CrawlJobs Logo

Head of Security Governance, Risk & Compliance

ppro.com Logo

PPRO GmbH

Location Icon

Location:
Luxembourg , Luxembourg

Category Icon

Job Type Icon

Contract Type:
Not provided

Salary Icon

Salary:

Not provided

Job Description:

We’re looking for a dynamic, experienced Head of GRC to lead our global governance, risk and compliance agenda. It’s a key leadership role, reporting to the CISO, where you’ll have the opportunity to transform a next-gen GRC function that supports PPRO’s exciting growth trajectory. This role is central to our vision as GRC as a business enable, maintaining our global regulatory posture while supporting our cloud-native, API-first payments business with operations across the EU, UK, LATAM, US and APAC. It’s an exciting opportunity to drive strategic improvements across our enterpriseGRC framework, ensuring alignment with DORA, ISO27001, PCI DSS v4.0 and international regulatory requirements (e.g. CSSF requirements in Luxembourg, FCA in UK). A strategic thinker, you’ll bring a modern, engineering-aware approach to GRC, focusing on smart automation, scalable processes and low-friction compliance, driving our 'secure-by-design, continuous compliance’ culture across multiple continents and complex regulatory regimes. This role has strategic breadth, operational depth and high visibility with senior cross-organisational stakeholders, regulators, auditors and customers. Your combination of regulatory discipline, operational pragmatism, strong leadership and deep customer-focus will build credibility and trust.

Job Responsibility:

  • Lead PPRO’s global Security GRC strategy and team, to support our international regulatory and compliance footprint
  • Oversee and enhance our ISO27001:2022 and PCI DSS v4.0 programmes, building a culture of continuous compliance through automation and control transformation
  • Partner with relevant functions to ensure ongoing DORA compliance, including security risk management, incident reporting, operational resilience testing and governance
  • Define and deliver a strategy for a pragmatic, high-value 2nd line automated control assurance programme, underpinned by relevant business metrics
  • Own and manage regulatory expectations on security topics by the CSSF in Luxembourg, FCA in the UK and other international bodies as relevant
  • Maintain and enhance PPRO’s security risk register, defining and delivering cross-organisation improvement and remediation roadmaps
  • Lead security control testing, issue management, KRI monitoring, SLA reporting and Board-level reporting
  • Act as Information Security Officer for PPRO’s local Luxembourg entity
  • Own third party security risk management and oversight for PPRO across the full procurement lifecycle
  • Partner closely with Engineering to build shared understanding and transform controls via thoughtful automation, streamlining evidence collection and control monitoring
  • Act as the primary face to external auditors, regulatory examiners and major enterprise customers
  • Manage internal and external audits end-to-end, ensuring preparation, evidence readiness and smooth execution
  • Continually refine PPRO’s “always audit-ready” operating model
  • Coach colleagues across Product, Engineering and business functions on regulatory expectations and risk-informed decision-making
  • Operate as a trusted partner to leadership teams, bringing pragmatic recommendations and crisp communication

Requirements:

  • A proven track record transforming traditional GRC frameworks (ISO27001, PCI DSS, SOC2) into modern, automated, developer-friendly control assurance programmes
  • Solid grounding in financial services regulation, payments, operational resilience, outsourcing/cloud guidelines etc.
  • Strong experience interacting with regulators and auditors (CSSF, FCA, etc.) and implementing regulatory requirements
  • Proven ability to run risk management processes, control frameworks and audit cycles
  • Experience evaluating technology, cyber and operational risks in a cloud-native environment
  • Engineering-first mindset, with an understanding of cloud-native architectures (AWS preferred) and how GRC requirements fit into engineering workflows
  • Experience with GRC tooling, workflow automation or process optimisation
  • Ability to translate regulatory requirements into practical, technical control expectations
  • Excellent communicator, capable of influencing executives, engineers, auditors and regulators
  • Pragmatic, commercially-minded, empathetic and customer-focused
  • Deeply collaborative, comfortable and effective operating in a fast-paced, ambiguous environment
What we offer:
  • Hybrid working with a 3 days / week on site expectation
  • Work from abroad policy, enabling employees to work remotely for up to another 30 days per year
  • €1,000 annual budget for professional growth
  • Leadership cafés, on-the-job training
  • Lunch Vouchers - 12,80euros x 18 / month
  • Enhanced family leave
  • Travel Insurance
  • Gym membership contribution
  • Mental Health Platform
  • Pet-friendly office

