Job Title: Head of Cyber Governance, Risk and Compliance (GRC)
Department: IT Department
Reporting to: Head IT GRC
Main Role (Overall accountability):
- The Head of Cyber GRC is part of the IT GRC team and acts as the central coordination point for all internal and external audits, regulatory engagements concerning 1st and 1.5 line and defense (1LOD/1.5LOD), and general risk and control activity as described in the enterprise risk management framework.
Principal Accountabilities:
- Accountable for governing the 1LOD control environment, ensuring compliance with 2LOD policies, and providing an independent report on the 1LOD risk posture and control performance
- Accountable for executing the 1LOD GRC mandate: "Ensure the 1st Line is meeting its obligations and operating controls correctly. Focus on Control Performance and operational readiness
- Accountable for the definition and maintenance of 1LOD Security Standards, Baselines, and Control Procedures, ensuring they align with the Policies and Control Objectives set by 2LOD
- Manages the standards lifecycle, coordinates compliance/audit, and facilitates the exception process within 1LOD. Objectives and are periodically reviewed. “Implements and monitors adherence to the policies and frameworks defined by 2LOD”
- Accountable for the coordination and execution of the 1LOD Risk and Control Self-Assessments (RCSAs) by Leading the 1LOD risk assessment process, control validation, 1.5LOD thematic reviews, and executive reporting
- Accountable for monitoring and reporting on the operational performance and compliance status (KPIs) of the 1LOD
- Accountable for conducting quality assurance (QA) checks and internal control reviews (1.5LOD audits) on 1LOD activities
- Maintains the 1LOD Cyber Risk Register and tracks the status of risk treatment plans.
- Manages the “Control Library & Attestation” process and executes the 1.5LOD assurance plan, including “Internal Security Audits (1.5LOD Control Reviews)” and developing “Continuous Controls Monitoring (CCM)”.
- Facilitates the submission of exception requests initiated by the 1LOD and tracks their lifecycle
- Provides “Regulatory Intelligence & Advisory” service, interpreting regulatory changes and advising 1LOD on compliance readiness.
- Aggregates KPIs and risk data to prepare the independent 1.5LOD executive risk and control reports. “Tracks Key Performance Indicators (KPIs)”
Personnel Specifications:
- 10+ years in IT/cyber GRC, IT audit, or security management within financial services
- Minimum 4 years leading GRC functions
- Experience with GRC platforms
- Enterprise risk management and control frameworks, and core processes (e.g., RCSAs)
- Strong understanding of Three Lines of Defence and regulatory requirements
- Driving process improvements to operational risk management specifically on cyber, tech and resilience risk and control
- Experience establishing 1.5LOD assurance capabilities
- Bachelor's degree in Information Systems, Computer Science, or related field (Master's preferred)
- CISA, CISM, or CRISC certification required
- Knowledge of CBO regulations and banking standards
- GRC platform certifications advantageous