IT GRC Manager - Digital Identity
Summary
The IT GRC Manager leads the development of governance, risk, and compliance frameworks for identity and lending services. Key responsibilities include driving ISO 27001 and ISO 27701 certifications, managing regulatory audits, and collaborating with engineering and legal teams to implement security controls and IT policies.
What You Will Do
-
Coordinating with the compliance team to ensure that every initiative, development, and collaboration complies with the standards and regulations (internal and external);
-
Conduct routine evaluation of policies and procedures implementation and ensure best-practice risk mitigation and assessment functions are maintained to comply with the company's strategy;
-
Act as a Subject Matter Expert to the stakeholders and provide relevant & applicable consultation for addressing the IT GRC requirement in lending & identity product & services;
-
Ensure effective governance, risk management, and compliance across the organization;
-
Develop and maintain compliance, governance, and risk-related IT and business process flow;
-
Coordinate with related IT work units to follow up on data requests and internal audit findings, external audits, and regulators;
-
Develop the process and conduct the activities to safeguard or archive every IT development document regularly;
-
Implement a good governance organization using ISO27001, ISO 27701, and other relevant Technology & Security best practices.
What You Will Need
- Minimum of 5 years of experience in IT governance, risk management, and compliance;
- Having excellent experience with PSrE, ISO 27001, ISO27701, ITIL, and COBIT;
-
Proven track record of successfully leading and achieving certifications such as ISO 27001 and ISO 27701;
-
Excellent stakeholder management skills, with the ability to communicate and influence at all levels of the organization;
-
Demonstrated ability to deliver results with limited resources and minimal supervision;
-
Extensive experience in managing and navigating regulatory audits and ensuring compliance with industry standards;
-
Strong leadership skills with the ability to effectively lead a small team and foster a collaborative work environment;
-
Strong adaptability and flexibility to take on new areas of responsibility and lead new functions, while effectively leveraging existing skills, knowledge, and experience;
- One or more of the following or equivalent certifications preferred: CISA, CISM, CRISC, ITIL, COBIT, and ISO 27001 LA is preferred.
-
Engineering & Tech: You’ll partner with our engineers to ensure that security controls are "baked in" to our lending and identity platforms from day one.
-
Legal & Regulatory: You’ll work alongside our compliance experts to translate complex financial laws into clear, actionable IT policies.
-
People & Partner Teams: You’ll collaborate to foster a company-wide culture of security, ensuring that every employee and third-party partner understands their role in protecting our ecosystem.
Skills
As published by lever · 3 questions
Basics
Resume/CV, Full name, Email, Phone, Current location, Current company, LinkedIn URL, GitHub URL, Portfolio URL, What gender do you identify as?
Short answers (1)
- What is your current salary package in gross?
Pick from a list (2)
- Are you eligible to work in the country where this job is located? optional
- By submitting this application, you hereby declare and confirm that all personal data and information provided above ("Personal Data") is true, accurate, and complete. You also consent GoTo to process your Personal Data for purposes related to managing your job application, including but not limited to evaluating your application for the role you applied or for other roles we consider suitable for you within the GoTo Group, communicating with you during recruitment process, conducting background checks, verifying information, scheduling interviews, making hiring decisions, and, where applicable, extending an offer of employment. Your Personal Data will not be shared or disclosed to external parties without your prior consent, unless otherwise required by law, and will be retained only as long as necessary to achieve the purpose for which it was collected or as permitted under applicable laws. optional