Overview
IT Governance, Risk and Compliance (GRC) Manager role at Backbase. The role enables Backbase to operate in compliance with all relevant national and international laws and regulations, internal policy standards and IT security frameworks such as SOC2, ISO27001 and PCI-DSS requirements.
There is both an ethical component and a pragmatic approach to compliance required to help the organization manage risk and build trust with its customers. The GRC Manager must understand the highly innovative and dynamic environment of a FinTech organization.
Responsibilities
- Support design, implementation and management of IT Controls & Compliance Frameworks for an international organisation.
- Ensure compliance with industry best security practices within SaaS environments.
- Manage and coordinate customer and independent third-party attestations as part of contractual obligations and certification requirements.
- Support Third-Party Risk assessments and regular assurance program.
- Prior experience working with GRC tools and platforms.
- Ability to analyse and translate laws, regulations and technical requirements into commercially focussed business processes.
- Ability to execute and report status on Risk Assessment and Risk Mitigation Program metrics.
- Proficient at maintaining policies and procedures as part of the Policy Governance Framework and coordinating that with other departments.
- Integrate in an Agile / Scrum working environment to drive teams.
- Knowledge of multiple security and privacy frameworks, third-party risk, outsourcing and banking regulations, etc.
- Knowledge of Secure-SDLC tooling and design.
- Knowledge of modern cloud technologies (AWS, Azure) and risks associated with Software-as-a-Service model.
- Knowledge of Open Banking / PSD2 is an added advantage.
- Knowledge of the requirements of ethics & compliance programs in international business.
Qualifications and experience
Minimum of 6-8 years of relevant working experience in the practical implementation of Compliance programs in an international environment.Bachelor’s degree required; academic degree desired in IT Security.Cloud Management experience (Azure, GCP or AWS).Fluent English - written and spoken required (mandatory).Professional certifications (e.g. ISC2 or CompTIA) desired or willingness to obtain them.Experience with managing in a functional way (not hierarchical).Ability to work with the latest tech stack (Latest Azure Services, Grafana, Elastic Cloud, Open Source tooling, Dependency Track, Trivy etc. - Security Tools).Seniority level
ExecutiveEmployment type
Full-timeJob function
Information TechnologyIndustries
IT Services and IT Consulting#J-18808-Ljbffr