Additional Information:

Job Posted:
January 04, 2026

Employment Type:
Fulltime
Work Type:
Hybrid work
Job Link Share:

Looking for more opportunities? Search for other job offers that match your skills and interests.

Briefcase Icon

Similar Jobs for Head of Security Governance, Risk & Compliance

Security Strategy and Risk Management Head of Department

The Security Strategy and Risk Management Head of Department is a senior leaders...
Location
Location
United States , Irvine
Salary
Salary:
181240.00 - 259160.00 USD / Year
haeaus.com Logo
Hyundai AutoEver America
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 15–20 years of progressive experience across Information Security, GRC/Risk Management, customer/vendor security management and/or strategic operations
  • Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, Business Administration or a related discipline
  • Excellent stakeholder management, communication, and leadership skills
  • Demonstrated experience working across multi-disciplinary teams to achieve common objectives
  • Proficient in English for effective communication and coordination
Job Responsibility
Job Responsibility
  • Lead enterprise-wide risk assessment, risk issue management, and risk exception management
  • Maintain and enhance risk management frameworks aligned with industry best practices
  • Deliver insightful, data-driven risk reporting to senior leadership
  • Oversee the Information Security compliance and control assurance program
  • Lead coordination of internal and external audits, assessments, and certification processes
  • Lead the Third-Party Risk Management (TPRM) program
  • Oversee creation, governance, maintenance, and communication of Information Security policies, standards, and procedures
  • Direct the Information Security Training and Awareness program
  • Partner with the CISO to define and maintain the Information Security strategic roadmap
  • Lead budget planning, forecasting, tracking, and optimization for the full Information Security organization
  • Fulltime
Read More
Arrow Right

Head of Security

OpenSea is the gateway to web3’s next chapter—where NFTs, fungible tokens, and e...
Location
Location
United States
Salary
Salary:
270000.00 - 350000.00 USD / Year
opensea.io Logo
OpenSea
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 10+ years in security, with experience at a crypto company that ships quickly
  • Practical knowledge of blockchain security and crypto-specific attack vectors
  • Deep expertise operating in a cloud-hosted environment (AWS preferred)
  • Experience developing and implementing large-scale security strategies in a software company
  • Expertise in risk management, incident response, and security governance within the crypto space
  • Proven ability to communicate effectively with both technical and executive stakeholders
  • Passion for improving crypto security combined with a methodical approach to solving complex security challenges
  • High ownership mentality
  • AI-forward mindset with hands-on experience adopting and integrating AI tools
Job Responsibility
Job Responsibility
  • Take hands-on ownership of all aspects of security at OpenSea including threat detection/response, infra, application & organizational security
  • Establish robust risk management processes, conducting regular assessments to identify vulnerabilities and implement mitigation strategies
  • Lead incident response and crisis management efforts, ensuring the organization can respond effectively to security threats
  • Foster a security-first culture through awareness programs and by engaging with stakeholders across all functions
  • Oversee security compliance initiatives and align with relevant industry standards while enabling our startup agility
  • Collaborate with executive leadership to ensure security initiatives support OpenSea's business goals
What we offer
What we offer
  • Health Benefits: We cover 100% Dental/Vision/Medical for employees and 90% for dependents
  • Flexible Time Off Policy
  • Parental Leave: 16 Weeks of Paid Parental Bonding & up to 8 additional weeks for the birthing parent
  • Mental Health: We offer access to Spring Health, covering 8 therapy & 8 coaching sessions per year
  • 11 Company Holidays
  • Fidelity 401K Plan
  • Internet/Mobile Reimbursement Plan
  • Reimbursement or Monthly Snack Delivery
  • Company & Team retreats
  • Team Member Co-Working and Gathering Expense
  • Fulltime
Read More
Arrow Right

