Cyber Security GRC Lead

Nawy Real Estate · Posted 2026-04-08

We are seeking an experienced GRC Lead to drive governance, risk, and compliance activitiesin Nawy. This role ensures that security risks are identified, assessed, and managed whilemaintaining compliance with relevant regulatory and industry standards.The GRC lead leads the risk governance initiatives, oversees audits, develops policies,manages security awareness, and partners closely with engineering, product, and legal teamsto ensure secure-by-design operations across the entire organization.Responsibilities● Maintain an enterprise-wide information security governance & ISMS framework thataligns with business objectives, regulatory requirements, and industry best practices.● Develop, maintain, and enforce security policies, standards, and procedures.● Lead strategic planning initiatives for security risk management, ensuring alignmentwith ISO 27001 requirements.● Design, implement, and manage a security risk management framework that includesrisk assessments, control evaluations, and mitigation strategies.● Oversee and continuously improve the processes for vendor security risk assessments,ensuring third-party risks are effectively managed.● Develop and monitor key risk indicators (KRIs) and performance metrics to evaluate theeffectiveness of security controls and risk mitigation efforts.● Oversee the development, implementation, and ongoing management of theorganization’s security policies.● Prepare and lead the organization’s readiness for external and internal security audits,including ISO 27001 certification audits.● Build and run security awareness and phishing simulation programs and promote anorganization-wide culture of security accountability.● Ensure ongoing compliance with local regulatory frameworks, including those issued byCBE, FRA, and related bodies.

Apply for this role