Location: Dublin – On-site during probation, with hybrid working available post-probation.
Role Overview
A senior IT governance and risk role responsible for strengthening the organisation’s IT risk, compliance and security framework, while leading audits, DR/BCP, policy management and key IT governance projects across the business.
About the Role
BEX Group is seeking an experienced IT Risk & GRC Manager to take ownership of IT risk, governance, compliance and business continuity across the organisation.
This is a senior role combining strategic oversight with hands-on delivery. You will work closely with senior IT leadership, MSPs, suppliers and internal stakeholders to strengthen IT controls, manage regulatory requirements and ensure the organisation is prepared for emerging risks.
You will also lead relevant IT risk, compliance and continuity projects, ensuring they are delivered effectively and aligned with business objectives.
Key Responsibilities
- Own and continuously develop the IT Risk Register, including risk assessments, mitigation plans and reporting.
- Lead cyber security risk reviews and coordinate remediation activity with MSPs and internal teams.
- Manage compliance with key requirements including NIS2, GDPR and ISO 27001 principles.
- Own the lifecycle of IT policies, procedures, standards and supporting compliance evidence.
- Coordinate internal and external IT audits, from preparation and evidence gathering through to remediation and closure.
- Oversee software licence compliance, application governance and IT asset visibility.
- Support effective governance of IT suppliers, contracts, renewals, SLAs and related financial processes.
- Lead Disaster Recovery and Business Continuity planning, testing and continuous improvement.
- Coordinate IT/cyber insurance submissions and ensure relevant controls are maintained.
- Lead IT risk, compliance and continuity projects, managing timelines, stakeholders, risks and deliverables.
- Act as a trusted advisor to senior leadership and promote a strong culture of IT governance, security and accountability.
- Provide leadership and guidance to junior IT team members where required.
What We’re Looking For
- 7+ years’ experience in IT risk, governance, GRC, cyber security compliance or a related IT role.
- Strong practical knowledge of NIS2, GDPR, ISO 27001 and ITIL.
- Proven experience managing IT risk, audits, compliance frameworks and remediation programmes.
- Strong understanding of cyber security controls and risk management.
- Experience working with MSPs, suppliers and third-party technology providers.
- Experience with DR/BCP planning and testing.
- Strong project management, organisational and stakeholder-management skills.
- Excellent communication, analytical and problem-solving abilities.Strong documentation and reporting skills, including Microsoft Word and Excel.
- Experience in a multi-site, manufacturing, warehousing or operational environment.
- Experience working across multiple regions or jurisdictions.
- Relevant qualifications such as CISM, CISA, ISO 27001, GDPR Practitioner or ITIL.
- Experience with cyber insurance requirements and supplier security assessments.