Jobiglo

No results.

GRC Lead – Information Security Risk Management

Salmon Group Ltd · Manila

New Remote
Remote 🇬🇧 English
Endpoint security Vulnerability management Data protection GRC platforms

Job description

About the role

You will own information security risk management, control assurance, and ISO 27001 ISMS governance across a regulated group that includes banking, consumer finance, and technology.

Key responsibilities

  • Form an independent view of security risk and challenge proposed controls, working directly with the Group CISO.
  • Assess control design and operating effectiveness across IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure development.
  • Turn risk and control data into clear, decision‑ready reporting for governance forums.
  • Own the security risk process end‑to‑end: assessment, treatment, acceptance, monitoring, and reporting.
  • Maintain the risk register, challenge assessments, and ensure residual risk, ownership, and remediation status stay current.
  • Maintain the security control framework, test controls using evidence, data, sampling, or technical validation, and drive remediation with control owners.
  • Maintain the ISO 27001 ISMS, including policies, standards, Statement of Applicability, risk records, control evidence, exceptions, and key security registers.
  • Track control deficiencies, findings, exceptions, and remediation actions; define KRIs and control metrics and flag needed escalations.

Required profile

  • Strong practical experience in information security risk management, including inherent and residual risk, treatment, acceptance, and control effectiveness.
  • Ability to critically assess controls across IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure development.
  • Hands‑on experience reviewing or testing controls and distinguishing documented controls from effective ones.
  • Working knowledge of ISO 27001 and ability to translate complex risk information into concise management reporting.
  • Comfortable using GRC platforms, structured risk and control registers, and evidence management.

Required skills

  • Identity and Access Management (IAM)
  • Cloud security
  • Endpoint security
  • Security monitoring
  • Vulnerability management
  • Data protection
  • Secure software development
  • ISO 27001 governance
  • GRC platforms (risk and control registers)

What we offer

  • Ownership and flexibility with fully remote work; core collaboration hours 12:00–18:00 Manila time (UTC+8).
  • Company‑provided tools and equipment.
  • Medical insurance support for you and your family (co‑funded or reimbursed, subject to policy limits).
  • Access to an internal mental‑health support specialist.
  • 22 vacation days, Philippine public holidays, and 15 sick days.
  • Opportunities to learn through internal meetups, external conferences, speaking engagements, and industry publications.
  • Company‑sponsored trips to Manila to meet the team in person.
  • High‑performing teams can earn a dedicated beach‑house week in Southeast Asia.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Salmon Group Ltd.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in the Philippines.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 4 days ago

Expires 1 month from now

16 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Salmon Group Ltd

Manila