We are seeking a Governance Risk and Compliance lead (GRC) Lead for a top multinational offering hybrid remote work and a strong package.
You will be responsible for establishing and overseeing the organisation’s governance framework, enterprise risk management programme and regulatory compliance strategy, with a strong focus on information security, cyber resilience, data protection and AI governance.
Responsibilities
- Lead the design, implementation and continuous improvement of the ISO/IEC 27001-aligned ISMS.
- Develop and maintain policies and controls aligned to ISO, NIST, SOC 2 and applicable regulations.
- Advise senior leadership on cyber risk posture and regulatory obligations.
- Ensure governance supports secure digital transformation and cloud adoption.
- Identify and manage strategic, operational, cyber, AI and compliance risks.
- Maintain the risk register and report risk exposure to executive leadership.
- Conduct security risk assessments, threat modelling and business impact assessments.
- Develop and implement AI governance and model risk management frameworks.
- Conduct AI risk assessments (bias, transparency, privacy, adversarial threats).
- Oversee third-party AI risk due diligence and ongoing monitoring.
Compliance, Audit & Assurance
- Ensure compliance with GDPR and applicable regulatory requirements.
- Lead audits, certification programmes and regulatory engagements.
- Oversee remediation of audit findings and control deficiencies.
- Design, implement and test security controls aligned to ISO Annex A and NIST CSF.
- Monitor control effectiveness, vulnerability oversight and risk metrics.
- Drive continuous improvement to enhance cyber resilience.
Experience
- 8+ years’ experience in GRC, Information Security or Cyber Risk roles.
- Proven ISO 27001 implementation and certified ISMS experience.
- Strong knowledge of ISO 27001, NIST CSF, SOC 2 and GDPR.
- Experience in AI governance or technology risk frameworks.
- Previous experience working within a technical IT and Security Infrastructure role.
- Track record leading audits, risk assessments and regulatory engagement.
- Strong analytical and executive reporting skills.