התפקיד במילים פשוטות
התפקיד כולל הובלה מקצועית וניהול של צוות ה-GRC בחטיבת הגנת הסייבר בארגון פיננסי. ביומיום התפקיד כולל פיתוח והטמעה של מדיניות, נהלים ומתודולוגיות סייבר, מענה לדרישות רגולציה וניהול ממשקים מול ביקורת פנימית וחיצונית, לצד הובלת תוכניות מודעות והדרכה ומעקב אחר מדדי בקרה ארגוניים.
- 4+ years of experience in Information Security, Cyber GRC, or Risk Management within complex enterprise environments
- 2+ years of professional team management experience
- Proven experience developing and implementing cyber policies, procedures, and methodologies
- Experience working with regulators, internal and external audits, and compliance requirements
- Familiarity with leading standards and frameworks such as ISO 27001, NIST, COBIT, or similar
- Experience in cyber-related audits
חולץ מתיאור המשרה · מתעדכן אוטומטית
למי זה מתאים
התפקיד מתאים לבעלי לפחות 4 שנות ניסיון באבטחת מידע, ניהול סיכונים או GRC בארגונים גדולים ומורכבים, עם לפחות שנתיים ניסיון בניהול צוות והיכרות עם תקנים כגון ISO 27001 או NIST. הוא פחות מתאים למי שחסר ניסיון ניהולי או ניסיון בעבודה מול רגולציה וביקורת.
תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןWe’re looking for a GRC Team Lead to join the Cyber Defense Division of one of Israel’s leading financial organizations. This is an opportunity to take a key role in shaping and strengthening the organization’s cyber governance framework, leading GRC activities across the organization, and working closely with management, regulators, audit functions, and key stakeholders.
What You'll Do:
• Lead and professionally manage the GRC team within the Cyber Defense Division
• Develop, implement, maintain, and oversee cyber policies, procedures, methodologies, and standards
• Lead the organization’s response to information security and cyber regulatory requirements
• Manage interfaces with regulators, internal audit, and external audit
• Lead cyber awareness, training, and human resilience programs, including measurement and effectiveness monitoring
• Build a cross-organizational governance view of cyber activities, including metrics, dashboards, and management reporting
• Track the implementation of regulatory requirements, cyber policies, and work plans
• Drive control and measurement processes to strengthen organizational GRC maturity
Requirements:
Must Haves:
• 4+ years of experience in Information Security, Cyber GRC, or Risk Management within complex enterprise environments
• 2+ years of professional team management experience
• Proven experience developing and implementing cyber policies, procedures, and methodologies
• Experience working with regulators, internal and external audits, and compliance requirements
• Familiarity with leading standards and frameworks such as ISO 27001, NIST, COBIT, or similar
• Strong analytical and systemic thinking, with the ability to derive insights and present them to management
• Strong leadership skills and the ability to drive cross-functional processes and engage multiple stakeholders
• Excellent written and verbal communication skills in Hebrew and English
Nice to Have:
• Experience in cyber-related audits
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- 4+ years of experience in Information Security, Cyber GRC, or Risk Management within complex enterprise environments, 2+ years of professional team management experience, Proven experience developing and implementing cyber policies, procedures, and methodologies, Experience working with regulators, internal and external audits, and compliance requirements, Familiarity with leading standards and frameworks such as ISO 27001, NIST, COBIT, or similar