Great assignments await you with our key account clients in rich and varied environments
We are looking for an experienced Cybersecurity GRC Manager to support our client in strengthening its information security governance, risk management and compliance approach.
The consultant will join the cybersecurity team and work closely with the CISO, internal teams, external partners and business stakeholders. The mission focuses on ISO 27001:2022, NIS2 compliance, risk management, audit preparation and the continuous improvement of the Information Security Management System.
This role is ideal for a pragmatic GRC professional who combines strong documentation skills, security governance expertise and the ability to work in a multi-stakeholder environment.
The Cybersecurity GRC Manager will contribute to the operational implementation of governance, risk and compliance activities.
Main responsibilities include:
- Drafting and maintaining ISMS documentation, including security policies, operational procedures and risk treatment plans.
- Supporting ISO 27001 certification activities, from gap analysis to audit preparation.
- Preparing internal and external audits and following up on non-conformities.
- Supporting NIS2 compliance initiatives for essential and important entities.
- Maintaining risk registers, control follow-up and action plans.
- Using and administering a GRC tool such as CISO Assistant, OneTrust, ServiceNow GRC, Archer or equivalent.
- Facilitating workshops with IT, business and security stakeholders.
- Translating regulatory and security requirements into practical, actionable controls.
- Producing clear reports and dashboards for management and governance bodies.
- Supporting the CISO in structuring security governance across multiple stakeholders.