freehire launches on Product Hunt on 26 August.

Follow →

Manager Governance Risk And Compliance

Open 45d

Job description

Establishes the cyber security governance framework, including policies and standards, to ensure all organizational operations align with legal and regulatory requirements.
Directs the enterprise cyber risk management program to identify, analyze, and monitor threats in support of business objectives.
Governs the enterprise cyber risk register and remediation plans to ensure all identified risks are treated effectively and documented.
Leads formal compliance programs, including PCI DSS, ISO/IEC 27001, and SOC2, to protect sensitive financial data and payment systems.
Manages internal and external audit cycles, including certification and surveillance audits, to maintain valid security credentials and industry standing.
Develops Key Risk Indicators (KRIs) and security metrics to provide executive leadership and the board with clear visibility into the organization’s risk posture.
Oversees third-party and vendor cyber security risk management to ensure the security integrity of the external supply chain.
Standardizes security awareness and compliance training programs to foster a risk-aware culture across the organization.
Administers policy exceptions and risk acceptance processes to maintain control effectiveness and transparency in governance.
Acts as the primary liaison for regulators, banks, and auditors to facilitate due diligence requests and regulatory reporting.

Skills description

Interpersonal skills
• Strong leadership and team management skills.
• Ability to communicate complex cyber risks in business terms to executives.
• Strong stakeholder engagement and cross-functional collaboration.
• Strategic thinking and governance mindset.
• Strong documentation, reporting, and presentation skills.
• High ethical standards and professional integrity.

Technical skills
• Strong knowledge of fintech and payment security requirements.
• Deep expertise in security frameworks including ISO 27001/27002, NIST CSF, and CIS Controls.
• Strong working knowledge of PCI DSS requirements and cardholder data protection.
• Experience implementing and maintaining SOC 2 controls and audit readiness.
• Understanding of cloud security controls across AWS, Azure, or GCP.
• Experience with enterprise risk management methodologies.
• Familiarity with security architecture, IAM, vulnerability management, and security monitoring controls.
• Experience using GRC tools for risk and compliance management.

Professional experience
• 7+ years of experience in Governance, Risk & Compliance roles.
• Minimum 5 years managing SOC or security operations teams.

Management experience
3-4 years

Educational background
• Bachelor’s degree in Cyber Security, Computer Science, Information Technology or related field.
• Relevant certifications may include:
?o CISSP – Certified Information Systems Security Professional
?o CISM – Certified Information Security Manager
?o CRISC – Certified in Risk and Information Systems Control
?o CISA – Certified Information Systems Auditor
?o PCI ISA, PCI QSA (preferred for payment environments)
?o ISO 27001 Lead Implementer or Lead Auditor

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available