Own and mature the organisation's IT risk posture—covering cyber security risk review, application visibility, licence management, supplier process control, compliance, insurance requests, disaster recovery/business continuity (DR/BCP) testing, IT policy management, coordinating IT audits and PM delivery of follow-up actions.
Key Responsibilities
- Maintain and drive the IT Risk Register: identify, assess, prioritise, and track mitigation actions.
- Coordinate periodic cyber risk assessments and remediation with MSPs.
- Support incident response readiness and reporting.
2) Licence Management
- Own software asset & licence compliance: inventories, renewals, and optimisation.
3) Applications Visibility & Process Control
- Maintain application catalogue and enforce onboarding/offboarding standards.
- Validate approved POs, match invoices, track renewals, and monitor vendor SLAs.
5) Compliance (incl. NIS2 & GDPR)
- Map obligations to internal controls; prepare for audits and maintain evidence.
6) IT Policy Management
- Maintain and update IT policies (security, access, backup, acceptable use).
- Ensure policies are communicated and acknowledged by stakeholders.
7) Audit Coordination
- Act as primary coordinator for IT audits (internal/external).
- Gather evidence, liaise with auditors, and track follow-up actions to closure.
8) IT Insurance Requests
- Complete insurer questionnaires and ensure compliance with policy conditions.
9) DR & BCP Testing
- Plan and execute DR/BCP tests; maintain runbooks and update policies.
10) Project Management of Related Initiatives
- Act as project lead for IT risk, compliance, and continuity projects.
- Coordinate delivery with Managed Service Providers (MSPs) and internal stakeholders.
- Define scope, timelines, and deliverables; track progress and elevate risks.
- Ensure projects align with IT governance and business objectives.
Location:
Dublin (On site during probation period, Opportunity for Hybrid post probation)
About the Role
We’re seeking an experienced IT Risk (GRC) Manager to lead governance, risk, and compliance initiatives across multiple regions. You’ll own the IT risk framework, manage audits, and ensure our business meets regulatory and security obligations while driving supplier and continuity strategies.
Key Responsibilities
- Lead IT risk management, cyber security reviews, and mitigation plans.
- Oversee software licence compliance and application governance.
- Manage supplier relationships, contracts, and financial processes.
- Ensure compliance with NIS2, GDPR, and other regulatory frameworks.
- Own IT policy lifecycle and communicate updates across the business.
- Coordinate internal/external IT audits and close follow-up actions.
- Drive DR & BCP strategy, testing, and policy updates.
- Prepare IT insurance submissions and maintain compliance evidence.
- Provide leadership and mentoring to junior team members.
- Lead and oversee IT risk, compliance, and continuity projects, ensuring timely delivery with MSPs and cross-functional stakeholders.
What We’re Looking For
- 7+ years in IT risk/compliance or IT governance roles.
- Strong knowledge of frameworks: NIS2, ISO 27001, GDPR, ITIL.
- Proven experience managing audits and stakeholder engagement.
- Excellent leadership and communication skills.
Nice to Have
- Experience in multi-site or warehousing environments.
- Certifications: CISM, CISA, ISO 27001 Lead Implementer, ITIL.