The Information Security GRC Manager will oversee and coordinate the Bank’s Information Security Governance, Risk, and Compliance activities across all Group entities. This role is pivotal in supporting the implementation of the Group’s Information Security strategy by ensuring robust governance processes, effective cyber risk management, regulatory compliance, control assurance, and security awareness programs are consistently applied across multiple countries and subsidiaries. Acting as a key liaison among Information Security, Technology, Risk Management, Internal Audit, Compliance, and business stakeholders, the manager ensures that information security risks are properly managed and regulatory requirements are met.
Key Responsibilities
- Lead the development, implementation, and maintenance of Group Information Security policies, standards, procedures, and control frameworks, ensuring consistent governance across all entities.
- Manage the lifecycle of security policies and standards, including reviews, stakeholder engagement, approvals, publication, and compliance monitoring.
- Oversee the Information Security Risk Management process, conducting risk assessments for projects, systems, applications, and third-party services while maintaining the Group Risk Register and tracking remediation efforts.
- Administer Information Security controls within the Bank’s Internal Control System (ICS), coordinating periodic reviews, quality assurance, and documentation updates to ensure control effectiveness and compliance.
- Support regulatory compliance by coordinating assessments, monitoring adherence to policies and legal requirements, and assisting in responses to audits and regulatory examinations.
- Coordinate security control assessments, compliance reviews, and validation of remediation activities, supporting internal and external audits related to information security.
- Develop and maintain security dashboards, Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), and management reports, providing analysis and timely escalation of risks and compliance issues.
- Manage third-party security risk by coordinating due diligence, onboarding reviews, ongoing assessments, and monitoring remediation activities.
- Support the Group Information Security Awareness Program, coordinating training, phishing simulations, and awareness campaigns to promote a strong cybersecurity culture.
- Act as a central point of coordination between Information Security, Technology, Risk, Compliance, Internal Audit, and business units, facilitating governance discussions and supporting Group-wide GRC initiatives.
Required Qualifications
- Bachelor’s degree in Information Security, Computer Science, Information Technology, Risk Management, Business Administration, or a related field.
- 8-10 years of experience in Information Security, Cyber Risk, IT Risk, Governance, Compliance, or Security Assurance.
- At least 3-5 years in a leadership, management, or senior specialist role within Governance, Risk, and Compliance (GRC).
- Proven experience in banking, financial services, fintech, or other regulated industries.
- Strong background in conducting risk assessments, compliance reviews, and managing security governance activities.
- Familiarity with regulatory frameworks, information security standards, and coordinating audits and remediation programs.
- Experience working in multinational and matrixed organizations, preferably with exposure to Group-level governance and reporting.
Preferred Qualifications
- Professional certifications such as CISM, CISSP, CRISC, CISA, ISO 27001 Lead Auditor/Implementer, COBIT Foundation or Design & Implementation, and PCI DSS Professional.
- Excellent skills in enterprise information security governance, cyber risk management, regulatory compliance, security assurance, and control testing.
- Strong leadership, stakeholder management, and communication skills with the ability to influence at executive and board levels.
- Fluency in English (written and spoken); additional languages relevant to the Bank’s operating regions are advantageous.
- Knowledge of banking regulatory requirements, technology risk management, data protection, outsourcing risk, and cybersecurity governance in financial services.
This role offers the opportunity to lead critical information security governance and risk management functions within a complex, multinational banking environment, driving compliance and enhancing the organization’s security posture.