Über diese Information Security Governance Manager Stelle bei HugoBank
We are seeking an experienced Information Security Governance Manager to lead our Governance, Risk, and Compliance (GRC) function and strengthen the bank's Information Security Governance Framework. This role is responsible for driving regulatory compliance, developing security policies and standards, managing enterprise cyber risks, coordinating audits, and ensuring the bank maintains a robust and resilient security posture.
Key Responsibilities
- Develop, implement, and continuously improve the Information Security Governance Framework.
- Establish and maintain information security policies, standards, procedures, and guidelines.
- Ensure compliance with applicable regulatory requirements and industry best practices.
- Lead Governance, Risk & Compliance (GRC) activities, including enterprise security risk assessments and risk reporting.
- Coordinate internal, external, regulatory, and certification audits, ensuring timely remediation of findings.
- Manage third-party security risk assessments and vendor security reviews.
- Track security KPIs, KRIs, compliance metrics, and prepare executive dashboards for senior management and Board committees.
- Promote security awareness and foster a strong security culture across the organization.
- Support enterprise initiatives involving cloud security, AI governance, and secure adoption of emerging technologies.
Requirements
Qualifications & Experience
- Bachelor's degree in Computer Science, Information Technology, Cyber Security, or a related discipline (Master's degree preferred).
- 4–6 years of experience in Information Security, Cyber Security, IT Risk, or Governance, Risk & Compliance (GRC), including 4+ years in a governance role within banking, financial services, fintech, or a digital bank.
- Hands-on experience implementing and maintaining ISO/IEC 27001 Information Security Management System (ISMS).
- Experience managing or supporting PCI DSS compliance and security assessments.
- Strong understanding of Digital Banking regulations, information security governance, enterprise risk management, and regulatory compliance.
- Experience with Cloud Security Governance (AWS, Azure, or Google Cloud Platform) and cloud security frameworks.
- Knowledge of AI Security, AI governance, and managing security risks associated with Generative AI and emerging technologies.
- Familiarity with NIST Cybersecurity Framework (CSF), CIS Controls, Zero Trust Architecture, data protection, and third-party risk management.
- Experience coordinating regulatory inspections, security audits, certification audits, and compliance assessments.
- Professional certifications such as CISM, CISA, CRISC, ISO/IEC 27001 Lead Implementer/Lead Auditor, CISSP, CCSP, PCI Professional (PCIP), or PMP will be an added advantage.
What We're Looking For
- Strong leadership, communication, and stakeholder management skills.
- Excellent analytical, problem-solving, and decision-making abilities.
- Experience engaging with regulators, auditors, executive management, and Board committees.
- Ability to translate regulatory and business requirements into practical, risk-based security controls.
- Passion for driving security governance, operational resilience, and continuous improvement in a fast-paced digital banking environment.