← Back to jobs
E

GRC Manager

HybridFull-timeIT Risk ManagementInsuranceEnterprise Software

Lead the Europe Platform Governance domain for a technology-led insurance and SaaS platform. Build scalable governance processes and translate European regulatory, security, privacy, resilience, and assurance requirements into practical controls.

Responsibilities

  • Build and lead the Europe Platform Governance GRC domain.
  • Translate DORA, GDPR, EU AI Act, group standards, and related requirements into governance, controls, and evidence processes.
  • Embed compliance and risk requirements into platform design and software delivery with technical and business stakeholders.
  • Govern cyber security risk, operational resilience, data protection, AI governance, third-party dependencies, incident management, logging, monitoring, access controls, and auditability.
  • Act as the GRC interface with European and group stakeholders.
  • Maintain regulatory readiness roadmaps, control mappings, gap assessments, risk registers, remediation plans, and executive reporting.
  • Design scalable evidence collection and assurance processes for audits, reviews, regulatory inquiries, and internal governance.
  • Coach GRC team members supporting the Europe domain.
  • Help mature the GRC function as the platform expands internationally.

Requirements

  • 7+ years of experience in GRC, security and regulatory compliance, operational resilience, privacy governance, and evidence-based audit readiness.
  • Managerial experience leading, coaching, and developing team members across complex GRC initiatives.
  • Experience with AWS-native environments, cloud-based products, regulated financial services, and fintech.
  • Strong knowledge of DORA, GDPR, and the EU AI Act, with the ability to translate regulatory requirements into technical and operational controls.
  • Experience building new governance and compliance programs rather than only operating established processes.
  • Experience collaborating with engineering, product, security, cloud infrastructure, DevOps, legal, privacy, and audit teams.
  • Experience managing group-level, enterprise, or parent-company stakeholders.
  • Experience using AI, automation, or data-driven methods to improve regulatory analysis, evidence management, reporting, or operational efficiency.
  • Excellent written and verbal communication, prioritization, execution, and follow-through skills.

Relevance

More opportunities

Similar jobs

The newest open roles in IT Risk Management.

Questions, answered

Frequently asked questions