





Niche GRC role requiring ISO27001 and financial-services experience reduces applicant density.
Strong GRC, ISO27001 and financial services emphasis limits cross-industry transferability.
Explicit 8–10 years, ISO27001 lead certification and FS regulatory experience mandate strict filters.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Own the lifecycle management of information security policies, standards, and frameworks ensuring alignment with business and regulatory requirements.
Lead ISO 27001 certification and recertification activities, including audit coordination and maintenance of certification evidence.
Own and continuously improve enterprise information security risk management and lead responses to client security questionnaires, regulatory enquiries, and third-party risk assessments.
8 to 10 years experience in Governance, Risk & Compliance, Information Security, Audit or Risk Management, preferably in financial services.
Bachelor’s degree or equivalent experience.
ISO27001 Lead Implementer / Auditor with demonstrable experience leading certification and recertification programs in large complex organizations.
Proven experience designing and maintaining enterprise risk management frameworks.
Experienced in managing client assurance activities, including security questionnaires and Right-to-Audit engagements with regulated financial institutions.
Strong knowledge of ISO 27001, ISO 31000, ISO 27005, ISO 22301, ISO 42001, NIST Cybersecurity Framework, SOC1/SOC2, GDPR, DORA, and NIS2 frameworks.
Capable of presenting risk and compliance information to senior stakeholders and executive leadership effectively.