About the Role
The Security Governance function is responsible for strengthening information security governance, risk management, regulatory resilience, AI security and governance, and assurance across the organization. The Digital Trust & Regulatory Resilience (DTRR) section provides an integrated governance capability across cyber security, data, privacy, AI, regulatory compliance, assurance, human risk, and enterprise risk intelligence.
Responsibilities
- Work across the DTRR pillars to support the implementation and continuous improvement of the Digital Trust & Regulatory Resilience operating model.
- Provide hands-on governance, risk, and compliance support to DTRR Pillar Leads, helping translate strategic objectives into practical processes, controls, standards, procedures, and operational guidance.
- Provide primary cross-functional support to DTAM - Digital Trust Assurance Model, including control framework development, control mapping, evidence requirements, assessment processes, remediation tracking, control maturity, and assurance activities.
- Support the development, review, maintenance, and continuous improvement of information security policies, standards, procedures, operational manuals, and governance processes.
- Support policy and standards lifecycle management, including periodic reviews, stakeholder consultation, change impact assessment, approval preparation, communication, and implementation tracking.
- Support the development and adoption of governance automation capabilities, including workflow automation and AI-assisted policy, standards, control, and evidence review processes.
- Assist in translating regulatory, security, data, privacy, AI, and business requirements into practical controls and governance processes.
- Support the maintenance and evolution of the DTRR control framework, including mapping requirements from ISO/IEC 27001, ISO/IEC 27002, ISMS, ISMAP, and other applicable standards and regulatory frameworks.
- Support ISMS and ISMAP readiness activities, including control reviews, evidence preparation, gap identification, remediation tracking, internal assessments, and audit coordination.
- Support the DTRR exception management process, including intake, assessment, documentation, compensating controls, approval routing, expiration monitoring, remediation tracking, and closure.
- Support internal and external assurance activities by coordinating evidence, control-owner responses, remediation actions, and audit readiness across relevant stakeholders.
- Provide primary cross-functional support to DTEN - Digital Trust Enablement Network, helping translate governance requirements into practical guidance, communications, awareness, training, and business enablement activities.
- Support and coach Trust Enablement Representatives and other business stakeholders in understanding their responsibilities for security, data, privacy, AI, risk, and regulatory governance.
- Help develop role-based guidance and enablement materials for control owners, business owners, data owners, data stewards, technical custodians, product owners, and other governance stakeholders.
- Support security and Digital Trust awareness initiatives that strengthen organizational understanding of security, data protection, responsible AI, regulatory obligations, and risk accountability.
- Identify recurring areas of misunderstanding, control failure, process friction, or poor adoption and work with DTAM, DTEN, and the relevant Pillar Lead to improve the underlying governance process.
- Support DTDPG - Digital Trust Data Product Governance by helping operationalize data governance processes, data classification and handling requirements, ownership and stewardship responsibilities, HPDU governance, cloud data governance, and HLD-related governance requirements.
- Support DTRC - Digital Trust Regulatory Compliance by helping translate regulatory requirements into controls, policies, standards, processes, evidence requirements, and organizational guidance.
- Support DTARG - Digital Trust AI & Responsible Governance through AI policy and standards development, AI governance processes, risk assessment support, ISO/IEC 42001 alignment, responsible AI awareness, and integration of AI governance requirements into DTAM and DTEN.
- Support DTRIM - Digital Trust Risk Intelligence Management by contributing consistent control, assurance, exception, adoption, and governance data for risk intelligence, KPI/KRI measurement, and management reporting.
- Support development and improvement of internal DTRR processes, ensuring activities are clearly documented, repeatable, scalable, and aligned with defined roles and decision rights.
- Facilitate cross-pillar working sessions to identify dependencies, clarify responsibilities, resolve governance gaps, and coordinate activities requiring multiple DTRR capabilities.
- Support Security High-Level Design and other governance review processes where DTRR involvement is required, helping identify applicable data, privacy, security, AI, regulatory, and control requirements.
- Support incident-response governance where required, including coordination of governance actions, control impact reviews, remediation tracking, lessons learned, and translation of incident findings into policy, control, process, or awareness improvements.
- Support governance metrics and reporting by helping define, collect, validate, and improve KPIs and KRIs relating to control effectiveness, exceptions, assurance, adoption, policy health, remediation, and governance maturity.
