Global Edge Group is exclusively recruiting on behalf of a well-established technology company in the mining industry, seeking an experienced GRC Information Security Manager to lead and mature its Governance, Risk, Compliance, and Information Security capability.
This strategic leadership role requires a seasoned professional with a strong background in cybersecurity governance, enterprise risk management, regulatory compliance, audit management, security assurance, policy development, and stakeholder engagement.
The successful candidate will be responsible for establishing and maintaining a robust security governance framework, ensuring regulatory compliance, managing information security risks, and driving organisational security maturity.
Key Responsibilities
Governance & Information Security Management
- Develop, implement, and maintain the Information Security Governance Framework.
- Establish and maintain security policies, standards, procedures, and controls.
- Ensure alignment of information security initiatives with business objectives.
- Drive continuous improvement of the organisation's security posture and maturity.
- Lead enterprise-wide information security risk assessments.
- Manage the information security risk register and remediation programmes.
- Identify, evaluate, and mitigate cyber, operational, and third-party security risks.
- Provide risk-based recommendations to business and executive stakeholders.
Compliance & Regulatory Oversight
- Ensure compliance with applicable laws, regulations, and industry standards.
- Maintain compliance with frameworks such as ISO 27001, NIST, COBIT, GDPR, POPIA, and related regulatory requirements.
- Monitor legislative and regulatory developments impacting information security and privacy.
- Support regulatory reviews and compliance reporting activities.
Audit & Assurance
- Manage internal and external security audits.
- Coordinate assessments, controls testing, and compliance reviews.
- Oversee remediation of audit findings and control deficiencies.
- Provide assurance reporting to senior leadership and key stakeholders.
Third-Party Risk Management
- Manage supplier and vendor security risk assessments.
- Evaluate third-party security controls and compliance practices.
- Ensure appropriate contractual and security requirements are implemented.
Security Awareness & Culture
- Develop and lead security awareness programmes.
- Promote a culture of security, risk awareness, and compliance throughout the organisation.
- Provide guidance and training to business stakeholders on information security best practices.
Reporting & Stakeholder Management
- Prepare and present risk, compliance, and security reports to senior management.
- Engage with executives, business leaders, auditors, regulators, and external partners.
- Develop and track key security metrics, KRIs, and compliance indicators.
- Act as a trusted advisor on governance, risk, and security matters.
- Bachelor's Degree in Information Security, Information Technology, Computer Science, Risk Management, or a related field.
- Minimum 7+ years' experience within Information Security, Cybersecurity, Governance, Risk, and Compliance environments.
- Proven experience managing information security governance and risk frameworks.
- Strong understanding of enterprise risk management principles.
- Demonstrated experience managing audits, compliance programmes, and regulatory requirements.
- Experience developing and implementing security policies, standards, and controls.
- Strong business partnering and stakeholder management skills.
- Excellent communication, analytical, and leadership capabilities.
Preferred Certifications
One or more of the following certifications will be highly advantageous:
- CISSP
- CISM
- CRISC
- CGEIT
- Certified Risk Manager or equivalent
This is an outstanding opportunity to join an organisation where information security, governance, and risk management are viewed as strategic business enablers. The successful candidate will play a key role in shaping the organisation's security strategy, risk posture, and compliance landscape.