GRC Lead — Governance, Risk & Compliance (Cybersecurity)

Be | Shaping the Future

Remote (Romania) Remote Full-time 6 days ago
Workplace
Remote
Location
Romania

Check your CV against this job

Free · No signup · A 0–100 ATS match score and the keywords you're missing.

Check my CV free

$14.99/month, cancel anytime. Already have an account? Log in

About the role

CORE COMPETENCIES

PRIMARY SKILLS

* Governance, Risk & Compliance (GRC) * GDPR * NIS2 * ISO 27001 * Information Security Policy and Procedure Development

SECONDARY SKILLS

* NIST Cybersecurity Framework (NIST CSF) * Privacy Management

RESPONSIBILITIES

* Lead the cybersecurity governance, risk, and compliance (GRC) program, working closely with Legal, Privacy, Risk Management, and Government Affairs teams to address evolving regulatory requirements. * Establish, implement, and continuously improve the Information Security Management System (ISMS) in accordance with ISO 27001/27002 standards. * Develop, maintain, and enhance information security, privacy, data protection, incident response policies, standards, procedures, and governance frameworks. * Manage an enterprise-wide cybersecurity and risk program to protect the confidentiality, integrity, and availability of information assets. * Conduct risk assessments, facilitate risk management activities, and support business units in identifying and mitigating security and compliance risks. * Provide subject matter expertise on global cybersecurity and privacy regulations and frameworks, including GDPR, NIS2, ISO 27001/27002, and NIST CSF. * Perform compliance assessments, audits, gap analyses, and oversee remediation initiatives. * Support internal and external audits, certification activities, and regulatory examinations. * Assess security threats, vulnerabilities, and control effectiveness; communicate risks and recommendations to business and technical stakeholders. * Align cybersecurity, privacy, and compliance initiatives with organizational objectives and business strategy. * Lead governance and project management activities related to cybersecurity, privacy, and compliance programs. * Evaluate and recommend security and privacy controls for new and existing technologies, applications, and infrastructure. * Monitor emerging threats, regulatory developments, and industry best practices. * Support organizational compliance efforts related to GDPR, NIS2, ISO 27001/27002, and NIST CSF, including compliance reporting, governance metrics, and risk dashboards. * Promote the adoption of security and privacy-enhancing technologies that support effective privacy and compliance operations.

Originally posted on Himalayas

Get matched & apply with FindAJobAI

Upload your resume once. We score every job against your profile, tailor your resume and cover letter, and autofill the application.