Head of Cyber Security Operations Process Strategy and Optimization

The Cyber Security Operations (CSO) organization is seeking a highly motivated a...
Location
Location
Ireland , Dublin
Salary
Salary:
Not provided
https://www.citi.com/ Logo
Citi
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 10+ years of professional experience in cybersecurity, technology risk management, or a related field
  • Extensive experience in Cyber Security Operations is highly preferred
  • Proven track record of leading large-scale business process re-engineering, process design, and optimization initiatives with measurable results
  • Demonstrated expertise in developing service maps, process documentation, and workflows using technologies such as Visio, JIRA, and other workflow management tools
  • Strong knowledge of continuous improvement models (e.g., Six Sigma, Lean) and their practical application in a technology or security environment
  • Experience in identifying and implementing automation and AI solutions, with a firm understanding of best practices and their impact on operational efficiency
  • Exceptional ability to identify financial and efficiency opportunities within complex operational processes
  • Proven leadership skills with the ability to influence and partner with senior stakeholders across a global organization
  • Excellent communication, presentation, and negotiation skills, with the ability to articulate complex concepts to both technical and non-technical audiences
Job Responsibility
Job Responsibility
  • Act as a direct transformation partner to CSO operational teams, driving a strategic agenda focused on operational excellence, efficiency, and scalability
  • Lead the identification, design, and execution of high-impact opportunities for process re-engineering
  • Develop, maintain, and govern a comprehensive inventory of all CSO Services, their supporting processes, and their interrelationships
  • Define, monitor, and report on strategic metrics for both operational performance and risk posture
  • Serve as the central hub for identifying, vetting, and prioritizing AI and automation candidates
  • Champion and embed methodologies like Six Sigma to foster a culture of operational excellence
  • Build and maintain strong relationships with senior leaders and operational teams across CSO
  • Appropriately assess risk when business decisions are made
  • Drive compliance with applicable laws, rules, and regulations
  • Lead business process re-engineering and operational excellence efforts
What we offer
What we offer
  • Competitive base salary, annually reviewed
  • Hybrid working model
  • Business casual workplace
  • Additional benefits to support well-being, growth, and work-life balance
  • Fulltime
Read More
Arrow Right

Head of Custody

Blockchain.com is connecting the world to the future of finance. As the most tru...
Location
Location
Malta
Salary
Salary:
Not provided
blockchain.com Logo
Blockchain
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 5+ years in financial operations, custody, or risk management
  • 3+ years specifically in digital asset custody
  • Proven experience operating under regulatory frameworks such as MiFID or MiCA
  • Understanding of custody technologies: MPC, HSMs, cold storage, wallet security
  • Strong organizational and communication skills with stakeholder and regulator engagement experience
  • Demonstrated success in high growth, regulated environments with strong problem-solving skills
  • Experience interacting with EU regulators (e.g., MFSA)
  • Knowledge of blockchain infrastructure and staking or settlement mechanics
  • Leadership experience in institutional custody operations
  • Familiarity with regulatory reporting, operational due diligence, and audit readiness
Job Responsibility
Job Responsibility
  • Act as the Head of Custody for Blockchain.com’s operations in Malta and the EU, accountable for custody operations and regulatory compliance
  • Oversee all elements of digital asset custody including wallet architecture, key management, and transaction workflows
  • Implement governance and internal control frameworks aligned with MiCA and MFSA standards
  • Lead regulatory reporting and ensure traceability and segregation of client assets
  • Develop and maintain custody-related business continuity and incident response protocols, ensuring operational resilience in line with DORA
  • Continuously assess custody risks and introduce mitigations to maintain high security and reliability
  • Partner with Legal, Compliance, Product, Risk, Wallet Operations and Security teams to ensure strategic alignment of custody operations
  • Serve as a subject-matter expert in custody across cross-functional initiatives including product launches (e.g., staking, tokenized assets, institutional settlement)
  • Represent Blockchain.com’s custody capabilities in institutional onboarding, product design, and sales enablement
  • Monitor the evolving custody regulatory landscape to maintain compliance and innovation leadership
What we offer
What we offer
  • Bonus scheme based on both company and individual performance
  • Unlimited vacation policy
  • Apple equipment provided by the company
  • Work from Anywhere Policies
  • Fulltime
Read More
Arrow Right

Senior Compliance Sanctions Officer

Serves as a senior compliance risk officer for Independent Compliance Risk Manag...
Location
Location
Ireland , Dublin
Salary
Salary:
Not provided
https://www.citi.com/ Logo
Citi
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Expertise of Global Sanctions regulations, risks and typologies, including restrictive measures imposed by the OFAC, the OFSI and the European Commission
  • Broad knowledge of global capital markets products
  • Understanding of securities services and trading
  • Knowledge of securities settlements processes and transactions flows
  • Ability to clearly communicate with business heads providing credible challenge in difficult situations
  • Expertise of Compliance laws, rules, regulations, risks and typologies and interpretations of the regulations
  • Excellent written, verbal and analytical skills
  • Must be a self-starter, flexible, innovative and adaptive
  • Highly motivated, strong attention to detail, team oriented, organized
  • Strong presentation skills with the ability to articulate complex problems and solutions through concise and clear messaging
Job Responsibility
Job Responsibility
  • Provide sanctions guidance to Citi's Markets Businesses transacting in Global Capital Markets products
  • Provide sanctions oversight of in business controls and review in-flight and proposed transactions involving capital markets products
  • Executing and implementing firm-wide sanctions risk management policy as well as the strategic ICRM direction
  • maintaining the sanctions compliance program for the businesses (assessment of risks, development of policies, procedures, governance)
  • Designing and maintaining elements of the ICRM Sanctions Framework
  • Advising and overseeing adherence to procedures and processes for compliance by front line units meet required standards
  • Directing technology solutions that enable effective and efficient compliance risk management solutions
  • Supporting investigations and interactions with the U.S. Treasury Departments' Office of Foreign Assets Control (OFAC), competent authorities of the European Union (E.U.) Member States, the Office of Financial Sanctions Implementation of the HM Treasury (“OFSI”) and/or local government authorities
  • Monitoring adherence to Citi’s Global Sanctions Policy and relevant procedures to verify adherence to applicable requirements
  • Working closely with ICRM Compliance Assurance and Internal Audit in the evaluation of results and proposed remedial actions, identifying opportunities to conduct more targeted comprehensive reviews
What we offer
What we offer
  • business casual workplace
  • hybrid working model
  • competitive base salary
  • additional benefits that support you (and your family) to be well, live well and save well
  • Fulltime
Read More
Arrow Right

