Security Governance & Risk Management Specialist

UPSIDE

Cybersec

Compliance

Security

About this role

This role sits in the security function of a financial platform and focuses on company-wide security governance and risk management. It connects risk assessment, control design, monitoring, audit, and incident management across product security, corporate security, legal, internal audit, and business teams, while reporting security risks to management.

The role covers risk assessments for the company, businesses, and systems; information-security policies, standards, and guidelines; ISMS operation and improvement; PCI DSS and other security requirements; audits; customer and partner assessments; corrective-action tracking; and security questionnaires. During incidents, it coordinates severity decisions, internal escalation, relevant departments, and external responses. Required experience includes security risk assessment, security policy or standard development and operation, ISMS operation, audit or security-assessment response, cross-functional remediation, incident escalation, and driving initiatives with management, legal, IT, product, and business stakeholders.

This is an AI-generated summary of the employer's original posting — details can be incomplete, out of date or simply wrong. Always confirm everything on the official posting before applying.