Drive the cybersecurity governance, risk, and compliance program across the enterprise. Establish, implement, and continuously improve the Information Security Management System (ISMS) in line with ISO 27001/2. Manage an enterprise-wide cybersecurity and risk program protecting the confidentiality, integrity, and availability of information assets.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Job Description
Job Description
We are looking for a GRC Lead to drive the cybersecurity governance, risk, and compliance program of a large enterprise. You will work closely with Legal, Privacy, Risk Management, and Government Affairs teams to address evolving regulatory requirements. This is a 12-month fully remote engagement. Fluent English is mandatory; French is a plus. Primary skills include GRC, GDPR, NIS2, ISO 27001, and the development of information security policies and procedures; secondary skills include NIST CSF and Privacy Management.
Core Responsibilities
- Lead the GRC Program: Drive the cybersecurity governance, risk, and compliance program across the enterprise.
- ISMS Ownership: Establish, implement, and continuously improve the Information Security Management System (ISMS) in line with ISO 27001/2.
- Policies and Frameworks: Develop, maintain, and improve policies, standards, procedures, and governance frameworks covering information security, privacy, data protection, and incident response.
- Enterprise Risk Management: Manage an enterprise-wide cybersecurity and risk program protecting the confidentiality, integrity, and availability of information assets; conduct risk assessments and support business units in identifying and mitigating security and compliance risks.
- Regulatory Expertise: Provide subject matter expertise on global cybersecurity and privacy regulations and frameworks, including GDPR, NIS2, ISO 27001/2, and NIST CSF.
- Audits and Assessments: Perform compliance assessments, audits, and gap analyses; oversee remediation initiatives; support internal and external audits, certification activities, and regulatory examinations.
- Threat and Control Evaluation: Evaluate security threats, vulnerabilities, and control effectiveness; communicate risks and recommendations to business and technical stakeholders; recommend security and privacy controls for new and existing technologies, applications, and infrastructure.
- Strategic Alignment and Reporting: Align cybersecurity, privacy, and compliance initiatives with organizational objectives; lead related governance and project management activities; deliver compliance reporting, governance metrics, and risk dashboards; monitor emerging threats, regulatory developments, and industry best practices; promote security and privacy-enhancing technologies.
Interested in remote work opportunities in Cyber Security? Discover Cyber Security Remote Jobs featuring exclusive positions from top companies that offer flexible work arrangements.
Browse our curated collection of remote jobs across all categories and industries, featuring positions from top companies worldwide.
- Proven experience leading GRC programs in complex enterprise environments.
- Deep expertise in GDPR, NIS2, ISO 27001/2, and information security policy development.
- Working knowledge of NIST CSF and Privacy Management.
- Strong stakeholder communication skills across business, legal, and technical audiences.
- Fluent English; French is a plus.
Similar Jobs
Explore other opportunities that match your interests