Stockbit / Bibit is looking for an
IT Security – Governance, Risk & Compliance (GRC) professional to strengthen our security governance, risk management, and compliance practices.
You'll have the opportunity to build and strengthen security governance within a
fast-growing fintech environment, working closely with Technology, Security, Risk, Compliance, and business teams.
What You'll Do
- Manage cyber risk identification, assessment, remediation tracking, and risk acceptance processes.
- Ensure security compliance with regulatory requirements, internal/external audits, and applicable security standards.
- Develop and maintain security policies, standards, controls, and control ownership frameworks.
- Coordinate security audits, including evidence collection, finding management, and remediation tracking.
- Establish and manage Third-Party / Vendor Security Risk Assessment processes.
- Support data protection governance, including data classification, handling, and protection requirements.
- Establish governance around access reviews, privileged access, and access control requirements.
- Drive security awareness initiatives, including security training and phishing simulations.
- Support business continuity, disaster recovery, and cyber resilience governance.
- Manage security exceptions, compensating controls, and formal risk acceptance.
- Support security incident handling, including incident coordination, documentation, post-incident review, and tracking of remediation actions.
- Manage security dashboards and management reporting covering security posture, risk, compliance, initiatives, and security maturity
What We're Looking For
- 3–5 years of experience in IT Security, GRC, Cybersecurity, IT Audit, Risk Management, or related areas.
- Strong understanding of security governance, risk management, and compliance frameworks.
- Experience working with security audits, regulatory requirements, and control assessments.
- Familiarity with frameworks and standards such as ISO 27001, NIST CSF, COBIT, or similar.
- Experience in risk assessment, policy development, control implementation, and audit remediation.
- Experience or good understanding of security incident handling and response processes.
- Good understanding of information security, access management, data protection, and third-party risk.
- Strong analytical, documentation, and stakeholder management skills.
- Comfortable working with both technical and non-technical stakeholders.
- Experience in fintech, financial services, or other regulated industries is a plus.