M

GRC Lead

mindsolve consulting • Romania
Remote
Apply
AI Summary

Drive the cybersecurity governance, risk, and compliance program across the enterprise. Establish, implement, and continuously improve the Information Security Management System (ISMS) in line with ISO 27001/2. Manage an enterprise-wide cybersecurity and risk program protecting the confidentiality, integrity, and availability of information assets.

Key Highlights
Lead the GRC Program
Establish, implement, and continuously improve the Information Security Management System (ISMS)
Manage an enterprise-wide cybersecurity and risk program
Key Responsibilities
Lead the GRC Program: Drive the cybersecurity governance, risk, and compliance program across the enterprise.
ISMS Ownership: Establish, implement, and continuously improve the Information Security Management System (ISMS) in line with ISO 27001/2.
Policies and Frameworks: Develop, maintain, and improve policies, standards, procedures, and governance frameworks covering information security, privacy, data protection, and incident response.
Enterprise Risk Management: Manage an enterprise-wide cybersecurity and risk program protecting the confidentiality, integrity, and availability of information assets; conduct risk assessments and support business units in identifying and mitigating security and compliance risks.
Regulatory Expertise: Provide subject matter expertise on global cybersecurity and privacy regulations and frameworks, including GDPR, NIS2, ISO 27001/2, and NIST CSF.
Audits and Assessments: Perform compliance assessments, audits, and gap analyses; oversee remediation initiatives; support internal and external audits, certification activities, and regulatory examinations.
Threat and Control Evaluation: Evaluate security threats, vulnerabilities, and control effectiveness; communicate risks and recommendations to business and technical stakeholders; recommend security and privacy controls for new and existing technologies, applications, and infrastructure.
Strategic Alignment and Reporting: Align cybersecurity, privacy, and compliance initiatives with organizational objectives; lead related governance and project management activities; deliver compliance reporting, governance metrics, and risk dashboards; monitor emerging threats, regulatory developments, and industry best practices; promote security and privacy-enhancing technologies.
Technical Skills Required
GRC GDPR NIS2 ISO 27001
Benefits & Perks
12-month fully remote engagement

Job Description


Job Description

We are looking for a GRC Lead to drive the cybersecurity governance, risk, and compliance program of a large enterprise. You will work closely with Legal, Privacy, Risk Management, and Government Affairs teams to address evolving regulatory requirements. This is a 12-month fully remote engagement. Fluent English is mandatory; French is a plus. Primary skills include GRC, GDPR, NIS2, ISO 27001, and the development of information security policies and procedures; secondary skills include NIST CSF and Privacy Management.

Core Responsibilities

  • Lead the GRC Program: Drive the cybersecurity governance, risk, and compliance program across the enterprise.
  • ISMS Ownership: Establish, implement, and continuously improve the Information Security Management System (ISMS) in line with ISO 27001/2.
  • Policies and Frameworks: Develop, maintain, and improve policies, standards, procedures, and governance frameworks covering information security, privacy, data protection, and incident response.
  • Enterprise Risk Management: Manage an enterprise-wide cybersecurity and risk program protecting the confidentiality, integrity, and availability of information assets; conduct risk assessments and support business units in identifying and mitigating security and compliance risks.
  • Regulatory Expertise: Provide subject matter expertise on global cybersecurity and privacy regulations and frameworks, including GDPR, NIS2, ISO 27001/2, and NIST CSF.
  • Audits and Assessments: Perform compliance assessments, audits, and gap analyses; oversee remediation initiatives; support internal and external audits, certification activities, and regulatory examinations.
  • Threat and Control Evaluation: Evaluate security threats, vulnerabilities, and control effectiveness; communicate risks and recommendations to business and technical stakeholders; recommend security and privacy controls for new and existing technologies, applications, and infrastructure.
  • Strategic Alignment and Reporting: Align cybersecurity, privacy, and compliance initiatives with organizational objectives; lead related governance and project management activities; deliver compliance reporting, governance metrics, and risk dashboards; monitor emerging threats, regulatory developments, and industry best practices; promote security and privacy-enhancing technologies.

Qualifications And Experience

  • Proven experience leading GRC programs in complex enterprise environments.
  • Deep expertise in GDPR, NIS2, ISO 27001/2, and information security policy development.
  • Working knowledge of NIST CSF and Privacy Management.
  • Strong stakeholder communication skills across business, legal, and technical audiences.
  • Fluent English; French is a plus.

Similar Jobs

Explore other opportunities that match your interests

Application Security Engineer

Cyber Security
•
3w ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Entry level

BetterQA

Romania

Cyber Incident Response Analyst

Cyber Security
•
3w ago
Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Entry level

Independent Contractor

Romania

Senior Runtime Protection Engineer

Cyber Security
•
3w ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

CloudLinux

Romania

Subscribe our newsletter

New Things Will Always Update Regularly