GRC Lead — Governance, Risk & Compliance (Cybersecurity)
# GRC Lead — Governance, Risk & Compliance (Cybersecurity) **Be | Shaping the Future** · Romania · `Remote` · `Full Time` 💼 **Уровень роли:** `Senior` 🕒 **Статус:** *Опубликовано: сегодня* · *Источник: Himalayas (JSON API)* --- ### Top Skills & Match 🎯 **Ключевой стек роли:** `[Cybersecurity-GRC-Specialist]` `[Security-Compliance-Manager]` `[Risk-And-Compliance-Analyst]` `[Information-Security-Manager]` `[IT-Governance-Analyst]` `[Security-GRC-Lead]` `[Cybersecurity-Governance-Risk-and-Compliance-Manager]` `[Governance-Risk-And-Compliance-Manager]` `[Lead-GRC-Technology-Specialist]` `[Information-Security-GRC-Manager]` `[Director-Of-Governance-Risk-And-Compliance]` `[IT-Compliance-Lead]` --- ### About the Role Core Competencies Primary Skills - Governance, Risk & Compliance (GRC) - GDPR - NIS2 - ISO 27001 - Information Security Policy and Procedure Development Secondary Skills - NIST Cybersecurity Framework (NIST CSF) - Privacy Management Responsibilities - Lead the cybersecurity governance, risk, and compliance (GRC) program, working closely with Legal, Privacy, Risk Management, and Government Affairs teams to address evolving regulatory requirements. - Establish, implement, and continuously improve the Information Security Management System (ISMS) in accordance with ISO 27001/27002 standards. - Develop, maintain, and enhance information security, privacy, data protection, incident response policies, standards, procedures, and governance frameworks. - Manage an enterprise-wide cybersecurity and risk program to protect the confidentiality, integrity, and availability of information assets. - Conduct risk assessments, facilitate risk management activities, and support business units in identifying and mitigating security and compliance risks. - Provide subject matter expertise on global cybersecurity and privacy regulations and frameworks, including GDPR, NIS2, ISO 27001/27002, and NIST CSF. - Perform compliance assessments, audits, gap analyses, and oversee remediation initiatives. - Support internal and external audits, certification activities, and regulatory examinations. - Assess security threats, vulnerabilities, and control effectiveness; communicate risks and recommendations to business and technical stakeholders. - Align cybersecurity, privacy, and compliance initiatives with organizational objectives and business strategy. - Lead governance and project management activities related to cybersecurity, privacy, and compliance programs. - Evaluate and recommend security and privacy controls for new and existing technologies, applications, and infrastructure. - Monitor emerging threats, regulatory developments, and industry best practices. - Support organizational compliance efforts related to GDPR, NIS2, ISO 27001/27002, and NIST CSF, including compliance reporting, governance metrics, and risk dashboards. - Promote the adoption of security and privacy-enhancing technologies that support effective privacy and compliance operations. Originally posted on Himalayas
- Cybersecurity-GRC-Specialist
- Security-Compliance-Manager
- Risk-And-Compliance-Analyst
- Information-Security-Manager
- IT-Governance-Analyst
- Security-GRC-Lead
- Cybersecurity-Governance-Risk-and-Compliance-Manager
- Governance-Risk-And-Compliance-Manager
- Lead-GRC-Technology-Specialist
- Information-Security-GRC-Manager
- Director-Of-Governance-Risk-And-Compliance
- IT-Compliance-Lead
Наблюдалась 2026-10-04, впервые 2026-10-04, источник — Himalayas (JSON API).