Head of Governance, Risk and Compliance
- Full-time
- City: Hybrid
Company Description
We are an equal opportunities employer and place where everyone is welcome. We strongly encourage people from minority backgrounds, LGBTQIA+, parents, and individuals with disabilities to apply. If you need reasonable adjustments at any point in the application or interview process, please let us know.
In your application, please feel free to note which pronouns you use (For example - she/her/hers, he/him/his, they/them/theirs, etc).
We’re one of the world’s largest privately owned real estate tech companies and a subsidiary of Axel Springer. Our mission is to unlock everyone’s perfect place! Some of Europe’s best known digital real estate marketplaces and brands form part of our Group, they are: 🇫🇷 Meilleurs Agents, 🇫🇷 Groupe SeLoger, 🇧🇪 Immoweb, 🇩🇪 Immowelt, 🇪🇸 Housell and 🇮🇱 Yad2.
We also invest in innovative business models which shape the future of how people buy, sell, rent or lend properties and hold minority participations in companies such as: 🇬🇧 PurpleBricks, 🇩🇪 Homeday, 🇺🇸 Zumper and 🇺🇸 Parcel.
Our ambition is to be the leading Employer in PropTech across Europe and this is a pivotal time to join us as we embark on this journey enabling us to help unlock everyone’s perfect place!
Job Description
WHAT WE DO IN THE GRC, RISK & COMPLIANCE TEAM:
Reporting directly to the Group’s CISO, the Head of GRC is responsible for the implementation of the Information Security Governance, Risk and Compliance function. The Head of GRC Authors and publishes information security policies, standards and controls. He/She/They leads enterprise-wide risk assessment activities, the development of control frameworks and implementation of new Cybersecurity program initiatives. He/She/They oversees GRC projects, develops project plans and timelines and coordination of project resources.
This is a new function in the organization which is to be built from scratch.
WE ARE LOOKING FOR AN INDIVIDUAL WHO CAN:
- Build and lead the GRC Function (recruit and manage the team members);
- Build and lead the Internal/M&A Audit function (recruit and manage the team members);
- Review new regulations for security impact and document requirements for compliance;
- Communicate requirements and compliance status to leadership and impacted Product & Tech teams;
- Identify and document cyber risks and manage mitigation and follow up on open security risks. Report issues to stakeholders;
- Develop and lead strategies for the governance, risk and compliance functions across the company that support transformation of the security function;
- Develop, maintain and communicate corporate Security policies, standards, procedures, and guidelines and ensure IT compliance programs are both established and followed (KRIs);
- Perform and help in leading Third Party risk assessments on new and existing partners and suppliers;
- Provide reports and metrics of the current state and improvements of the security of the group.
Qualifications
AN INDIVIDUAL WHO HAS :
- Several years of experience in Information Security - security governance, regulatory governance and/or IT audit preferred
- Several years of managerial experience with proven track records in building and leading strong international teams.
- A strong understanding of security frameworks, standards and where and when to apply them;
- Ability to integrate technical data into executive reports;
- Methodical and detail driven;
- Straight shooter, pragmatic and adaptable in a fast paced environment;
- Strong reporting skills;
- Ability to manage directly and indirectly;
- Dedicated to delivering results and meeting deadlines;
- Able to see the big picture and create strategic plans to execute against it;
- Global knowledge of cloud environments and associated constraints, especially on AWS and GCP;
- Relevant industry standard certifications preferred (i.e., CISA, CISM, CISSP, SANS Institute/GIAC, PCIP);
- Fluency in English is mandatory for this position. The working language is English. All content and deliverables must be produced in english.
Additional Information
WHAT WE OFFER YOU :
- We are one of the leading PropTech platforms in Europe. If you’ve ever rented or purchased a property then you may have used one of our classified portals. This is a great time to join us to help elevate our AVIV brand.
- A high visibility role in our organisation reporting into our Group CISO.
- 30 Days of Holidays
- Unlimited opportunities for your self-development and growth.
- The opportunity to work hybrid within our operating footprint with international travel to our locations in France, Belgium and Germany.
- The autonomy to work in a style which suits you to be the most productive
- The freedom to tell us which tools you need to be successful in your job so we can set you up to make it happen.
By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply