Job Description
The Governance, Risk, and Compliance (GRC) Lead will oversee security risk and compliance, develop and implement security policies, establish measures and metrics, and drive security awareness training initiatives.
Key Responsibilities
* Security Risk and Compliance:
o Identify, assess, and manage security risks to ensure compliance with industry standards and regulations.
o Develop and maintain risk assessment and management processes.
o Monitor and report on compliance with security policies, standards, and regulations.
* Policy Development:
o Develop, review, and update security policies and procedures.
o Evaluate policy alignment with industry best practices and regulatory requirements.
o Communicate and enforce security policies across the organization.
* Measures and Metrics:
o Develop and implement security metrics and reporting systems.
o Track and report on security performance, risks, and compliance status.
o Provide regular updates and insights to senior management.
* Security Awareness Training:
o Design and deliver security awareness training programs for employees.
o Promote a culture of security awareness and best practices.
o Assess the effectiveness of training programs and make improvements as necessary.
Qualifications
* Education and Experience
o Bachelor's degree in Information Security, Cybersecurity, or a related field.
o Proven experience in security governance, risk management, and compliance.
* Skills and Knowledge
o Strong knowledge of security frameworks, standards, and regulations (e.g. NIST CSF, ISO 27001/27002, GDPR).
o Excellent communication and interpersonal skills.
o Ability to develop and deliver effective training programs.
o Strong analytical and problem-solving skills.
o Relevant certifications (e.g., CISSP, CISM, CISA).
o Familiarity with cloud security and hybrid environments.