Global Manager of Information Security overseeing the Governance, Risk, and Compliance program at BCM One. Leading audits, developing policies, and ensuring legal compliance in a hybrid role.
Responsibilities
Define and implement the organization's GRC program, including policies, procedures, and controls
Oversee and manage our global information security governance and compliance programs
Develop and maintain robust security policies, procedures, and best practices
Coordinate internal and external audits (SOC, ISO, Cyber Essentials Plus), ensuring readiness and compliance
Conduct internal audits, identify gaps, and recommend corrective actions
Deliver training sessions and security awareness initiatives across the organization
Lead third-party risk assessments (TPRM) and respond to vendor security assessments
Chair ISMS Management Review meetings and monitor cyber risk metrics
Support IT with vulnerability management and penetration testing planning
Contribute to data privacy and governance compliance under GDPR, UK DPA, NZ Privacy Act, etc.
Support Business Continuity Planning (BCP) testing and documentation
Requirements
Bachelor’s degree in Computer Science, Information Systems, or related field (or equivalent work experience)
10+ years of experience in IT governance, compliance, or risk management at a global company
Proven experience with international compliance, specifically GDPR, data protection laws, and compliance initiatives
Six Sigma is a nice to have
ISO 27001 Internal Auditor certification is highly desirable
Strong understanding of information security and IT governance frameworks
Familiarity with telecommunications and technologies like networking and VoIP is preferred
Ability to manage complex, cross-functional projects with a high attention to detail
Excellent communication and stakeholder engagement skills
Proficient in Microsoft Office Suite, especially SharePoint, OneDrive, Outlook, Teams, etc.
Benefits
Competitive industry salaries
Comprehensive medical, dental, and vision insurance
Company-provided life and disability insurance
Matching 401 (k) plan
Employee Emergency Assistance Fund
Paid holidays and vacation time
Job title
Global Manager, Information Security, Governance & Compliance
Senior Security Advisor enhancing security measures to align with corporate objectives at Desjardins. Leading development of strategic initiatives and overseeing best practices in security.
Controls Professional assessing internal control frameworks at Barclays, improving control effectiveness and managing risks to ensure compliance with regulations.
Senior Information Security Engineer at Wells Fargo investigating insider threats and strengthening cybersecurity measures. Conducting advanced investigations and collaborating with cyber teams to mitigate risks.
Staff Product Manager overseeing enterprise security product strategy for Tenable. Collaborating with various teams to deliver customer - focused solutions and product features.
Information Systems Security Officer managing operational security posture for information systems at GDIT. Collaborating closely with ISSM and ISO, handling security aspects, and ensuring compliance with security standards.
Program Security Representative providing multi - discipline security support for Special Access Programs. Ensuring compliance, developing policies, and conducting security assessments in a military context.
Senior Cyber Security Project Manager at Airbus Protect managing medium complexity projects in Cyber Security Consulting. Focusing on project leadership and team management in diverse client settings.
Security Architect responsible for designing cloud security architectures for leading brands. Ensuring compliance and guiding incident response strategies in AWS environments.
Senior Security Consultant for ISMS Management at Bundesdruckerei GmbH in Berlin. Responsible for security analysis, management, and advisory roles on cybersecurity issues.
IT - Systemadministrator managing Video Surveillance and Alarm Systems at Mühlbauer. Supporting technical solutions for multimedia and conference systems with project involvement and ticket handling.