Governance Risk and Compliance Manager

Governance Risk and Compliance Manager

Full-Time No working from home possible
P

Role Overview

The Governance, Risk, and Compliance (GRC) Manager is responsible for developing, implementing, and maintaining the organisation's governance, risk management, and compliance frameworks. This role ensures that business operations comply with applicable laws, regulations, industry standards, and internal policies while proactively identifying and mitigating organisational risks.

Key Accountabilities / Responsibilities:

• Develop, implement, and manage the organisation's GRC strategy, policies, and procedures.
• Conduct enterprise risk assessments and maintain the organisation's risk register.
• Identify, assess, and monitor operational, regulatory, cybersecurity, financial, and third-party risks.
• Ensure compliance with applicable regulations, legal requirements, and industry standards.
• Coordinate internal and external audits and manage remediation of audit findings.
• Develop and maintain compliance monitoring and reporting mechanisms.
• Collaborate with business units to implement effective risk mitigation controls.
• Monitor changes in regulatory requirements and assess their impact on the organisation.
• Prepare and present risk and compliance reports to senior management and executive leadership.
• Lead awareness and training programs on governance, risk management, and compliance.
• Manage policy development, review, approval, and periodic updates.
• Support business continuity, disaster recovery, and information security governance initiatives.
• Evaluate third-party/vendor risks and oversee due diligence activities.
• Drive continuous improvement of the GRC framework through metrics, reporting, and best practices.

Skills, Knowledge, and Experiences:

Essential
• Hold valid security clearance or be eligible undergo the process to achieve the desired level of security clearance which includes the highest level.
• 5-10 years of experience in Governance, Risk, Compliance, Audit, Information Security, or related disciplines
• Strong knowledge of risk management frameworks and regulatory compliance requirements.
• Experience with enterprise risk management, internal controls, and audit processes.
• Excellent analytical, problem-solving, communication, and stakeholder management skills.
• Experience with GRC platforms and risk management tools.
• Experience with GDPR regulations and compliance. (ROPA, LIA and DPIA).

Desirable
• Experience with Defence Cyber Certification (DCC)
• Eperience with CE and CE+ certification.
• Experience with Secure by Design (SbD) and JSP 453 Assurance activity.
• Understanding of Vendor risk management
• Understanding of SOC2
• Knowledge of NIS2
• Experience as a Crypto Custodian or an Alternate Custodian

Preferred Certifications
• Certified Information Systems Auditor (CISA)
• Certified in Risk and Information Systems Control (CRISC)
• Certified Information Security Manager (CISM)
• Certified Information Systems Security Professional (CISSP)

Compliance with Company Policies, Procedures and Rules
A condition of Employment as an Employee shall be, at all times, to comply with all Policies, Procedures and Rules of the Company, which include, but are not limited to: the Prolinx Integrated Management System (IMS) Manual, Prolinx Information Security Management System (ISMS) Manual and includes all Policies, Procedures and Rules specified in the Company’s Employee Handbook.

Equal Opportunities
Prolinx does not discriminate on the basis of race, religion, colour, sex, age, disability or sexual orientation. All recruitment decisions are based solely on qualifications, skills, knowledge and experience and relevant business requirements.

The Job Holder will understand the regulatory, fair trading and competition rules relating to their work sufficiently to be able to comply with them, relying on their knowledge or on their ability to recognise that they will need specialist support.

The Job Holder will actively support at all times company policy and best practice in the area of security, with particular emphasis on the protection of sensitive customer information. This includes the Security requirements of our customers.

Governance Risk and Compliance Manager employer: Prolinx

Prolinx is an exceptional employer that prioritises employee growth and development, offering a dynamic work culture where teamwork and innovation thrive. As a Shift Leader Service Desk Support Engineer, you will benefit from a supportive environment that encourages continuous learning and provides opportunities for career advancement, all while working in a fast-paced, customer-focused setting that values flexibility and a positive attitude.

P

Contact Details:

Prolinx Recruitment Team