At a Glance
- Tasks: Lead a dynamic team in Governance, Risk Management & Compliance to ensure security and regulatory adherence.
- Company: Join monday.com, a fast-growing SaaS company committed to innovation and security excellence.
- Benefits: Enjoy a collaborative work environment, professional development opportunities, and a commitment to diversity and inclusion.
- Why this job: Be a key player in shaping security strategies while empowering your team and driving impactful change.
- Qualifications: 5+ years in GRC roles with leadership experience; strong knowledge of industry standards like ISO and GDPR.
- Other info: We value equal opportunity and encourage diverse candidates to apply for a workplace free of discrimination.
The predicted salary is between 72000 - 108000 £ per year.
We are looking for a highly skilled, motivated and experienced global Head of GRC (Governance, Risk Management & Compliance) to join us!
This role will own the GRC domain, lead a boutique team and play a key position in the Security Leadership group (reporting to the CISO) and its vision for the company’s scale. The role includes work with different levels of seniority from various domains and will possess strong capabilities of collaborative work and communication skills.
This is a unique opportunity to play a pivotal role in ensuring that our organization adheres to regulatory requirements, industry standards and best practices while effectively managing risks associated with the security operations, especially in light of our fast growth and readiness for scale.
About The Role
- Leadership : Lead the team, develop and empower the team’s personnel (e.g. crafting a PDP – Personal Development Plan), alongside planning the team’s vision, budget, OKRs, annual work plan (consisting of both innovation and operations activities) and additional duties as needed.
- Governance : Review, update, and execute policies, procedures, and ceremonies to ensure alignment with global regulations, compliance programs and customer requirements.
- Risk Management : Managing the company’s comprehensive security risks, including incident response procedures and activities, resilience status, risk assessments and remediation plans, considering global threats as well as internal business changes and demands.
- Compliance : Manage monday.com’s compliance domain, ensuring compliance with current certifications (e.g. ISO, SOC), while extending the compliance suite based on business impact.
- Third Party Risk Management : Responsible for the vendor assessment program, for both ongoing processes and new initiatives for improving efficiency.
- Employees Education : Lead the monday.com’s security awareness & training program for employees in general and for specific departments (e.g. customer facing, R&D).
- Customer Enablement : The main point of contact for customers regarding security inquiries, including managing top-tier customer calls, legal agreements and questionnaires. In parallel, create customer-facing materials to enhance customer understanding of monday.com’s security posture.
Your Experience & Skills
- Minimum of 5 years of experience in GRC roles, with at least 2 years in leading teams, preferably in SaaS companies of 500+ employees.
- Strong understanding and practical experience of industry standards and frameworks such as ISO 27001, SOC2, NIST, GDPR, HIPAA.
- Legal background – an advantage.
- Advanced knowledge of risk assessment methodologies, controls implementation, incident response management, vendor assessment, awareness initiatives, and compliance monitoring.
- Ability to assess and communicate effectively security and privacy risks to technical and non-technical stakeholders of different seniority.
- Proven track record of successfully leading and managing teams, including strong decision-making and problem-solving skills, and ability to foster a collaborative and inclusive work environment.
- Excellent verbal and written communication skills in English and Hebrew, and ability to communicate complex concepts in a clear manner.
- Strong analytical and critical thinking skills to identify risks, gaps, and areas of improvement in existing processes and create strategies for mitigating risks effectively.
- Demonstrated ability to handle multiple tasks, prioritize effectively, and meet deadlines in a dynamic and fast-paced environment.
We believe in equal opportunity.
monday.com is an equal opportunity employer and bans discrimination and harassment of any kind. monday.com is committed to the standard of equal employment opportunity for all employees and to creating and maintaining a workplace free of discrimination and harassment.
All qualified applicants will be considered for employment regardless of any personal characteristic. We encourage candidates from all backgrounds to apply, regardless of their race, religion, national origin, ethnicity, sexual orientation, gender identity, age, marital status, family or parental status, physical or mental disability or any other status protected by the laws or regulations in the locations where monday.com operates.
monday.com is committed to working with and providing access and reasonable accommodation to applicants with any disabilities. If you think you may require accommodation for any part of the recruitment process, please send a request to
All requests for accommodation are treated confidentially, as practical and permitted by law.
Meet the Security Team
We are responsible for providing our customers, employees, and management with best-in-class security in order to promote our business goals and company growth.
#J-18808-Ljbffr
Head of GRC - London employer: monday.com
Contact Detail:
monday.com Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Head of GRC - London
✨Tip Number 1
Make sure to familiarize yourself with the specific GRC frameworks and standards mentioned in the job description, such as ISO 27001 and SOC2. Being able to discuss these frameworks in detail during your interview will demonstrate your expertise and readiness for the role.
✨Tip Number 2
Highlight your leadership experience by preparing examples of how you've successfully led teams in the past. Be ready to discuss your approach to team development and empowerment, as this is a key aspect of the role.
✨Tip Number 3
Since communication is crucial for this position, practice articulating complex security concepts in a clear and concise manner. You might want to prepare a few scenarios where you effectively communicated risks to both technical and non-technical stakeholders.
✨Tip Number 4
Research monday.com’s current security posture and any recent developments in their compliance efforts. This knowledge will not only help you understand the company better but also allow you to ask insightful questions during your interview.
We think you need these skills to ace Head of GRC - London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights your experience in Governance, Risk Management, and Compliance (GRC). Focus on your leadership roles and any specific achievements related to security operations, compliance certifications, and team management.
Craft a Compelling Cover Letter: In your cover letter, emphasize your understanding of industry standards like ISO 27001 and SOC2. Discuss your approach to risk management and how you have successfully led teams in previous roles, showcasing your communication skills and collaborative work style.
Showcase Relevant Experience: When detailing your work history, highlight specific projects or initiatives where you managed compliance programs or improved security processes. Use metrics to demonstrate the impact of your contributions, such as reduced incident response times or successful audits.
Prepare for Behavioral Questions: Anticipate questions about your leadership style and problem-solving abilities. Be ready to provide examples of how you've fostered a collaborative environment and handled challenges in fast-paced settings, particularly in relation to GRC.
How to prepare for a job interview at monday.com
✨Showcase Your Leadership Skills
As a Head of GRC, you'll be leading a team. Be prepared to discuss your leadership style and provide examples of how you've developed and empowered your team in the past. Highlight any Personal Development Plans (PDPs) you've crafted and how they benefited your team.
✨Demonstrate Your Knowledge of Compliance Standards
Familiarize yourself with key industry standards such as ISO 27001, SOC2, NIST, GDPR, and HIPAA. Be ready to discuss how you've implemented these frameworks in previous roles and how you plan to ensure compliance at monday.com.
✨Communicate Effectively with Diverse Stakeholders
You will need to communicate complex security concepts to both technical and non-technical stakeholders. Prepare to share examples of how you've successfully conveyed critical information to different audiences and how you adapt your communication style accordingly.
✨Prepare for Scenario-Based Questions
Expect questions that assess your problem-solving skills and ability to manage risks. Think of specific scenarios where you've identified risks, implemented controls, or handled incidents, and be ready to explain your thought process and the outcomes.