GRC Lead – Information Security Risk Management
Salmon Group Ltd · Tbilissi
Job description
About the role
You'll own information security risk management, control assurance, and ISO 27001 ISMS governance across a regulated group spanning banking, consumer finance, and technology. The role reports directly to the Group CISO and works across IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure development.
Key responsibilities
- Form an independent view of security risk and challenge proposed controls, working directly with the Group CISO.
- Assess control design and operating effectiveness across IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure development.
- Turn risk and control data into clear, decision‑ready reporting for governance forums.
- Own the end‑to‑end security risk process: assessment, treatment, acceptance, monitoring, and reporting.
- Maintain the risk register, security control framework, and ISO 27001 ISMS artifacts (policies, SoA, risk records, control evidence, exceptions).
- Track control deficiencies, findings, exceptions, and remediation actions; define KRIs and control metrics.
Required profile
- Strong practical experience in information security risk management, including inherent and residual risk, treatment, acceptance, and control effectiveness.
- Enough technical depth to critically assess controls across IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure development.
- Hands‑on experience reviewing or testing controls, distinguishing documented controls from effective ones.
- Working knowledge of ISO 27001 and ability to translate complex risk information into concise management reporting.
- Comfort with GRC platforms, structured risk and control registers, and evidence management.
Required skills
- Information security risk management
- Identity and Access Management (IAM)
- Cloud security
- Endpoint security
- Security monitoring
- Vulnerability management
- Data protection
- Secure software development
- ISO 27001
- GRC platforms
What we offer
- Ownership and flexibility with fully remote work (core hours 12:00‑18:00 Manila time).
- Company‑provided tools and equipment.
- Health and time‑off benefits, including medical insurance support for you and your family.
- 22 vacation days, Philippine public holidays, and 15 sick days.
- Learning opportunities through internal meetups, external conferences, and speaking engagements.
- Company‑sponsored trips to Manila to meet the team in person.
- High‑performing teams can earn a dedicated beach‑house week in Southeast Asia.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in the Philippines.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 4 days ago
Expires 1 month from now
18 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Salmon Group Ltd
Tbilissi