job description
Are you a seasoned Governance, Risk & Compliance (GRC) leader with expertise in securing IT and OT environments? Join a leading Philippine power and energy conglomerate as the Head of Security GRC and drive strategic initiatives to ensure robust compliance, risk management, and cybersecurity frameworks across critical infrastructure.
In this high-impact role, you will oversee the development and implementation of enterprise-wide GRC programs, aligning security policies with industry standards (e.g., ISO 27001, NIST, IEC 62443). You will collaborate with cross-functional teams to mitigate risks, ensure regulatory adherence, and foster a culture of security awareness. This is a unique opportunity to shape the future of cybersecurity in a dynamic and essential industry.
Based in Bali, Indonesia, this role offers a competitive compensation package and the chance to work with a forward-thinking organization committed to innovation and excellence in energy solutions.
Responsibility
- Develop, implement, and maintain a comprehensive GRC framework for IT and OT environments, ensuring alignment with global security standards and regulatory requirements.
- Lead risk assessments, vulnerability analyses, and compliance audits to identify and mitigate security gaps across the organization.
- Establish and enforce security policies, procedures, and controls to protect critical infrastructure and sensitive data.
- Collaborate with IT, OT, and business stakeholders to integrate GRC principles into operational and strategic decision-making.
- Oversee third-party risk management, including vendor assessments and contract compliance reviews.
- Drive security awareness programs and training initiatives to foster a culture of risk-aware employees.
- Monitor emerging cybersecurity threats and regulatory changes, proactively adjusting GRC strategies to maintain resilience.
- Prepare and present executive-level reports on GRC performance, risk exposure, and remediation progress.
Qualifications
- Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or a related field. Advanced degrees or certifications (e.g., CISM, CISSP, CISA, CRISC, ISO 27001 Lead Auditor) are highly preferred.
- Minimum of 8-10 years of experience in GRC, cybersecurity, or risk management, with at least 5 years in a leadership role.
- Proven expertise in IT and OT security frameworks, including NIST, ISO 27001, IEC 62443, and COBIT.
- Strong understanding of regulatory compliance in the energy sector (e.g., NERC CIP, local/regional energy regulations).
- Experience in conducting risk assessments, audits, and compliance gap analyses for complex, multi-environment systems.
- Excellent stakeholder management and communication skills, with the ability to influence senior leadership and cross-functional teams.
- Familiarity with GRC tools (e.g., RSA Archer, MetricStream, ServiceNow GRC) and security technologies (e.g., SIEM, IAM, endpoint protection).
- Demonstrated ability to develop and implement security policies, standards, and procedures at an enterprise level.