Information Security Governance, Risk & Compliance Manager

JustMarkets

United States

Remote

USD 120,000 - 190,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

20 vacation days
10 sick leave days
Public holidays per policy
Medical budget
Remote work opportunity
Professional education budget
Language learning budget
Wellness budget

Job summary

JustMarkets is seeking an experienced Information Security GRC Manager to lead governance, risk and compliance in a growing international FinTech environment. This is a hands-on leadership role with a chance to shape the GRC operating model, roadmap, team, and core processes.

You will work directly with the CISO and collaborate with Security, Legal, Risk, IT, Procurement, HR, and business teams to translate regulatory requirements into practical controls and processes that support business

Qualifications

  • Strong practical experience in Information Security GRC, cyber/technology risk, security compliance, or assurance.
  • Experience with frameworks such as SOC 2, ISO 27001, DORA, PCI DSS, NIST CSF, COBIT or similar.
  • Experience coordinating audits, regulatory or assurance activities.
  • Ability to translate regulatory requirements into practical controls and processes.
  • Proven stakeholder management with technical and executive audiences.

Responsibilities

  • Own and develop the Information Security GRC strategy, roadmap, operating model, and governance cadence.
  • Lead security governance, regulatory assurance, cyber risk, and policy lifecycle oversight.
  • Establish clear ownership for security controls, risks, evidence, and remediation actions.
  • Coordinate SOC 2, DORA/CySEC, audits, and regulatory requests.
  • Maintain cyber-risk and exception registers and manage material risks.
  • Develop practical security policies, standards, controls, and guidance.
  • Prepare concise GRC and risk reporting for the CISO and executives.
  • Build and manage the GRC team with clear goals and performance expectations.
  • Improve GRC efficiency through automation and better data quality.

Skills

GRC management
Cyber risk
Security compliance
Audits coordination
Stakeholder management
Cloud & IT understanding
Team leadership
Policy development

Job description

We are looking for an experienced Information Security GRC Manager to lead and develop our Information Security Governance, Risk & Compliance function.

This is a hands-on leadership role with the opportunity to shape the GRC operating model, roadmap, team, and core processes in a growing international FinTech environment.

You will work directly with the CISO and collaborate closely with Security, Legal, Risk, Procurement, IT, Engineering, Product, Platform, HR, and business teams.

The role combines security governance, cyber risk, regulatory assurance, third-party risk, policy management, and security awareness, with a strong focus on building practical controls and processes that support business growth.

Requirements
  • Strong practical experience in Information Security GRC, cyber/technology risk, security compliance, or assurance.
  • Hands-on experience with recognized frameworks such as SOC 2, ISO 27001, DORA, PCI DSS, NIST CSF, COBIT, or similar.
  • Experience establishing or operating security controls, risk registers, exception processes, and assurance programs.
  • Strong understanding of control design, operating effectiveness, evidence quality, findings, and remediation.
  • Experience coordinating internal or external audits and regulatory or assurance activities.
  • Practical experience with cyber risk assessment, risk treatment, risk acceptance, and escalation.
  • Understanding of third-party and ICT supplier security risk.
  • Ability to translate regulatory and security requirements into practical controls and processes.
  • Strong stakeholder management skills and ability to work effectively with technical, business, and executive audiences.
  • Sufficient technical understanding of cloud, infrastructure, identity, IT operations, and product development to work effectively with technical teams.
  • Experience leading a team, function, program, or complex cross‑functional initiatives.
  • Strong ownership, prioritization, and decision‑making skills.
Responsibilities
  • Own and develop the Information Security GRC strategy, roadmap, operating model, and governance cadence.
  • Lead security governance, regulatory assurance, cyber risk, third‑party security risk, policy lifecycle, and security‑awareness oversight.
  • Establish clear ownership for security controls, risks, exceptions, evidence, and remediation actions.
  • Coordinate SOC 2, DORA/CySEC‑related assurance, internal and external audits, and regulatory requests.
  • Maintain cyber‑risk and exception registers and ensure material risks are treated, accepted, or escalated.
  • Lead security aspects of ICT supplier tiering, due diligence, reassessment, and high‑risk supplier decisions.
  • Develop practical security policies, standards, controls, and guidance.
  • Ensure audit and assurance evidence is reliable, traceable, and reusable.
  • Track control gaps, findings, and remediation commitments and escalated material risks.
  • Partner with Security, IT, Engineering, Product, Platform, Legal, and business teams on control design and risk‑based decisions.
  • Prepare concise GRC and risk reporting for the CISO and executive stakeholders.
  • Build, develop, and manage the GRC team, including responsibilities, goals, and performance expectations.
  • Improve GRC efficiency through automation, reusable evidence, better data quality, and responsible AI‑assisted workflows.

We Offer

  • 20paid vacation days per year
  • 10paid sick leave days per year
  • Public holidays according tocompany policy
  • Medical budget
  • Remote work opportunity
  • Professional education budget
  • Language learning budget
  • Wellness budget (gym membership, sports gear, etc.)
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Manager, Information Security Governance, Risk & Compliance (GRC)
Manager, Information Security Governance, Risk & Compliance (GRC)

Burtch Works • United States

Remote
USD 140,000 - 170,000
Health and wellness benefits
Remote, US-based work
GRC (Governance, Risk, and Compliance) Consultant
GRC (Governance, Risk, and Compliance) Consultant

Zoho • United States

Remote
USD 120,000 - 180,000
Head of Security GRC
Head of Security GRC

drivewealth • United States

Remote
USD 180,000 - 320,000
Base + bonus + equity
401(k) plan with match
Extensive healthcare coverage (dental,
+5
GRC Analyst
GRC Analyst

Golden Technology • North Carolina

Hybrid
USD 120,000 - 160,000
Information Security Officer
Information Security Officer

super • United States

Remote
USD 180,000 - 240,000
Medical insurance
Open annual leave
Employee assistance programme
+1
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

LexisNexis • Raleigh (NC)

On-site
USD 118,000 - 220,000
Head of Information Security and GRC
Head of Information Security and GRC

Stott and May • New York (NY)

On-site
USD 250,000 - 350,000
Equity
Head of Information Security & GRC – GRC, Compliance, Information Security, ISO27001, DDQ’s
Head of Information Security & GRC – GRC, Compliance, Information Security, ISO27001, DDQ’s

Stott and May • New York (NY)

On-site
USD 180,000 - 260,000
Governance, Risk, & Compliance (GRC) Analyst
Governance, Risk, & Compliance (GRC) Analyst

Districttechgroup • Washington

On-site
USD 80,000 - 100,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+2
Staff Security Analyst - GRC
Staff Security Analyst - GRC

Jobgether • United States

Hybrid
USD 150,000 - 164,000
Remote work within the United States
Hybrid option with designated offices