Global Data Privacy Counsel

We are looking for a senior attorney with extensive experience in global data pr...
Location
Location
United States , Atlanta
Salary
Salary:
Not provided
arrive.com Logo
Arrive
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Juris Doctor degree from a reputable, accredited U.S. law school
  • Active license in good standing with one or more U.S. state bars (Georgia preferred)
  • 10+ years of progressive experience in data privacy and cybersecurity legal matters, with significant in-house experience at a high-growth, technology-driven company
  • Deep expertise and knowledge of and hands-on experience with U.S. and international data privacy, cybersecurity, and compliance laws and frameworks (including GDPR, CCPA/CPRA, PCI-DSS, ISO certifications, and other relevant global standards) and leading-edge AI regulations and frameworks
  • Demonstrated success in providing strategic legal counsel that balances risk management with enabling innovation and business growth, particularly in payments and data-driven initiatives
  • Proven experience leading global privacy and data protection programs, including managing privacy and data protection risk frameworks and governance
  • Experience managing external counsel, auditors, and regulators
  • Proven ability to lead, develop, and inspire diverse, global teams, including direct leadership experience with Data Protection Officers and other privacy professionals
  • Strong business acumen with the ability to translate complex legal concepts into clear, actionable advice that aligns with business objectives and supports deal-making and sales acceleration
  • Excellent communication and interpersonal skills, with the ability to influence stakeholders at all levels, including senior executives and cross-functional teams globally
Job Responsibility
Job Responsibility
  • Serve as a trusted strategic legal advisor to executive leadership, business unit and function heads, and the governance committees on global privacy, data protection, and cybersecurity risks, as well as opportunities aligned with rapid business growth and innovation
  • Design, lead, and continuously evolve the global privacy and data protection program, ensuring it not only meets regulatory requirements but also supports scalable growth and competitive advantage in a fast-paced, high-growth environment
  • Partner closely with product, technology, payments, data, software and hardware sales, marketing, and strategy teams to embed privacy-by-design and data governance principles into all data-driven and payment-related initiatives
  • Advise on privacy, data protection, cross-border data processing, and emerging technologies (AI and machine learning), in connection with parking, public transport and other urban mobility technologies and data services (B2B, B2C), to help the company navigate these complex regulatory environments while accelerating innovation
  • Balance risk management with enabling agility—help business units achieve their ambitious growth objectives without compromising compliance or customer trust
  • Lead and manage a global, unified privacy and data protection team, including the EU Data Protection Officer and EU Privacy Program Manager, and serve as the global privacy and data protection leader responsible for harmonizing privacy and data protection practices across all regions
  • Act as the company’s U.S. and Canada Privacy Officer, overseeing all U.S.-specific and Canada-specific aspects of the global privacy and data protection program
  • Own enterprise-wide development, implementation, and continuous improvement of privacy and data protection policies, standards, and frameworks aligned with relevant global privacy and data protection-related regulations
  • Develop and maintain a privacy and data protection risk management framework and a dashboard of key privacy metrics to inform leadership decision making and monitor program effectiveness in a high-growth environment
  • Lead privacy and data protection audits and program assessments to ensure compliance and identify areas for improvement aligned with rapid company growth
Read More
Arrow Right

Head of Security

Prezzee is a global leader in digital gifting and payments. As our Head of Secur...
Location
Location
Australia , Melbourne
Salary
Salary:
Not provided
prezzee.com.au Logo
Prezzee
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • A degree in Computer Science, Software Engineering, or a related discipline
  • 5+ years’ experience in a senior cyber security role, ideally within a systems development or technology-led environment
  • Strong understanding of AWS technologies and modern cloud architecture models
  • Proven experience delivering strategic security programs, including policy development, risk management, BCP/DR testing, third-party risk, and end-user device security
  • Hands-on experience triaging, investigating, and resolving security and operational incidents within SLAs
  • Deep knowledge of modern cyber security principles, threat landscapes, threat intelligence, and remediation techniques
  • Experience coordinating outcomes across internal teams, external vendors, auditors, and security partners
  • A collaborative, business-minded approach with the confidence to influence at leadership level
Job Responsibility
Job Responsibility
  • Lead Our Security Strategy: Own and deliver a clear, ongoing security roadmap aligned to Prezzee’s risk appetite, business priorities, and growth plans
  • Continuously uplift our administrative, technical, and procedural security posture across the business
  • Stay ahead of emerging threats and evolving standards, ensuring Prezzee remains proactive rather than reactive
  • Build a Security-First Culture: Act as the Security Champion across all teams and locations, embedding security awareness into how we work every day
  • Partner closely with engineering, product, IT, and the wider business to ensure security is at the forefront of design
  • Manage and mentor a small, high-performing security team, driving engagement and alignment with Prezzee’s purpose
  • Governance, Risk & Compliance: Maintain and expand compliance with frameworks and certifications including PCI, ISO:27001, Cyber Essentials+, ISO:42001 and others as required
  • Chair and manage the ISMS Committee, ensuring stakeholders have clear visibility of risks, controls, and progress
  • Lead third-party and vendor security due diligence across tools, partners, and workplace technology
  • Operational Security & Incident Management: Oversee vulnerability management, penetration testing outcomes, and remediation within agreed SLAs
What we offer
What we offer
  • Prezzeeversary Leave – Extra day of annual leave for each year you’re with us
  • BirthYay Leave – Celebrate you with a paid day off during your birthday month
  • Novated Car Leasing – A tax-smart way to bundle and pay for your car and running costs
  • ClassPass Membership – Fully covered monthly credits for fitness, wellness, and beauty
  • Office Allowance – One-time payment to upgrade your office setup
  • Flexible Work Perks – Flex your hours, take Culture Swap Days, and work from anywhere for 30 days a year
  • Prezzee Staff Discounts – Exclusive deals on Prezzee gift cards – just for being part of the team
  • Wellbeing Support – Access to mental, social, financial, and physical wellbeing support via Telus
  • Learning & Development – Grow your career with LinkedIn Learning, job shadowing, industry programs, and our Lunch & Learn sessions
  • Employee Resource Groups – Be an advocate or ally and foster belonging through groups like EmpowHer and Pride
  • Fulltime
Read More
Arrow Right

Head of Security

As our Head of Security, you’ll play a critical role in protecting the trust our...
Location
Location
Australia , Sydney
Salary
Salary:
Not provided
prezzee.com.au Logo
Prezzee
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • A degree in Computer Science, Software Engineering, or a related discipline
  • 5+ years’ experience in a senior cyber security role, ideally within a systems development or technology-led environment
  • Strong understanding of AWS technologies and modern cloud architecture models
  • Proven experience delivering strategic security programs, including policy development, risk management, BCP/DR testing, third-party risk, and end-user device security
  • Hands-on experience triaging, investigating, and resolving security and operational incidents within SLAs
  • Deep knowledge of modern cyber security principles, threat landscapes, threat intelligence, and remediation techniques
  • Experience coordinating outcomes across internal teams, external vendors, auditors, and security partners
  • A collaborative, business-minded approach with the confidence to influence at leadership level
Job Responsibility
Job Responsibility
  • Lead Our Security Strategy: Own and deliver a clear, ongoing security roadmap aligned to Prezzee’s risk appetite, business priorities, and growth plans
  • Continuously uplift our administrative, technical, and procedural security posture across the business
  • Stay ahead of emerging threats and evolving standards, ensuring Prezzee remains proactive rather than reactive
  • Build a Security-First Culture: Act as the Security Champion across all teams and locations, embedding security awareness into how we work every day
  • Partner closely with engineering, product, IT, and the wider business to ensure security is at the forefront of design
  • Manage and mentor a small, high-performing security team, driving engagement and alignment with Prezzee’s purpose
  • Governance, Risk & Compliance: Maintain and expand compliance with frameworks and certifications including PCI, ISO:27001, Cyber Essentials+, ISO:42001 and others as required
  • Chair and manage the ISMS Committee, ensuring stakeholders have clear visibility of risks, controls, and progress
  • Lead third-party and vendor security due diligence across tools, partners, and workplace technology
  • Operational Security & Incident Management: Oversee vulnerability management, penetration testing outcomes, and remediation within agreed SLAs
What we offer
What we offer
  • Prezzeeversary Leave – Extra day of annual leave for each year you’re with us
  • BirthYay Leave – Celebrate you with a paid day off during your birthday month
  • Novated Car Leasing – A tax-smart way to bundle and pay for your car and running costs
  • ClassPass Membership – Fully covered monthly credits for fitness, wellness, and beauty
  • Office Allowance – One-time payment to upgrade your office setup
  • Flexible Work Perks – Flex your hours, take Culture Swap Days, and work from anywhere for 30 days a year
  • Prezzee Staff Discounts – Exclusive deals on Prezzee gift cards – just for being part of the team
  • Wellbeing Support – Access to mental, social, financial, and physical wellbeing support via Telus
  • Learning & Development – Grow your career with LinkedIn Learning, job shadowing, industry programs, and our Lunch & Learn sessions
  • Employee Resource Groups – Be an advocate or ally and foster belonging through groups like EmpowHer and Pride
  • Fulltime
Read More
Arrow Right