Skip to main content
zerohash
zerohash

Senior Risk Management / GRC Manager

RemoteNetherlands only
Published
Role
Security
Experience
Senior
Employment
Contract
Salary not disclosed
Check eligibility

Open to NL only. Set where you work from to check your eligibility.

No BS summary

Senior GRC/Risk manager to own DORA compliance and IT security governance at a crypto/fintech infrastructure company. Must have prior GRC leadership experience and hands-on DORA experience; CISSP/CISM/CRISC/CISA certifications are a plus. Only candidates based in the Netherlands will be considered.

What you'll do

  • Own and manage day-to-day compliance with DORA
  • Stay current on relevant laws and regulations (DORA, GDPR, NY DFS Part 500)
  • Manage technical compliance programs and conduct compliance assessments
  • Prepare compliance reports and documentation for regulatory audits
  • Develop and maintain governance policies, procedures, and standards
  • Manage governance frameworks such as ISO 27001, SOC 1, SOC 2
  • Develop and implement IT security strategies and solutions
  • Manage and monitor security systems (firewalls, intrusion detection, endpoint protection)
  • Conduct security assessments, vulnerability scans, and penetration tests
  • Respond to and resolve security incidents, including forensic investigations and root cause analysis
  • Identify, assess, and prioritize technical risks
  • Develop risk management strategies and mitigation plans
  • Monitor and track risk mitigation activities
  • Develop and implement technical security policies and procedures
  • Oversee the technical incident management process
  • Develop and deliver security, governance, risk, and compliance training programs
  • Collaborate with internal and external stakeholders (auditors, regulators, technical teams)
  • Prepare and present technical reports to senior management and the board

What they require

  • Prior experience in a Risk Management / GRC leadership role (required)
  • Prior experience with the Digital Operational Resilience Act (DORA) (required)
  • Professional certifications such as CISSP, CISM, CRISC or CISA (plus)
  • Proven experience in technical IT security, governance, risk management, and compliance roles
  • Strong technical knowledge of IT governance frameworks, regulatory requirements, and best practices
  • Experience with SOC 1, SOC 2, and ISO 27001 (strongly preferred)
  • Strong analytical and problem-solving skills with attention to detail
  • Ability to manage multiple technical projects and priorities in a fast-paced environment
  • Experience with technical security and GRC tools and software
  • Excellent communication and interpersonal skills, with the ability to collaborate effectively with cross-functional teams
  • Proficiency in risk assessment methodologies and tools
  • Experience with IT audit processes and procedures
  • Knowledge of GDPR, NYDFS Part 500 (plus)

Benefits

  • Chance to earn equity
  • Maternity & Paternity leave
  • WeWork Membership
  • WFH Yearly Stipend
  • L&D Stipend (after 6 months)

zerohash is the leading crypto infrastructure platform powering major fintech names.

CryptoMid-sizezerohash.com
Salary not disclosed