Senior Manager, Information Security GRC
Core
Owns the strategy, execution, and continuous improvement of the Global Information Security Governance, Risk, and Compliance (GRC) program, building internal team capability and directing third-party partners.
Role type
Senior Manager, Information Security GRC
Builds
Enterprise security risk management program, GRC function, compliance frameworks, and AI governance practices.
Domain
Real Estate / Information Security / Risk Management
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Enterprise risk management program ownership, Third-party risk management, Security frameworks (ISO 27001, SOC 2, NIST 800-53, GDPR), Cloud risk (AWS, GCP, Azure), AI governance (ISO 42001, NIST AI RMF), GRC platforms (Hyperproof, OneTrust, Archer), People management, Audit response, Security awareness program design
Preferred skills
Industry certifications (CRISC, CISA, CISSP, CISM, CCSK)
Technologies
Hyperproof, OneTrust, Archer, AWS, GCP, Azure
Responsibilities
Set GRC program roadmap and strategy, Advise senior leadership on enterprise security risk posture, Own information security policy framework development and enforcement, Lead enterprise information security risk management and risk register, Oversee third-party risk management program including vendor due diligence, Oversee responses to client, regulator, and internal audit requests, Own enterprise security awareness program including phishing simulations
Seniority
Senior, hands-on IC with people management