EU remote
Information Security GRC Team Lead
About this role
ABOUT THE ROLE The Information Security Department at LeoVegas forms part of the Legal & Compliance team and focuses its activities in 4 main areas of Information Security: Governance, Risk, and Compliance (GRC), Security Operations (SECOPS), Incident response (CSIRT), and Security Awareness Training (SAT). The Information Security GRC Lead is a key individual in a small team focusing on GRC and SAT, working alongside Internal IT, Privacy, Risk, Tech Compliance, Legal, Platform, and other teams.
This individual is responsible for ensuring good governance and compliance with regulatory requirements, as well as the adoption of good security industry practices across LeoVegas Group. The role also includes providing leadership to the team, ensuring alignment with the organization’s broader business objectives, and managing the team’s performance to ensure effective risk management and security governance. This position calls for a strong communicator and risk advisor, focused on identifying and mitigating risks through best practices.
YOU WILL BE RESPONSIBLE FOR: - Develop and implement the organization's GRC strategy together with the Head of Information Security, ensuring governance, risk, and compliance efforts stay aligned with overall business objectives, and maintain a roadmap of team activities based on projects, department goals, and regulatory requirements. - Contribute to the development of security KPIs, objectives, and strategies to improve the Group's overall security posture and maturity.
- Conduct security maturity assessments and lead/conduct other risk assessments and analyses, contributing to the identification and mitigation of security risks across the organization. - Detect gaps in security processes and product portfolios, determine associated risks, an recommend remediation. - Assist the Risk Management function in maintaining the Group's Security Risk Register. - Develop, maintain, and implement the Group's Information Security policies, standards, and guidelines.
- Manage and lead regulatory audits, external auditor and regulatory-body relationships, and licensed market entry projects, assisting Tech Compliance and other teams as required. - Participate in and contribute to security certification projects. - Manage and lead vendor onboarding due diligence and supplier monitoring processes. - Assist with the development, maintenance, and testing of business continuity and disaster recovery plans.