Senior Risk Management / GRC Manager
The Governance, Risk and Compliance Manager will develop, implement, and maintain zerohash’s security, governance, risk management, and compliance programs within the European Risk Function, with a particular focus on DORA compliance.
Responsibilities
- Manage compliance with DORA and other applicable laws, regulations, and industry standards.
- Manage technical compliance programs, assessments, reports, and audit documentation.
- Develop and maintain governance policies, procedures, standards, and frameworks.
- Manage ISO 27001, SOC 1, and SOC 2 governance frameworks.
- Coordinate governance committees and technical committees.
- Develop and implement IT security strategies and solutions.
- Manage firewalls, intrusion detection systems, and endpoint protection.
- Conduct security assessments, vulnerability scans, and penetration tests.
- Respond to security incidents and conduct forensic investigations and root-cause analysis.
- Identify, assess, prioritize, and mitigate technical risks.
- Develop and enforce technical security policies and procedures.
- Oversee technical incident management and corrective actions.
- Deliver security, governance, risk, and compliance training.
- Collaborate with auditors, regulators, and technical teams.
- Present security, governance, risk, and compliance reports to senior management and the board.
Requirements
- Prior experience in a Risk Management or GRC leadership role.
- Prior experience with the Digital Operational Resilience Act (DORA).
- Professional certifications such as CISSP, CISM, CRISC, or CISA are a plus.
- Proven experience in technical IT security, governance, risk management, and compliance.
- Strong knowledge of IT governance frameworks, regulatory requirements, and best practices.
- Experience with SOC 1, SOC 2, and ISO 27001 is strongly preferred.
- Strong analytical and problem-solving skills with attention to detail.
- Ability to manage multiple technical projects and priorities.
- Experience with technical security and GRC tools and software.
- Excellent communication and interpersonal skills.
- Proficiency in risk assessment methodologies and tools.
- Experience with IT audit processes and procedures.
- Knowledge of GDPR and NYDFS Part 500 is a plus.
Benefits
- Chance to earn equity
- Maternity and paternity leave
- WeWork Membership
- WFH yearly stipend
- L&D stipend after 6 months