Description
You will manage security governance, risk, and compliance functions within a large, complex, global matrix organization.
Responsibilities
- Support the Information Security Management System (ISMS) and security team strategy.
- Maintain security certifications, specifically focusing on ISO27001 implementation and ongoing maintenance.
- Automate GRC workstreams through the implementation, maintenance, and expansion of GRC software.
- Facilitate security framework and governance meetings for senior executives and board members.
- Draft and update security documentation, including policies, standards, requirements, and guidelines.
- Compile and manage security KPIs, metrics, and GRC reporting.
Required Skills
- 3–5 years of experience in an information security role within a large commercial organization.
- Proven experience in Security Governance, Risk, and Compliance (GRC).
- Hands-on experience with the implementation and maintenance of Security GRC software.
- Direct experience with ISO27001 implementation and maintenance.
- Expertise in at least two areas: risk management, vendor security, security policies, security governance, assurance, or audit.
- Subject matter expertise in applicable security legislation and regulatory requirements.
- Strong general awareness of cybersecurity and security architecture technical measures and best practices.
- Degree level education or professional qualifications such as CISSP, CISM, or ISO 27001 Auditor/Implementer.
Preferred Skills
- Knowledge or experience within the telecoms industry.
- Knowledge of cloud security and governance.