
Job description
Job Description – Security Governance & Risk Leader Position Title Security Governance, Risk & Compliance (GRC) Leader Department Information Security / Technology Reports To Chief Information Security Officer (CISO) / Chief Information Officer (CIO)/VP IT infrastructure and Information security Position Summary The Security Governance, Risk & Compliance (GRC) Leader is responsible for establishing and maintaining a robust security governance framework that aligns cybersecurity initiatives with organizational objectives, regulatory requirements, and industry best practices.
This role provides strategic leadership for information security governance, risk management, compliance, policy administration, audit readiness, and security oversight across the enterprise. The incumbent will work closely with executive leadership, business stakeholders, IT teams, auditors, regulators, and third-party partners to ensure that security risks are effectively managed, compliance obligations are met, and security controls support business growth while protecting organizational assets.
Key Responsibilities
- Security Governance & Strategy Develop and implement enterprise-wide cybersecurity governance frameworks aligned with business objectives and regulatory requirements. Define, maintain, and enforce information security policies, standards, procedures, and guidelines. Establish governance structures, security committees, and reporting mechanisms to support security oversight. Partner with executive leadership to align security strategy with organizational goals and risk appetite. Develop security roadmaps and maturity improvement programs based on industry frameworks and emerging threats. Present security governance updates, risk posture, and compliance status to executive management and board committees.
- Security Risk Management & Compliance Establish and maintain an enterprise information security risk management framework. Identify, assess, monitor, and mitigate cybersecurity risks affecting business operations and technology environments. Maintain security risk registers and track remediation activities to closure. Ensure compliance with applicable regulatory, legal, and contractual requirements, including: ISO 27001 NIST Cybersecurity Framework GDPR HIPAA PCI-DSS SOX RBI and other regional regulatory requirements Conduct compliance assessments and readiness reviews for certifications and audits. Collaborate with business units to implement risk treatment and control improvement plans.
- Security Controls & Policy Management Design, implement, and monitor security control frameworks across infrastructure, applications, cloud platforms, and business processes. Oversee periodic review and enhancement of security policies and procedures. Ensure organization-wide awareness and adherence to security standards. Lead control testing, effectiveness evaluations, and compliance validation activities. Monitor key security controls including: Identity and Access Management (IAM) Privileged Access Management (PAM) Change Management Data Protection Endpoint Security Cloud Security Controls Business Continuity and Disaster Recovery
- Information Security Governance & Security Oversight Collaborate with the CISO and security operations teams to drive cybersecurity governance initiatives. Monitor compliance with internal security standards and industry best practices. Oversee security assessment programs including: Vulnerability Assessments Penetration Testing Security Architecture Reviews Cybersecurity Maturity Assessments Support security incident management and crisis response governance processes. Review threat intelligence, emerging risks, and cybersecurity trends to strengthen organizational resilience. Ensure periodic reporting of security metrics, risks, incidents, and remediation activities.
- Security Program & Operational Governance Establish governance frameworks for security initiatives, projects, and transformation programs. Oversee security budgeting, planning, and resource prioritization. Monitor vendor security performance and third-party risk management programs. Ensure security requirements are integrated into technology projects and procurement processes. Track security KPIs, KRIs, and service-level metrics to drive continuous improvement. Evaluate effectiveness of security investments and governance programs.
- Audit Management & Regulatory Coordination Act as the primary liaison for internal and external security audits. Coordinate audit planning, evidence collection, and stakeholder engagement activities. Review audit findings and develop remediation plans. Ensure timely closure of audit observations and compliance gaps. Support regulatory examinations and customer security assessments. Maintain documentation required for compliance certifications and governance reviews.
- Stakeholder Management & Leadership Serve as the key liaison between Information Security, IT, Risk, Legal, Compliance, Audit, and Business Units. Build strong relationships with executive leadership and business stakeholders. Promote a culture of security awareness, accountability, and compliance throughout the organization. Lead and mentor governance, risk, and compliance teams. Drive security training, awareness, and communication initiatives across the enterprise. Provide strategic recommendations to leadership regarding security investments, risk mitigation, and governance improvements.
Requirements
Qualifications & Experience Education Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related discipline. Master's Degree (MBA, MS Information Security, or equivalent) preferred. Experience 12+ years of experience in Information Security, IT Governance, Risk Management, Audit, or Compliance.
Minimum 5+ years in a leadership or management role within Security Governance, Risk, and Compliance. Proven experience implementing and managing enterprise security governance frameworks. Hands-on experience managing security audits, risk assessments, compliance programs, and security control frameworks. Strong understanding of enterprise technology environments, cloud security, cybersecurity operations, and regulatory requirements.
Preferred Certifications Certified Information Security Manager (CISM) Certified Information Systems Auditor (CISA) Certified in Risk and Information Systems Control (CRISC) Certified Information Systems Security Professional (CISSP) COBIT Foundation / Design & Implementation ISO 27001 Lead Auditor or Lead Implementer ITIL Foundation or Expert Certified Cloud Security Professional (CCSP) – Preferred Key Competencies Leadership & Strategy Strategic thinking and business alignment Executive presence and influencing skills Decision-making and governance leadership Risk & Compliance Security risk assessment and mitigation Regulatory compliance management Control design and validation Technical Knowledge Information security frameworks and standards Cybersecurity governance and operations Cloud security and data protection Communication & Collaboration Stakeholder management Board and executive reporting Negotiation and conflict resolution Presentation and communication excellence Operational Excellence Program and project governance Process improvement and optimization Performance measurement and reporting Key Performance Indicators (KPIs) Governance & Compliance Audit compliance score Number of repeat audit findings Timely closure of audit observations Regulatory compliance adherence rate Risk Management Reduction in high-risk findings Risk remediation closure percentage Security control effectiveness scores Risk assessment completion rates Security Program Effectiveness Security maturity assessment improvement Security policy compliance rate Third-party risk assessment completion rate Vulnerability remediation performance Operational Metrics SLA adherence for security governance activities Budget utilization and optimization Security project delivery success rate Service delivery performance metrics Stakeholder Satisfaction Business stakeholder satisfaction score Executive reporting effectiveness Security awareness adoption metrics Alignment of security initiatives with business objectives Job Level: Senior Manager / Director / Head of Information Security Governance & Risk Management