- Identify opportunities to simplify, standardize, and automate GRC activities while maintaining appropriate governance, accountability, evidence, and human oversight.
- Maintain awareness of emerging information security, regulatory, AI, data protection, risk, and governance practices and help assess their relevance to DTRR.
- Build collaborative relationships across Security, Technology, Business Units, Privacy, Legal, Compliance, Internal Audit, Cloud, Data, AI, and other relevant functions to support consistent adoption of DTRR requirements.
- Promote a culture of practical governance, shared accountability, continuous improvement, and Digital Trust across the organization.
Requirements
- 7-12 years of progressive experience in Governance, Risk Management, Information Security, and/or Compliance roles, with experience supporting significant programs, developing the capabilities of others, or assuming responsibility for key program components.
- Proven experience working within or alongside teams of GRC professionals, including experience coaching, mentoring, supporting development, and improving team or stakeholder capability.
- Broad understanding across multiple GRC domains, including security risk management, compliance management, policy and standards management, third-party risk, business continuity, information security governance, assurance, and control management.
- Strong experience with GRC technology platforms and governance automation; experience with leading GRC, compliance automation, workflow, or control-management platforms is a significant advantage.
- Strong critical thinking, leadership, problem-solving, and influencing skills, with the ability to operate effectively across organizational and functional boundaries.
- Excellent verbal and written communication, presentation, facilitation, and interpersonal skills, with the ability to translate complex technical, risk, security, and regulatory information for diverse audiences, including non-technical stakeholders and executives.
- Demonstrated ability to manage multiple priorities, projects, dependencies, and stakeholders within a fast-paced and evolving environment.
- Ability to work as a senior individual contributor, provide guidance and coaching to others, and influence outcomes without requiring direct management authority.
Skills
- Information Security Governance
- Risk Management
- Regulatory Resilience
- AI Security
- AI Governance
- Data Trust
- Privacy & Protection Governance
- Adaptive Compliance
- Regulatory Intelligence
- Intelligent Governance
- Policy Automation
- Human Risk
- Security Culture
- Integrated Cyber Risk Intelligence
- GRC Technology Platforms
- Governance Automation
- Control Framework Development
- Control Mapping
- Assessment Processes
- Remediation Tracking
- Control Maturity
- Assurance Activities
- Information Security Policies
- Standards Management
- Procedures Development
- Operational Guidance
- Policy Lifecycle Management
- Stakeholder Consultation
- Change Impact Assessment
- Workflow Automation
- AI-Assisted Review Processes
- ISO/IEC 27001
- ISO/IEC 27002
- ISMS
- ISMAP
- ISO/IEC 42001
- NIST CSF
- Data Governance
- Data Classification
- Cloud Data Governance
- Responsible AI
- Risk Intelligence Management
- KPI/KRI Measurement
- Management Reporting
- Security Awareness Initiatives
- Incident Response Governance
Experience Level
- 7-12 years of progressive experience
Education Level
- Bachelor's degree in Information Technology, Law, Finance, Cybersecurity, Engineering, or a related field.
- Advanced degree (Master's or higher) in a relevant discipline, such as an MBA or Cybersecurity, is highly preferred.
- Relevant professional certifications such as CISA, CISM, CRISC, CISSP, CGEIT, ISO/IEC 27001, ISO/IEC 42001, NIST CSF, or other qualifications demonstrating expertise across GRC, information security, risk, compliance, or Digital Trust domains are good to have.
About the Company
- The Security Governance function is responsible for strengthening information security governance, risk management, regulatory resilience, AI security and governance, and assurance across the organization.
- The Digital Trust & Regulatory Resilience (DTRR) section provides an integrated governance capability across cyber security, data, privacy, AI, regulatory compliance, assurance, human risk, and enterprise risk intelligence.
- DTRR operates through six interconnected strategic pillars: Data Trust, Privacy & Protection Governance; Adaptive Compliance & Regulatory Intelligence; Intelligent Governance & Policy Automation; Human Risk & Security Culture; AI Security & Responsible AI Governance; and Integrated Cyber Risk Intelligence.
- The function is supported by strategic capabilities including DTDPG - Digital Trust Data Product Governance, DTRC - Digital Trust Regulatory Compliance, DTAM - Digital Trust Assurance Model, DTEN - Digital Trust Enablement Network, DTARG - Digital Trust AI & Responsible Governance, and DTRIM - Digital Trust Risk Intelligence Management.
