GRC Lead – Information Security Risk Management
Salmon Group Ltd
Job description
About the role
You will own information security risk management, control assurance, and ISO 27001 ISMS governance for a regulated group that spans banking, consumer finance, and technology. The role works closely with the Group CISO to ensure that security controls are effective and aligned with business risk appetite.
Key responsibilities
- Form an independent view of security risk and challenge proposed controls, collaborating directly with the Group CISO.
- Assess control design and operating effectiveness across IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure development.
- Turn risk and control data into clear, decision‑ready reporting for governance forums.
- Own the end‑to‑end security risk process: assessment, treatment, acceptance, monitoring, and reporting.
- Maintain the risk register, control framework, and ISO 27001 ISMS documentation, driving remediation with control owners.
- Define KRIs and control metrics, flagging issues that require management escalation.
Required profile
- Strong practical experience in information security risk management, including inherent and residual risk, treatment, acceptance, and control effectiveness.
- Technical depth to critically assess controls across IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure development.
- Hands‑on experience reviewing or testing controls, distinguishing documented controls from truly effective ones.
- Working knowledge of ISO 27001 and ability to translate complex risk information into concise management reports.
- Comfortable using GRC platforms, structured risk and control registers, and evidence management tools.
Required skills
- IAM
- Cloud security
- Endpoint security
- Monitoring
- Vulnerability management
- Data protection
- Secure development
- ISO 27001
- GRC platforms
What we offer
- Fully remote work with core collaboration hours from 12:00 PM to 6:00 PM Manila time (UTC+8).
- Company‑provided tools and equipment.
- Medical insurance support for you and your family through co‑funding or reimbursement.
- Access to an internal mental‑health support specialist.
- 22 vacation days, Philippine public holidays, and 15 sick days.
- Opportunities to learn and share expertise via internal meetups, external conferences, and industry publications.
- Company‑sponsored trips to Manila to meet the team in person.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in the Philippines.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 1 hour ago
Expires 1 month from now
5 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Salmon Group Ltd