Senior Risk Management GRC Manager
Summary
Leads zerohash’s European security, governance, risk, and compliance programs, focusing on DORA, ISO 27001, SOC 1/2, and technical risk mitigation across IT infrastructure.
You will develop, implement, and maintain zerohash’s security, governance, risk management, and compliance programs in Europe, with a focus on DORA compliance. You will manage technical security controls, assess and mitigate IT risks, oversee incidents, maintain policies, and report to senior management and the board.
Responsibilities
- Manage the company’s compliance with DORA
- Monitor laws, regulations, and industry standards related to IT security and compliance
- Manage technical compliance programs and initiatives
- Conduct compliance assessments and prepare audit documentation
- Develop and maintain governance policies, procedures, standards, and frameworks
- Manage ISO 27001, SOC 1, and SOC 2 governance frameworks
- Coordinate governance committees and technical committees
- Develop and implement IT security strategies and solutions
- Manage and monitor firewalls, intrusion detection systems, and endpoint protection
- Conduct security assessments, vulnerability scans, and penetration tests
- Respond to security incidents and conduct forensic investigations and root cause analysis
- Identify, assess, prioritize, and mitigate technical risks
- Monitor risk mitigation activities and control effectiveness
- Develop and enforce technical security policies and procedures
- Oversee technical incident management and corrective actions
- Deliver security, governance, risk, and compliance training
- Collaborate with auditors, regulators, and technical teams
- Present security, governance, risk, and compliance reports to senior management and the board
Requirements
- Experience in a Risk Management or GRC leadership role
- Experience with the Digital Operational Resilience Act
- Technical IT security, governance, risk management, and compliance experience
- Knowledge of IT governance frameworks, regulatory requirements, and best practices
- Experience with SOC 1, SOC 2, and ISO 27001
- Strong analytical and problem-solving skills
- Ability to manage multiple technical projects and priorities
- Experience with technical security and GRC tools and software
- Excellent communication and interpersonal skills
- Proficiency in risk assessment methodologies and tools
- Experience with IT audit processes and procedures
- Knowledge of GDPR and NYDFS Part 500
Benefits
- Chance to earn equity
- Maternity and paternity leave
- WeWork Membership
- WFH yearly stipend
- L&D stipend