Posted on: 13/05/2026
Job Summary :
We are looking for a hands-on Governance, Risk, and Compliance (GRC) Manager to take ownership of our pristine ISO 27001 : 2022 ISMS, lead our expansion into new certification frameworks like ISO/IEC 42001 (AI Management System), and drive a culture of practical security.
You will not be a "template pusher." You will be a strategic partner to our IT, HR, Legal, and Delivery teams, ensuring our security and compliance controls are deeply integrated into our daily workflows without slowing down engineering innovation.
Key Responsibilities :
- Own the ISMS : Maintain, monitor, and continuously improve our highly mature ISO 27001 : 2022 framework, managing all core processes (Risk Assessments, Internal Audits, MRMs) and Annex A controls.
- Lead New Frameworks (AI Governance) : Spearhead the readiness and implementation of ISO/IEC 42001 to ensure the safe, compliant use of AI across our operations.
- Commercial Enablement : Take full ownership of answering complex Client Security Questionnaires to accelerate enterprise sales cycles.
- Vendor Risk Management : Evaluate the security posture of third-party SaaS tools and APIs before they are integrated into our ecosystem.
- Security Training & Culture : Design and run targeted internal training programs, including secure coding (SDLC), AI acceptable use policies, and anti-phishing simulations.
- AI Certification Management : Oversee technical upskilling requirements for engineering teams (e.g., tracking individual credentials like Claude Certified Architect or Google Generative AI badges) and ensure our internal practices meet AI vendor partner network compliance.
- Business Continuity (BCDR) : Build, test, and maintain robust Business Continuity and Disaster Recovery playbooks to ensure operational resilience.
- External Audit Management : Act as the primary liaison for all external certification bodies, ensuring smooth, non-disruptive surveillance and recertification audits.
- Cross-Functional Integration : Work directly with engineering and operational leaders to translate compliance requirements into practical processes. If a policy breaks a workflow, you rewrite the policy to fix it.
What We Are Looking For :
- Experience : 5+ years of dedicated GRC or Information Security experience, specifically within the IT Services, custom software development, or B2B SaaS sectors.
- Certifications : Active certification as an ISO 27001 Lead Auditor or Lead Implementer. Knowledge of ISO 42001 is a massive plus.
- Technical Literacy : A strong understanding of modern tech stacks, cloud infrastructure, and software development lifecycles (SDLC).
- The "Anti-Consultant" Mindset : You are a builder and an executor. You roll up your sleeves, draft the procedures, and help the team implement them flawlessly.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1635511