Responsibilities
- Maintain and enhance the organization's information security, governance, and compliance framework continuously.
- Ensure policies, procedures, and standards are current, approved, version-controlled, accessible, and aligned with ISO 27001 and legal, regulatory, and contractual requirements.
- Support governance forums including management reviews, steering committees, and risk or compliance meetings.
- Clarify and assign roles, responsibilities, and accountability for controls across departments.
- Help develop governance tools that give leadership insight into compliance status, control performance, and major risks.
- Manage and maintain the central risk register covering enterprise, operational, project, and technology risks.
- Ensure risks are consistently identified, assessed using a defined method, assigned to owners, and tracked through resolution or acceptance.
- Lead risk workshops and risk assessment sessions with departments and key stakeholders.
- Track risk treatment plans and escalate overdue or ineffective actions as needed.
- Ensure risks, incidents, audit findings, and control deficiencies are properly connected and documented.
- Promote a consistent and repeatable risk management process across the organization.
- Monitor compliance with standards such as ISO 27001, GDPR, EU AI Act, and other internal and external requirements.
- Keep organized, up-to-date, and verifiable records of all compliance activities.
- Coordinate internal and external audits, including collecting evidence, engaging stakeholders, tracking findings, and supporting resolution.
- Produce compliance and assurance reports for management review.
- Integrate compliance activities into daily operations to avoid isolated or one-time efforts.
- Maintain the organization’s control framework and align it with ISO 27001 Annex A and other relevant standards.
- Ensure controls are clearly defined, assigned to owners, implemented, periodically tested, and supported by evidence.
- Identify gaps, inconsistencies, or weaknesses in controls and lead remediation efforts.
- Support assurance assessments to evaluate the effectiveness of controls.
- Encourage continuous improvement in control maturity and the quality of supporting evidence.
- Ensure security, compliance, and operational incidents are recorded, categorized, investigated, and followed to resolution.
- Analyze incidents and issues for root causes, control impacts, and recurring patterns.
- Link incidents and issues to risk responses, control enhancements, and organizational learning.
- Track corrective actions from incidents, audits, or reviews to ensure completion and effectiveness.
Compensation
Excellent package on offer with room for negotiations
Work Arrangement
Remote — Ireland, UK, Europe, South Africa