
Key Responsibilities
- Lead and oversee security governance activities, including policy implementation, regulatory compliance, and process improvements.
- Identify, assess, and mitigate information security risks, providing actionable recommendations to management.
- Monitor, track, and report security metrics to support informed decision-making.
- Manage security programs such as phishing simulations, penetration tests, and security assessments.
- Advise on security architecture and controls to enhance the organization’s overall security posture.
- Develop and deliver employee training and awareness initiatives to promote best practices in security.
- Support internal and external audits related to information security and compliance.
- Drive data loss prevention initiatives, including policy management, reporting, and employee education.
Candidate Profile
Extensive experience (8+ years) in information security governance, including at least 2 years in a leadership role.Strong knowledge of IT governance frameworks, risk management, and compliance practices.Hands-on experience managing security programs and activities, including assessments and threat simulations.Excellent communication skills, capable of translating technical concepts for non-technical audiences.Strategic thinker with the ability to manage complex projects and make data-driven decisions.Able to work independently while collaborating effectively across cross-functional teams.Qualifications
Bachelor’s degree in computer science, engineering, or a related field.Professional certifications in security governance or IT asset management are preferred (e.g., CISSP, CISA, CISM, CGEIT, CRISC).Technical / security certifications (e.g., OSCP, OSWE, CRTP, cloud certifications) are advantageous.Proficiency in written and spoken English.Reg. No. R1878306
EA License no. : 16S8066
Tell employers what skills you have
Information Security
Security Architecture
Security Audits
Security Governance
Regulatory Compliance
Cyber Security
Release Management
Information Security Governance
IT Governance
Risk Management
Phishing
Employee Training
Audits
CISA
Simulations
Information Security Management
Cyber Security Management
Loss Prevention
IT Asset Management
CISSP