Information Security Governance, Risk & Compliance Manager
JustMarkets · Europe
New
mid
information security
Apply on JustMarkets →
We are looking for an experienced Information Security GRC Manager to lead and develop our Information Security Governance, Risk & Compliance function.
This is a hands-on leadership role with the opportunity to shape the GRC operating model, roadmap, team, and core processes in a growing international FinTech environment.
You will work directly with the CISO and collaborate closely with Security, Legal, Risk, Procurement, IT, Engineering, Product, Platform, HR, and business teams.
The role combines security governance, cyber risk, regulatory assurance, third-party risk, policy management, and security awareness, with a strong focus on building practical controls and processes that support business growth.
Requirements
Strong practical experience in Information Security GRC, cyber/technology risk, security compliance, or assurance
Hands-on experience with recognized frameworks such as SOC 2, ISO 27001, DORA, PCI DSS, NIST CSF, COBIT, or similar
Experience establishing or operating security controls, risk registers, exception processes, and assurance programs
Strong understanding of control design, operating effectiveness, evidence quality, findings, and remediation
Experience coordinating internal or external audits and regulatory or assurance activities
Practical experience with cyber risk assessment, risk treatment, risk acceptance, and escalation
Understanding of third-party and ICT supplier security risk
Ability to translate regulatory and security requirements into practical controls and processes
Strong stakeholder management skills and ability to work effectively with technical, business, and executive audiences
Sufficient technical understanding of cloud, infrastructure, identity, IT operations, and product development to work effectively with technical teams
Experience leading a team, function, program, or complex cross-functional initiatives
Strong ownership, prioritization, and decision-making skills
Responsibilities
Own and develop the Information Security GRC strategy, roadmap, operating model, and governance cadence
Lead security governance, regulatory assurance, cyber risk, third-party security risk, policy lifecycle, and security-awareness oversight
Establish clear ownership for security controls, risks, exceptions, evidence, and remediation actions
Coordinate SOC 2, DORA/CySEC-related assurance, internal and external audits, and regulatory requests
Maintain cyber-risk and exception registers and ensure material risks are treated, accepted, or escalated
Lead security aspects of ICT supplier tiering, due diligence, reassessment, and high-risk supplier decisions
Develop practical security policies, standards, controls, and guidance
Ensure audit and assurance evidence is reliable, traceable, and reusable
Track control gaps, findings, and remediation commitments and escalate material risks
Partner with Security, IT, Engineering, Product, Platform, Legal, and business teams on control design and risk-based decisions
Prepare concise GRC and risk reporting for the CISO and executive stakeholders
Build, develop, and manage the GRC team, including responsibilities, goals, and performance expectations
Improve GRC efficiency through automation, reusable evidence, better data quality, and responsible AI-assisted workflows
We Offer
20 paid vacation days per year
10 paid sick leave days per year
Public holidays according to company policy
Medical budget
Remote work opportunity
Professional education budget
Language learning budget
Wellness budget (gym membership, sports gear, etc.)
Posted 2026-09-10