Information Security Officer
Core
Own company-wide security governance, policy, and compliance agenda; act as internal authority on standards and regulations.
Role type
Information Security Officer (GRC)
Builds
Security policy frameworks, compliance strategies, and awareness training programs.
Domain
Cybersecurity, Governance, Risk, and Compliance (GRC)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Information security governance, risk and compliance (GRC), ISO 27001, GDPR, security policy framework ownership, security awareness training program management, GRC platform operation, internal and external audit coordination, stakeholder management, reporting to senior leadership and boards
Preferred skills
CISM, CISA, ISO 27001 Lead Implementer/Auditor, CISSP, data-protection and PII program experience, fast-scaling technology, gaming, or fintech organization experience
Technologies
GRC platforms
Responsibilities
Own and maintain the company-wide information security policy framework; update and drive the security compliance strategy; design and deliver security awareness and training programmes; drive compliance adoption across all business units; track and report on policy exceptions and remediation progress; own the PII compliance plan; coordinate with external auditors and manage evidence collection; provide regular compliance reporting to leadership, the Board and the Risk Committee
Seniority
Mid-Senior, hands-on IC