Technology GRC Manager
Cork, County Cork, Ireland · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 4 giorni fa
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Company Overview
H&MV Engineering is a global frontrunner in high-voltage electrical engineering, dedicated to advancing sustainable energy solutions. Our expertise spans renewable energy, data centers, and complex utility infrastructures. We prioritize safety, teamwork, and respect as the pillars guiding our leadership and growth philosophy. We invest heavily in our workforce, offering chances to innovate, lead, and shape the evolving energy landscape. Passion, motivation, and problem-solving are highly valued, with diverse viewpoints driving superior results.
Position Summary
We seek a seasoned risk management expert to spearhead and expand our Technology Governance, Risk, and Compliance (GRC) function amid international growth. This senior role involves establishing a pragmatic, business-focused information security risk management system anchored in strong governance and compliance standards. The chosen individual will manage the complete lifecycle of information security risks, ensuring decisions are transparent, evidence-driven, and aligned with ISO 27001 standards, while preparing for emerging European regulations.
Key Responsibilities
- Develop, maintain, and continuously refine the company’s information security risk management framework.
- Align risk management methods with ISO 27001 and pertinent regulatory frameworks.
- Define clear governance structures for risk identification, assessment, ownership, escalation, treatment, and acceptance.
- Create practical policies, standards, procedures, and governance documents to ensure consistent, proportionate risk management.
- Translate regulatory, audit, and control frameworks into actionable risk activities and reporting metrics.
- Oversee the entire information security risk process including identification, assessment, scoring, treatment planning, review, and reporting.
- Maintain an up-to-date risk register with designated risk owners, mitigation actions, deadlines, and treatment outcomes.
- Collaborate with technology, security, business, and operational teams to evaluate risks arising from projects, suppliers, systems, regulation changes, and control gaps using a standardized methodology.
- Manage third-party information security risk in partnership with procurement and business units across lifecycle stages.
- Support risk-based decision-making by offering clear analyses, challenges, and recommendations to risk owners and senior leaders.
- Coordinate remediation activities and monitor progress until closure or formal acceptance.
- Develop insightful risk reporting that underscores key trends and themes.
- Ensure compliance and assurance initiatives are risk-driven, appropriate, and aligned with business priorities.
- Support adherence to ISO 27001, internal policies, client specifications, and upcoming European cyber regulations.
- Organize and back control assessments, gap analyses, maturity exams, audits, and regulatory reviews.
- Maintain organized evidence of control effectiveness, risk treatment, and compliance for auditing and regulatory requirements.
- Monitor audit findings and remediation actions, linking them clearly to risk treatments.
- Lead, cultivate, and grow a focused GRC team, establishing priorities, roles, and operational workflows aligned with business risk.
- Mentor team members to strengthen competencies in governance, risk assessment, reporting, compliance, and audit preparation.
- Foster a collaborative and accountable team atmosphere promoting continuous growth and improvement.
- Forecast and plan for future resourcing, skillsets, and process enhancements as the GRC function evolves.
- Serve as a reliable risk and GRC advisor to IT operations, legal, procurement, security, data protection, and business areas.
- Build and maintain strong stakeholder relationships to integrate risk management into everyday decisions.
- Deliver practical advice balancing risk appetite, regulatory requirements, security best practices, and business needs.
- Communicate information security risks to leadership clearly, concisely, and in an actionable manner.
- Promote a culture of business ownership of risk, supported by solid governance, evidence, and accountability.
Required Experience and Skills
- Extensive experience in Governance, Risk, and Compliance or information security risk management, preferably within technology, engineering, infrastructure, or regulated sectors.
- Proficient knowledge of ISO 27001 and hands-on experience with Information Security Management Systems.
- Demonstrated expertise in designing or managing risk processes including risk evaluation, scoring, treatment planning, reporting, and governance.
- Familiar with control frameworks, audit handling, compliance monitoring, and remediation tracking.
- Awareness of European cybersecurity and data privacy legislation, with capability to implement compliant risk and governance measures.
- Proven experience in team leadership or mentorship, including management of distributed teams, and capacity-building within a developing function.
- Excellent communication, documentation, and stakeholder engagement skills, able to clarify risk concepts to varied audiences.
- Strong organizational skills with ability to manage priorities and clarify complex demands independently.
Preferred Qualifications
- Professional certifications such as ISO 27001 Lead Implementer or Lead Auditor.
- Certifications like CISM, CRISC, CISSP, or CISA are advantageous.
- Hands-on knowledge of NIS2 readiness, third-party risk, supply chain assurance, GDPR, DORA, or other relevant European regulatory frameworks.
- Experience using Governance, Risk and Compliance platforms or third-party risk monitoring solutions.
Candidate Profile
This opportunity is ideal for a confident and experienced risk management professional who thrives in building structured, mature environments and influencing enterprise-wide practices. The successful candidate will be pragmatic, cooperative, results-driven, capable of transforming risk, compliance, and governance requirements into meaningful business impact and risk minimization. They will be adept at balancing strategic direction with hands-on execution, engaging senior stakeholders, developing their team, and embedding risk management principles through sensible governance, proportionate compliance, and effective assurance efforts.
Diversity & Inclusion
H&MV Engineering is committed to equal opportunity employment and values diversity. We strive to maintain an inclusive workplace culture for all employees.
Location
This role is based in Cork or Limerick, Ireland.