GRC Lead — Governance, Risk & Compliance (Cybersecurity)
Be | Shaping the Future · Romania · 2026-10-04
About this role
Core Competencies
Primary Skills
• Governance, Risk & Compliance (GRC)
• GDPR
• NIS2
• ISO 27001
• Information Security Policy and Procedure Development
Secondary Skills
• NIST Cybersecurity Framework (NIST CSF)
• Privacy Management
Responsibilities
• Lead the cybersecurity governance, risk, and compliance (GRC) program, working closely with Legal, Privacy, Risk Management, and Government Affairs teams to address evolving regulatory requirements.
• Establish, implement, and continuously improve the Information Security Management System (ISMS) in accordance with ISO 27001/27002 standards.
• Develop, maintain, and enhance information security, privacy, data protection, incident response policies, standards, procedures, and governance frameworks.
• Manage an enterprise-wide cybersecurity and risk program to protect the confidentiality, integrity, and availability of information assets.
• Conduct risk assessments, facilitate risk management activities, and support business units in identifying and mitigating security and compliance risks.
• Provide subject matter expertise on global cybersecurity and privacy regulations and frameworks, including GDPR, NIS2, ISO 27001/27002, and NIST CSF.
• Perform compliance assessments, audits, gap analyses, and oversee remediation initiatives.
• Support internal and external audits, certification activities, and regulatory examinations.
• Assess security threats, vulnerabilities, and control effectiveness; communicate risks and recommendations to business and technical stakeholders.
• Align cybersecurity, privacy, and compliance initiatives with organizational objectives and business strategy.
• Lead governance and project management activities related to cybersecurity, privacy, and compliance programs.
• Evaluate and recommend security and privacy controls for new and existing technologies, applications, and infrastructure.
• Monitor emerging threats, regulatory developments, and industry best practices.
• Support organizational compliance efforts related to GDPR, NIS2, ISO 27001/27002, and NIST CSF, including compliance reporting, governance metrics, and risk dashboards.
• Promote the adoption of security and privacy-enhancing technologies that support effective privacy and compliance operations.
Originally posted on Himalayas
Skills asked for
- cybersecurity
Similar jobs
- SENIOR SERVICENOW LEAD – GRC | REMOTELeading Edge
- SENIOR GRC LEAD | RemoteLeading Edge
- Senior GRC Lead: Risk & ComplianceZania · Palo Alto
- GRC LeadVoyagertechnologiesinc · Remote - United States
- GRC LeadVoyager Technologies, Inc.
- Security Assurance & GRC LeadWispr Flow · San Francisco or New York
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.