Information Security GRC Specialist (f/m/d)

Brak informacji o wynagrodzeniu
MidFull-time
#329961·Dodano 13 dni temu·24
Źródło: Awin
Aplikuj teraz

Tech Stack / Keywords

SecurityEmbeddedNetwork

Firma i stanowisko

Awin is part of the Axel Springer group, established in 2000, with a dynamic, social, and inclusive culture. The company operates globally with offices in multiple European cities and focuses on building the world's leading open partner ecosystem.


Wymagania

  • Proven track record of owning and delivering risk management initiatives end-to-end.
  • Experience driving risk remediation across teams without direct authority.
  • Strong experience presenting and defending risk positions to senior leadership and boards.
  • Hands-on experience within an ISO 27001-certified ISMS environment.
  • Strong knowledge of frameworks such as ISO 27001.
  • Experience designing, implementing, or improving control frameworks.
  • Experience with GRC platforms (e.g., Hyperproof).
  • Confident communicator with very good English skills, able to build relationships and challenge/influence senior stakeholders.

Obowiązki

  • Lead enterprise-wide risk identification and assessment across strategic initiatives, technology, and third parties.
  • Ensure risks are prioritised and clearly articulated in business terms to enable effective decision-making.
  • Drive risk remediation to closure, holding risk owners accountable and escalating where progress stalls.
  • Ensure risk management is embedded in cross-functional initiatives and key business decisions.
  • Own and maintain the Information Security Risk Register, reflecting true risk exposure and progress.
  • Facilitate risk reviews focused on decisions, accountability, and measurable progress.
  • Define, embed, and maintain the organisation’s risk appetite for business and technology decision-making.
  • Establish and track KPIs measuring real improvements in risk posture.
  • Provide clear, actionable risk insights to senior management and the board.
  • Act as a bridge between technical and business teams to ensure risks are understood and acted upon.
  • Challenge and influence stakeholders to ensure risks are appropriately accepted.
  • Own and improve Awin’s global information security risk management framework aligned to ISO 27001 and regulatory requirements.
  • Monitor control effectiveness, identify weaknesses, and drive improvements.
  • Embed risk management into business processes proactively.
  • Mentor and develop GRC team members, building capability in risk management and assurance.
  • Lead horizon scanning across emerging threats, regulatory changes, and industry developments, translating these into practical risk implications and actions.

Oferta

  • Flexible four-day Flexi-Week at full pay with no reduction to annual holiday allowance.
  • Variety of different paid special leaves and volunteer days.
  • Monthly remote working allowance and support for setting up remote workspace.
  • Flexi-Office and hybrid/remote work possibilities across Awin regions.
  • Extensive training suite (Awin Academy) covering a wide range of professional and personal development skills.
  • Peer-to-peer voucher program for appreciation and rewards.
Elastyczne godziny
Płatny urlop
Płatne święta
Dofinansowanie szkoleń
Bonusy
Awin

Awin

13 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz