The GRC Lead is responsible for designing, implementing, and maturing an enterprise-wide Governance, Risk & Compliance (GRC) framework. The role focuses on strengthening organisational resilience across disaster recovery, identity governance, cyber supplier risk, and regulatory compliance (including ISO 27001 and Cyber Essentials+).
This is a hands‑on leadership role combining strategic governance design with operational execution of risk and compliance controls.
Core Responsibilities
1. Governance Frameworks
- Develop and maintain enterprise GRC frameworks, policies, and security standards
- Define and govern Disaster Recovery (DR) strategy, including:
- DR testing cycles
- Documentation and audit readiness
- Align governance structures with regulatory, contractual, and internal risk requirements
- Promote a risk‑aware culture across IT and business functions
- Lead identification and management of IT and enterprise risks, including:
- Disaster recovery resilience risks
- Identity and access governance risks
- Supplier / third‑party cyber risk
- Single points of failure in critical systems
- Maintain and continuously update the enterprise risk register
- Develop and track risk mitigation and remediation plans
- Produce and present KRIs (Key Risk Indicators) and risk reporting to senior leadership and board‑level stakeholders
3. Compliance & Regulatory Management
- Lead and manage compliance programs including:
- ISO 27001 / ISO 27002
- GDPR and other relevant regulatory frameworks
- Monitor and interpret regulatory changes and emerging compliance requirements
- Coordinate and support internal and external audits, including evidence collection
- Deliver compliance training and awareness programs across IT and business units
4. Security Controls & Technology Risk
- Oversee identity governance controls, including:
- Joiner/Mover/Leaver (JML) processes
- Drive third‑party and supplier cyber risk assessments
- Partner with IT teams to ensure cloud, ERP, and enterprise systems meet security and control standards
- Maintain and enhance incident response governance and playbooks
5. Leadership & Stakeholder Engagement
- Act as a trusted advisor to CIO and executive leadership on risk, governance, and compliance matters
- Collaborate across IT, HR, Procurement, Security, and business units
- Build and mature a GRC capability and operating model
- Mentor and develop GRC team members as the function scales
Mandatory Training & Development Framework
Core GRC & Security Training
- ISO 27001 / ISO 27002 (Lead Implementer or Auditor level preferred)
- NIST Cybersecurity Framework (CSF)
- Regulatory Compliance Training:
- GDPR and data protection laws
- Industry‑specific compliance requirements
- Third‑Party Risk Management:
Leadership Development
- Executive and board‑level risk communication and reporting
- Influencing cross‑functional stakeholders without direct authority
- Advanced training in policy development and governance frameworks
Continuous Professional Development (CPD)
- Engagement with GRC, cybersecurity, and audit industry bodies
- Attendance at risk, security, and compliance conferences
- Ongoing vendor‑led training and regulatory updates
- Annual CPD planning aligned to organisational risk priorities
Internal Enablement
- Deliver risk and compliance awareness training across the organisation
- Develop and maintain internal GRC documentation, standards, and guidance
- Support development of a risk‑aware organisational culture
Qualifications & Experience
Education & Certifications
- Bachelor’s degree in IT, Cybersecurity, Risk Management, or related discipline
- Preferred certifications:
- CISA
- CRISC
- CISSP
Experience
- 6–15+ years in GRC, cybersecurity risk, internal audit, or enterprise risk roles
- Proven experience leading enterprise risk and compliance programmes
- Hands‑on involvement in:
- Disaster recovery governance
- Identity governance frameworks
- Supplier / third‑party risk management
Technical & Professional Skills
- Strong understanding of:
- IT infrastructure and cloud environments
- Identity and access management systems
- ERP and enterprise platforms
- Ability to translate technical risk into clear business impact
- Strong policy writing, documentation, and governance design skills
- Excellent stakeholder management and communication abilities
Must hold Stamp 4, EU or Irish passport - this is fully onsite North Dublin
shane.doolin@realtime.jobs with your CV or Direct message me to chat