This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We’re looking for a dynamic, experienced Head of GRC to lead our global governance, risk and compliance agenda. It’s a key leadership role, reporting to the CISO, where you’ll have the opportunity to transform a next-gen GRC function that supports PPRO’s exciting growth trajectory. This role is central to our vision as GRC as a business enable, maintaining our global regulatory posture while supporting our cloud-native, API-first payments business with operations across the EU, UK, LATAM, US and APAC. It’s an exciting opportunity to drive strategic improvements across our enterpriseGRC framework, ensuring alignment with DORA, ISO27001, PCI DSS v4.0 and international regulatory requirements (e.g. CSSF requirements in Luxembourg, FCA in UK). A strategic thinker, you’ll bring a modern, engineering-aware approach to GRC, focusing on smart automation, scalable processes and low-friction compliance, driving our 'secure-by-design, continuous compliance’ culture across multiple continents and complex regulatory regimes. This role has strategic breadth, operational depth and high visibility with senior cross-organisational stakeholders, regulators, auditors and customers. Your combination of regulatory discipline, operational pragmatism, strong leadership and deep customer-focus will build credibility and trust.
Job Responsibility:
Lead PPRO’s global Security GRC strategy and team, to support our international regulatory and compliance footprint
Oversee and enhance our ISO27001:2022 and PCI DSS v4.0 programmes, building a culture of continuous compliance through automation and control transformation
Partner with relevant functions to ensure ongoing DORA compliance, including security risk management, incident reporting, operational resilience testing and governance
Define and deliver a strategy for a pragmatic, high-value 2nd line automated control assurance programme, underpinned by relevant business metrics
Own and manage regulatory expectations on security topics by the CSSF in Luxembourg, FCA in the UK and other international bodies as relevant
Maintain and enhance PPRO’s security risk register, defining and delivering cross-organisation improvement and remediation roadmaps
Lead security control testing, issue management, KRI monitoring, SLA reporting and Board-level reporting
Act as Information Security Officer for PPRO’s local Luxembourg entity
Own third party security risk management and oversight for PPRO across the full procurement lifecycle
Partner closely with Engineering to build shared understanding and transform controls via thoughtful automation, streamlining evidence collection and control monitoring
Act as the primary face to external auditors, regulatory examiners and major enterprise customers
Manage internal and external audits end-to-end, ensuring preparation, evidence readiness and smooth execution
Continually refine PPRO’s “always audit-ready” operating model
Coach colleagues across Product, Engineering and business functions on regulatory expectations and risk-informed decision-making
Operate as a trusted partner to leadership teams, bringing pragmatic recommendations and crisp communication
Requirements:
A proven track record transforming traditional GRC frameworks (ISO27001, PCI DSS, SOC2) into modern, automated, developer-friendly control assurance programmes
Solid grounding in financial services regulation, payments, operational resilience, outsourcing/cloud guidelines etc.
Strong experience interacting with regulators and auditors (CSSF, FCA, etc.) and implementing regulatory requirements
Proven ability to run risk management processes, control frameworks and audit cycles
Experience evaluating technology, cyber and operational risks in a cloud-native environment
Engineering-first mindset, with an understanding of cloud-native architectures (AWS preferred) and how GRC requirements fit into engineering workflows
Experience with GRC tooling, workflow automation or process optimisation
Ability to translate regulatory requirements into practical, technical control expectations
Excellent communicator, capable of influencing executives, engineers, auditors and regulators
Pragmatic, commercially-minded, empathetic and customer-focused
Deeply collaborative, comfortable and effective operating in a fast-paced, ambiguous environment
What we offer:
Hybrid working with a 3 days / week on site expectation
Work from abroad policy, enabling employees to work remotely for up to another 30 days per year