עדיין מחפשים עבודה במנועי חיפוש? הגיע הזמן להשתדרג!
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
We're looking for a GRC manager to lead governance, risk and compliance within our information security and cyber defense team.
The role covers regulatory work, risk management, vendors and budget.
It also includes supporting projects from design through go-live.
You'll work closely with management, procurement, technology teams and vendors.
What you'll do:
- Own and update security policies, procedures and the threat reference model, according to the annual review plan and regulatory requirements
- Run compliance reviews against Israel National Cyber Directorate (INCD) directives, build remediation plans and track gap closure
- Submit the annual regulatory reports on cloud and cyber threats
- Run the annual security assessment and penetration testing plan: write RFPs, select vendors with procurement, hold kickoff and validation meetings, and log findings in the GRC system
- Run risk assessments for projects, new systems, cloud services and AI systems
- Run third-party risk management (TPRM): questionnaires, analyzing findings and tracking remediation
- Coordinate the cloud and AI committees and prepare materials for the security steering committee
- Track the department's annual work plan
- Manage the security budget, system purchases, license renewals and vendor payments
- Manage vendors: track service hours, approve invoices and monitor contract compliance
- Administer Commugen and the systems and licensing inventory, and track SWIFT CSP
- Lead security awareness: onboarding training, phishing campaigns and Cybeready
- Support business, technology and regulatory projects with a Security by Design approach
What we're looking for:
- 3+ years in GRC, compliance or information security risk management
- Familiarity with INCD directives, ISO 27001 and Israeli privacy regulations
- Experience managing security assessments and penetration tests with external vendors
- Experience managing vendors, budgets and procurement processes
- Hands-on experience with a GRC platform, Commugen preferred
- Strong writing and presentation skills, including materials for management
- Good English
Nice to have:
- Certifications such as CISM, CRISC or ISO 27001 Lead Auditor
- Experience in a financial or regulated organization
- Experience assessing risk for cloud and AI systems
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
ירושלים
ערב