GRC Lead

Apply
Apply

Share

successfully icon

Successfully

The vacancy has been successfully added to favorites

location icon

Remote Romania, Romania

specialization icon

Information Security

lob icon

BCM Industry

date icon

03/06/2026

Req. VR-123222

Apply
Project description

Establish and govern an enterprise-wide security framework across Network, EUC, Infra, cloud, AI, products, and business operations.

Responsibilities
bullet icon

Ownership of security governance across cloud, AI usage, products, and enterprise platforms

bullet icon

End-to-end risk management, policy, standards, and exception handling

bullet icon

Readiness and management of ISO 27001, ISO 42001, SOC 1 or SOC 2, NIST, DORA, client audits, and regulatory requirements

bullet icon

Consistent decision-making on risk acceptance and control effectiveness

bullet icon

Strong linkage between security governance and business objectives

bullet icon

Own and operate the cyber and information security risk management

bullet icon

Identify, assess, prioritize, and track information security and cyber risks

bullet icon

Manage information & Cyber risk registers, treatment plans, and risk acceptance

bullet icon

Support management in risk-based decision-making and control effectiveness reviews

Skills

Must have

bullet icon

8+ years of experience in Information Security, Cyber Risk, or GRC roles

bullet icon

Professional certifications: CISA, CRISC, ISO 27001 Lead Implementer/Lead Auditor, ISO42001

bullet icon

Strong hands-on experience with Information Security Governance, Risk, and Compliance

bullet icon

Proven experience leading enterprise-scale GRC programs

bullet icon

Deep working knowledge of:

bullet icon

ISO 27001 / NIST / SOC 2 / PCI DSS

bullet icon

Cyber and information risk assessment methodologies

bullet icon

Audit and assurance processes

bullet icon

Regulatory compliance and control mapping

bullet icon

Demonstrated experience implementing or managing GRC tools

bullet icon

Strong analytical, documentation, and reporting skills

bullet icon

Ability to influence and communicate effectively with senior stakeholders

Nice to have

bullet icon

N/A

Other
seniority icon

Languages

English: C1 Advanced,Romanian: C1 Advanced

seniority icon

Seniority

Lead

Remote Romania, Romania

Req. VR-123222

Information Security

BCM Industry

03/06/2026

Req. VR-123222

Apply for GRC Lead in Remote Romania

*Indicates a required field

Under the terms of your specific consent or to perform our obligations under a contract with you, as applicable, we, Luxoft Holding Inc. will manually and electronically process your personal data, specifically your first name, last name, phone number, e-mail address and other data you provide us through this form.


Within this context, we process personal data only for the specific purpose(s) indicated in the individual consent language or other notices provided below.


We will – insofar as reasonably necessary for the purpose you have agreed to and within the scope of applicable laws – transfer your personal data to other entities within the Luxoft Group and to the group of third party recipients listed in our Privacy Notice. Such Recipients can be located outside the European Union (EU) and/or the European Economic Area (EEA) (“Third Countries”). The Third Countries concerned, e.g. the USA, may not have the level of data protection that you enjoy e.g. under the GDPR. This can result in disadvantages such as an impeded enforcement of data subjects’ rights, a lack of control over further processing and access by state authorities. You may only have limited legal remedies against this. Insofar our transfer of your personal data to recipients in Third Countries is not covered by an adequacy decision of the EU Commission, we achieve an adequate level of data protection as further detailed out in our Privacy Notice.


With your consent, we personalise marketing communications to you by way of carrying out marketing research analysis, analysing the surfing-behaviour of our website visitors and to adjust it to their detected tendencies, as well as to plan more efficient future marketing activities. This personalised marketing does not include any automated decision-making activities.


Further information on how we process personal data in general is available in our Privacy Notice. You may withdraw any given consent at any time. The withdrawal of your consent(s) will not affect the lawfulness of processing before its withdrawal. For any request in this context, please e-mail us at: DPO@luxoft.com.


Before uploading CV or any other information to this website, to learn more about your obligations and restrictions arising from the use of this website, please read our Terms of Use.