Manager Governance Risk & Compliance (GRC)

Perceptive·
GBR - Decentralized
1mo ago
Full-timeMANAGERLegal & IPMasters
Market Rate — Lawyers
25th
$91K
Median
$146K
75th
$208K

BLS 2024 data (national)

Description

<p style="text-align:left">We’re on a mission to change the future of<br />clinical research. At Perceptive, we help the<br />biopharmaceutical industry bring medical<br />treatments to the market, faster.<br />Our mission is to change the world<br />but to do this, we need people like you.</p><h2></h2><h2></h2><h2><b>What can we offer you?</b></h2><p style="text-align:left">Apart from job satisfaction, we can offer you:</p><p style="text-align:left"><br /><b>YOURSELF</b><br />• 25 days’ holiday (with the option to buy more)</p><p style="text-align:left"><br /><b>HEALTH</b><br />• Health Cash Plan<br />• Optional private health, dental insurance, and health screens<br />• Cycle to work scheme</p><p style="text-align:left"><br /><b>WEALTH</b><br />• Generous pension scheme with up to 10% employer contribution<br />• Life assurance<br />• Season ticket loan</p><p style="text-align:inherit"></p><p style="text-align:left"><b>About the role</b></p><p></p><p><b><span>Job Purpose</span></b></p><p></p><p><span>The <b>Manager, Governance Risk &amp; Compliance (GRC)</b> is responsible for developing, implementing and maintaining governance, risk and compliance frameworks within Perceptive&#39;s security function. </span></p><p></p><p><span>Managing a small team, this role ensures adherence to ISO 27001 standards, manages internal and external audits and reviews contractual agreements (MSAs) for compliance with security and regulatory requirements. </span></p><p></p><p><b><span>Key Responsibilities</span></b></p><p></p><p><b>Governance &amp; Framework Management</b></p><ul><li><p>Maintain and enhance the organization’s Information Security Management System (ISMS) aligned with ISO 27001.</p></li><li><p>Develop and update security policies, standards, and procedures.</p></li><li><p>Ensure compliance with regulatory and contractual obligations.</p></li></ul><p></p><p><b>Risk Management</b></p><ul><li><p>Identify, assess, and monitor information security risks.</p></li><li><p>Maintain risk registers and ensure mitigation plans are in place.</p></li><li><p>Support business units in risk treatment and reporting.</p></li></ul><p></p><p><b>Compliance &amp; Audits</b></p><ul><li><p>Plan and execute internal audits for ISO 27001 and other relevant frameworks.</p></li><li><p>Coordinate external certification audits and liaise with auditors.</p></li><li><p>Track and manage audit findings and corrective actions.</p></li></ul><p></p><p><b>Contractual Reviews</b></p><ul><li><p>Review Master Service Agreements (MSAs), Statements of Work (SOWs), and vendor contracts for security and compliance clauses.</p></li><li><p>Collaborate with Legal and Procurement teams to ensure security requirements are embedded in agreements.</p></li><li><p>Advise on third-party risk management processes.</p></li></ul><p></p><p><b>Training &amp; Awareness</b></p><ul><li><p>Conduct security awareness sessions related to governance and compliance.</p></li><li><p>Provide guidance to stakeholders on compliance obligations.</p></li><li><p>Manage Cyber awareness and  phishing simulation platforms    </p></li></ul><p></p><p><b>Reporting &amp; Metrics</b></p><ul><li><p>Prepare regular compliance and risk reports for senior management.</p></li><li><p>Monitor key performance indicators (KPIs) for GRC activities.</p></li></ul><p></p><p><b>Functional Competencies (Technical knowledge/Skills)</b></p><ul><li><p>Ability to manage internal and external audits as they relate to cyber security.</p></li><li><p>Excellent interpersonal, verbal and written communication skills.</p></li><li><p>A flexible attitude with respect to work assignments and new learning.</p></li><li><p>Ability to manage multiple and varied tasks with enthusiasm and prioritize workload with attention to detail.</p></li><li><p>Ability to identify and implement process improvements.</p></li><li><p>Ability to manage a globally distributed team, including motivating, developing and coordinating team members.</p></li><li><p>Maintains an up-to-date awareness of trends, tools, technology, techniques and processes that affect cyber security GRC within the Life sciences domain.</p></li></ul><p></p><p><b>Experience, Education, and Certifications</b></p><ul><li><p>Proven experience in a similar GRC role in a regulated environment, ideally Life Sciences (GxP) but others acceptable (e.g., Financial, etc.).</p></li><li><p>Background in IT security governance within a global organization.</p></li><li><p>Previous experience as Lead Implementer/Auditor, CISM, CRISC or similar in an ISO 27001 accredited environment</p></li><li><p>Strong understanding of ISO 27001, risk management frameworks, and audit processes.</p></li><li><p>Proven experience of leading and mentoring a team..</p></li><li><p>Experience reviewing contracts and MSAs for security compliance.</p></li><li><p>Knowledge and understanding of regulations and frameworks relating data protection and cyber security (GDPR, SOC 2, NIS2, etc.).</p></li><li><p>Experience with GRC tools and platforms.</p></li><li><p>Bachelor’s degree or Engineering in IT/computer science/electronics</p></li><li><p>English: Fluent.</p></li></ul><p style="text-align:inherit"></p><p style="text-align:inherit"></p><p style="text-align:left"><b><span>Come as you are.</span></b><br /><span>We&#39;re proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, colour, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. </span></p>
Perceptive

Perceptive

BIOTECHNOLOGY

Medical Imaging

LocationUK - Nottingham
Open Jobs25
NeurologyOphthalmologyGastroenterologyHematology
View Company Profile

Pipeline

Vu-Path™N/A
Optical Coherence Tomography (OCT) Based Intraoral ScannerN/A