Match score not available

AVP - Global IS Governance, Risk and Compliance (GRC)

extra holidays - extra parental leave
Remote: 
Full Remote
Contract: 
Work from: 

Offer summary

Qualifications:

Master's degree in Business Administration, Computer Science, Information Systems, Cybersecurity, or a related field., 10+ years of experience in an information security environment with a focus on Global Governance, Risk, and Compliance., 5+ years of supervisory or management experience in a global organization., Strong knowledge of compliance frameworks and relevant regulations such as GDPR, SOX, and PCI-DSS..

Key responsabilities:

  • Develop and implement a Global GRC strategy aligned with organizational objectives.
  • Ensure adherence to global financial information security and privacy regulations.
  • Monitor emerging risks and adjust GRC strategies accordingly.
  • Collaborate with cross-functional teams to ensure cohesive risk management practices.

PRA Group (Nasdaq: PRAA) logo
PRA Group (Nasdaq: PRAA) Financial Services Large https://www.pragroup.com/
1001 - 5000 Employees
See all jobs

Job description

We invite you to explore a future with us at PRA Group, a diverse and growing company that has a tangible impact on the global economy.

Position Summary: 

AVP, Global IS Governance, Risk and Compliance (GRC)

The AVP, Global IS Governance, Risk and Compliance (GRC) will lead a team of diverse individuals and will be responsible for working with stakeholders across all of PRA Group’s Business Units. The AVP, Global IS GRC’s role is to assess and oversee all technology-related governance, risk, and compliance issues within the Information Technology and Information Security Departments, including auditing, security training and awareness, policy and procedure build and review, disaster recovery, incident response and data integrity. This includes providing objective internal and third-party risk assessments of the company's compliance with regulatory, organizational, and commercial requirements governing the organization's information technology systems.

The AVP, Global IS GRC will direct the development and implementation of policies, procedures, standards, and controls to ensure that the organization's practices remain observant to all pertinent local, state/province/county and federal laws and industry standards. The AVP, Global IS GRC will support the CISO with departmental operational tasks including budgeting, strategy, metrics development/delivery, and project alignment.

In this role, the AVP, IS GRC will work directly with non-IT compliance professionals such as legal, audit and corporate compliance to ensure organizational alignment.

Required Education and Experience:

  • Master's degree in Business Administration, Computer Science, Information Systems, Cybersecurity, or a related field.
  • 10+ years’ experience in an information security environment, with a strong focus on Global Governance, Risk, and Compliance.
  • 5+ years’ supervisory or management experience, preferably in a global organization.
  • Strong experience with Governance, Risk, and Compliance frameworks, including IT control self-assessment, measurement, remediation, exception management, reporting, and advanced IT risk evaluation.
  • Demonstrated expertise and leadership in risk frameworks.
  • Strong knowledge of the Sarbanes-Oxley Act, System and Organization Controls (SOC) framework, ISO 27000 Framework, PCI-DSS, and SEC guidance related to audits of the internal control environment. Also, familiar with PIPEDA (Canada), GLBA, SOX (USA), LGPD (Brazil), and the Privacy Act 1988 (Australia.
  • Strong background regarding audits, compliance, privacy (GDPR and DORA) and security provisions 
  • Certifications such as CISSP, CISA, CISM, CRISC, or other relevant certifications are required.

Key Responsibilities:

  • Develop and implement a Global GRC strategy that aligns with the organization’s objectives and risk appetite. Ensure integration of GRC activities with enterprise risk management and corporate governance frameworks.
  • Ensure adherence to global financial information security and privacy regulations, including GDPR (Europe), PIPEDA (Canada), GLBA, SOX (USA), LGPD (Brazil), the Privacy Act 1988 (Australia), DORA (Europe), SOC2, and PCI-DSS.
  • Monitor emerging risks, including technological advancements and regulatory changes, to proactively adjust GRC strategies.
  • Foster a culture of risk awareness by leading training and awareness programs across the organization.
  • Collaborate with cross-functional teams, including legal, audit, and corporate compliance, to ensure cohesive risk management practices.
  • Oversee the continuous improvement of the GRC program, incorporating best practices and industry standards.
  • Work directly with the data protection officer (DPO) and Privacy Program to ensure company adherence to data privacy and data governance requirements.
  • Manage and develop teams’ knowledge on GRC and data privacy matters.
  • Advise on GRC matters and recommend courses of action to the Chief Information Security Officer.
     

At PRA Group, we're committed to helping our employees reach their highest potential by offering competitive salaries with bonus structure, LTI, proprietary training programs, tuition reimbursement programs, comprehensive healthcare, health, dental and vision benefits, maternal and paternal leave, holiday pay and PTO, an employee assistance program, and valuable opportunities to establish a long career within our organization.

Salary Range:

$147,000.00 - $237,000.00

PRA Group has an effective process for assessing market data and establishing ranges to ensure we remain competitive. Actual compensation is influenced by a wide array of factors including but not limited to skill set, level of experience, specific working location and market position. This posted salary range is a good faith and reasonable estimate, and PRA Group reserves the right to adjust this range depending on the qualifications and location of the selected candidate.  In addition to base salary, PRA may offer additional benefits to include performance based bonus programs and/or equity programs depending on the position.  PRA offers paid time off, medical, dental, vision, 401k match, life insurance, and other benefits to assist with the physical and mental wellbeing of our employees.

All qualified applicants will receive consideration for employment regardless of age, race, color, sex, gender, religion, national origin, physical or mental disability, citizenship, or any other classes recognized by state or local law or any other characteristic protected under applicable federal, state or local law. We are a drug free workplace.

Required profile

Experience

Industry :
Financial Services
Spoken language(s):
English
Check out the description to know which languages are mandatory.

Other Skills

  • Governance
  • Training And Development
  • Collaboration
  • Communication
  • Leadership

Related jobs