Job Summary:
The GRC Manager plays a critical role in ensuring the organization's adherence to regulatory requirements, internal policies, and industry standards. This role involves leading governance initiatives, managing enterprise risk, and overseeing compliance programs across banking operations. The ideal candidate will have deep expertise in financial regulations, risk frameworks, and security governance, with the ability to influence senior stakeholders and drive strategic compliance initiatives.
Key Responsibilities:
- Develop and maintain GRC frameworks aligned withISO 27001, NIST, COBIT, and financial regulations (e.g., Basel III, SOX, GLBA).
- Establish governance structures for risk and compliance reporting, escalation, and decision-making.
- Lead internal policy development and ensure alignment with regulatory and business requirements.
- Conduct enterprise-wide risk assessments, identify key risks, and implement mitigation strategies.
- Maintain a risk register and ensure timely updates and reporting to senior leadership.
- Collaborate with business units to embed risk-aware culture and practices.
- Ensure compliance with banking regulations including GDPR, PCI-DSS, KYC, AML, and local central bank mandates.
- Oversee periodic audits, regulatory inspections, and remediation of findings.
- Manage compliance tools and platforms (e.g., RSA Archer, ServiceNow GRC).
- Monitor and report on key risk indicators (KRIs), compliance metrics, and control effectiveness.
- Lead vulnerability management, access control reviews, and exception handling.
- Coordinate with internal teams and external regulators during incidents and investigations.
Qualifications & Experience:
- Bachelor's or Master's degree in Information Security, Risk Management, or related field.
- 5-7 years of experience in GRC roles, preferably in banking or financial services.
- Certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor, or PMP are highly desirable.
- Proven experience in managing audits, regulatory compliance, and risk frameworks.
- Strong leadership, analytical, and communicationskills.
Preferred Tools & Technologies:
- GRC Platforms: RSA Archer, MetricStream, ServiceNow GRC
- Risk & Compliance Tools: Qualys, Nessus, Splunk, SIEM
- Regulatory Knowledge: Basel III, GDPR, SOX, GLBA, PCI-DSS