About this role
About the Role Define, develop, and maintain the regulatory GRC framework for cybersecurity, ensuring policies, standards, and procedures are current and aligned with business objectives. The role partners with Product Compliance and Learning & Development to drive product security standards and employee awareness. What You'll Do
- Define, develop, and maintain cybersecurity policies, standards, and procedures.
- Coordinate GRC-related processes with internal departments and business areas.
- Collaborate with Product Compliance to ensure compliance with product security standards, including ISO/SAE 21434.
- Coordinate GRC content creation with Learning & Development, developing awareness content, training modules, and educational materials for employees on cybersecurity topics. What We're Looking For
- Bachelor’s degree in information technology, computer science, or related field.
- 3–6 years of hands-on Governance & Risk Management experience.
- In-depth knowledge of ISO/IEC 27001.
- Familiarity with TISAX.
- Understanding of NIS2 Directive.
- Strong knowledge of risk management models and methodologies.
- Experience in industrial sector, preferably automotive.
- Prior knowledge of product security or ability to quickly acquire it.
- Proactive about identifying compliance gaps and improving GRC.
- Ability to work effectively in a cross-functional team and communicate with technical teams, senior management, legal, compliance. Nice to Have
- Automotive industry experience or preference for automotive. Compensation & Benefits
- Salary not disclosed in the posting.