GRC Manager
Lead the Europe Platform Governance domain for a technology-led insurance and SaaS platform. Build scalable governance processes and translate European regulatory, security, privacy, resilience, and assurance requirements into practical controls.
תחומי אחריות
- Build and lead the Europe Platform Governance GRC domain.
- Translate DORA, GDPR, EU AI Act, group standards, and related requirements into governance, controls, and evidence processes.
- Embed compliance and risk requirements into platform design and software delivery with technical and business stakeholders.
- Govern cyber security risk, operational resilience, data protection, AI governance, third-party dependencies, incident management, logging, monitoring, access controls, and auditability.
- Act as the GRC interface with European and group stakeholders.
- Maintain regulatory readiness roadmaps, control mappings, gap assessments, risk registers, remediation plans, and executive reporting.
- Design scalable evidence collection and assurance processes for audits, reviews, regulatory inquiries, and internal governance.
- Coach GRC team members supporting the Europe domain.
- Help mature the GRC function as the platform expands internationally.
דרישות
- 7+ years of experience in GRC, security and regulatory compliance, operational resilience, privacy governance, and evidence-based audit readiness.
- Managerial experience leading, coaching, and developing team members across complex GRC initiatives.
- Experience with AWS-native environments, cloud-based products, regulated financial services, and fintech.
- Strong knowledge of DORA, GDPR, and the EU AI Act, with the ability to translate regulatory requirements into technical and operational controls.
- Experience building new governance and compliance programs rather than only operating established processes.
- Experience collaborating with engineering, product, security, cloud infrastructure, DevOps, legal, privacy, and audit teams.
- Experience managing group-level, enterprise, or parent-company stakeholders.
- Experience using AI, automation, or data-driven methods to improve regulatory analysis, evidence management, reporting, or operational efficiency.
- Excellent written and verbal communication, prioritization, execution, and follow-through skills.