Job Purpose (Job Summary): Security and Privacy Governance Risk and Compliance Manager
The Department
The Governance and Risk Compliance Manager reports into the Chief Information Security Officer (CISO) and is accountable and responsible, on a global basis, for all Security and Privacy governance, controls and compliance activities
Your Role
The GRC Manager will establish and conduct risk and controls operational responsibilities of the Security and Privacy function, including aligning the vision, goals, objectives, policies, and standards of this function with the Company business strategy. The GRC Manager will work closely with Invesco Global Security to design and monitor policies and standards and will represent across relevant governance forums.
The GRC Manager will demonstrate a customer-first mindset, working alongside company officers, business managers, security teams, managed service providers and IT managers to effectively monitor Company assets to ensure alignment with security and privacy controls,
which includes customer data held across our software environments. To support a thriving and secure business, the GRC Manager will:
Key responsibilities / Duties:
- Represent Security and Privacy and act as the interface to the Company business. Build solid partnerships with the Company business to promote better interaction, communication, and understanding. Serve as the primary point of contact and escalation for business security matters.
- Understand the Company business strategy and direction, requirements, major initiatives, high-value assets, and risk appetite and tolerances. Drive alignment between Security and Privacy and the Company business. Inform and focus our Security and Privacy initiatives and promote a business-driven approach.
- Identify and communicate security risks within the Company business (including through third-party providers) and explain those risks in language understood outside Security and Privacy. De