Information Security Governance, Risk & Compliance Manager

7 hours, 19 minutes ago
Full-time
Lead
Legal
JustMarkets

JustMarkets

JustMarkets is a leading online trading platform that offers a wide range of financial instruments including Forex, CFDs, Gold, and Oil. With low spreads, high leverage up to 1:3000, and fast execution, JustMarkets provides a next-level trading experie...

Capital Markets
1-10

Description

  • Own the Information Security GRC strategy, roadmap, operating model, and governance cadence.
  • Lead security governance, regulatory assurance, cyber risk, third-party risk, policy management, and security awareness oversight.
  • Establish ownership for controls, risks, exceptions, evidence, and remediation actions.
  • Coordinate SOC 2, DORA/CySEC-related assurance, internal and external audits, and regulatory requests.
  • Maintain cyber-risk and exception registers, ensuring risks are treated, accepted, or escalated.
  • Lead ICT supplier security tiering, due diligence, reassessments, and high-risk supplier decisions.
  • Develop practical security policies, standards, controls, and guidance.
  • Track control gaps, audit findings, and remediation commitments, escalating material risks.
  • Partner with technical, business, legal, and executive stakeholders on control design and risk-based decisions.
  • Build and manage the GRC team while improving efficiency through automation, reusable evidence, data quality, and AI-assisted workflows.

Requirements

  • Practical experience in Information Security GRC, cyber or technology risk, security compliance, or assurance.
  • Hands-on experience with SOC 2, ISO 27001, DORA, PCI DSS, NIST CSF, COBIT, or similar frameworks.
  • Experience establishing or operating security controls, risk registers, exception processes, and assurance programs.
  • Strong understanding of control design, operating effectiveness, evidence quality, findings, and remediation.
  • Experience coordinating internal or external audits and regulatory or assurance activities.
  • Experience with cyber-risk assessment, risk treatment, risk acceptance, and escalation.
  • Understanding of third-party and ICT supplier security risk.
  • Ability to translate regulatory and security requirements into practical controls and processes.
  • Strong stakeholder management skills across technical, business, and executive audiences.
  • Technical understanding of cloud, infrastructure, identity, IT operations, and product development.
  • Experience leading a team, function, program, or complex cross-functional initiatives.
  • Strong ownership, prioritization, and decision-making skills.

Benefits

  • 20 paid vacation days per year.
  • 10 paid sick leave days per year.
  • Public holidays according to company policy.
  • Medical budget.
  • Remote work opportunity.
  • Professional education budget.
  • Language learning budget.
  • Wellness budget for gym memberships, sports equipment, and similar activities.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Director of Compliance (Remote)

Ennoble Care 51-250 Health Care Providers & Services

Ennoble Care is seeking a Director of Compliance to lead its hospice compliance program, overseeing regulatory strategy, audits, corrective actions, policies, investigations, and external audit responses across its multi-state home-based care operations.

7 hours, 19 minutes ago

Virginia Tech | Compliance Advisory - 2027 Summer Internship

Coalfire 251-1K Internet Software & Services

Coalfire is seeking paid Summer 2027 Compliance Advisory interns to support cybersecurity compliance assessments and advisory projects for public sector, healthcare, and GRC clients in a remote or hybrid setting.

Cybersecurity HIPAA
7 hours, 49 minutes ago

AML Analyst

Rush Street Interactive 251-1K Hotels, Restaurants & Leisure

Rush Street Interactive is seeking a remote AML Analyst to support anti-money laundering compliance, financial-crime investigations, and regulatory reporting across its online casino, sports betting, and retail gaming operations.

8 hours, 4 minutes ago

Forensic Regulatory Data Analyst

UtiliSave 11-50 Professional Services

UtiliSave is hiring a remote Forensic Regulatory Data Analyst to analyze utility billing records for commercial and industrial clients, identify recoverable savings, and pursue claims with utilities and regulators.

Agile Python
1 day, 8 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers