FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

GRC Lead
SALMON ROBOTICS LIMITED. Own information security risk management, control assurance, and ISO 27001 ISMS governance across a regulated group spanning banking, consumer finance, and technology .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in information security risk management, including ISO 27001 governance, control effectiveness assessment, and risk reporting. Proficient in managing security controls and collaborating with stakeholders to ensure compliance and effective risk treatment.
Highest-signal resume keywords
Information Security Risk ManagementISO 27001 GovernanceControl Effectiveness AssessmentGRC PlatformsRisk Reporting
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Risk AssessmentControl AssuranceVulnerability ManagementData ProtectionSecure DevelopmentIAMCloud SecurityEndpoint SecurityControl TestingRisk Appetite
Soft Skills
CollaborationCommunication
Tools & Technologies
GRC PlatformsStructured Risk RegistersEvidence Management
Industry Keywords
BankingConsumer FinanceTechnologyRisk RegisterKey Risk IndicatorsControl Metrics
Tech Stack
Tools & technologiesCloud
About the role
Key responsibilities & impact- Own information security risk management, control assurance, and ISO 27001 ISMS governance across a regulated group spanning banking, consumer finance, and technology
- Form an independent view of security risk and challenge whether proposed controls address it, working directly with the Group CISO
- Assess control design and operating effectiveness across IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure development
- Turn risk and control data into clear, decision-ready reporting for governance forums
- Own the security risk process end to end, including assessment, treatment, acceptance, monitoring, and reporting
- Maintain the risk register and challenge risk assessments and treatment plans
- Maintain the security control framework and test controls using evidence, data, sampling, or technical validation
- Drive remediation with control owners
- Maintain the ISO 27001 ISMS, including policies and standards, Statement of Applicability, risk records, control evidence, exceptions, and key security registers
- Track control deficiencies, findings, exceptions, and remediation actions
- Define KRIs and control metrics and flag where management decisions or escalation are needed
Requirements
What you’ll need- Strong practical experience in information security risk management, including inherent and residual risk, treatment, acceptance, control effectiveness, and risk appetite
- Technical depth to critically assess controls across IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure development
- Hands-on experience reviewing or testing controls
- Working knowledge of ISO 27001
- Ability to turn complex risk and control information into concise management reporting
- Comfortable working with GRC platforms, structured risk and control registers, and evidence management
- Ability to work core collaboration hours from 12:00 to 6:00 PM Manila time (UTC+8)
- English proficiency level required as part of the application
Benefits
Comp & perks- Fully remote work with core collaboration hours from 12:00 to 6:00 PM Manila time (UTC+8)
- Company-provided tools and equipment
- Medical insurance support for you and your family through co-funding or reimbursement, depending on your location and subject to policy limits
- Access to an internal mental health support specialist
- 22 vacation days
- Philippine public holidays
- 15 sick days
- Opportunities to learn and share expertise through internal expert meetups, external conferences, speaking opportunities, and industry publications
- Company-sponsored trips to Manila to meet and work with the team in person
- High-performing teams can earn a dedicated beach house week in Southeast Asia