Senior Risk Manager (GRC)
- Experience
- Senior
The listing doesn't say where it hires from. Check the description or the employer's site before applying.
No BS summary
We’re looking for a Senior Risk Manager (GRC) to join our team and help strengthen our enterprise risk management, operational resilience, and governance practices.
Required skills
Required languages
Jira ticket
We’re looking for a Senior Risk Manager (GRC) to join our team and help strengthen our enterprise risk management, operational resilience, and governance practices.
As a Senior Risk Manager , you will help take MacPaw’s risk management practices to the next level. You’ll work across business, product, and service teams to identify and manage risks, turn them into actionable mitigation plans, strengthen business continuity, and contribute to the development of our AI Governance practices.
This role is a great fit for someone who sees risk management as a way to enable better business decisions – not simply as a compliance exercise.
If you’re excited to strengthen MacPaw’s operational resilience and help shape the next stage of our risk and governance practices, we’d love to hear from you!
In this role, you will:
Maintain and further develop enterprise risk registers across business, product, facilities, and company-wide risks.
Partner with risk owners across MacPaw to develop practical mitigation plans and integrate them into team priorities and OKRs.
Strengthen Business Continuity Planning (BCP) and operational resilience across core and non-core business functions, including incident and crisis-management preparedness.
Contribute to MacPaw’s AI Governance practices by supporting the AI system inventory, classification under the EU AI Act, and review processes for new AI use cases together with Legal, Compliance, and Product teams.
Support information security and company-wide audits, including SOC2 and ISO-related activities within your area of expertise.
Prepare risk insights and reporting for internal governance forums, including the Risk Committee.
Skills you’ll need to bring:
Solid experience in Enterprise Risk Management (ERM), GRC, or risk management, ideally within a technology, SaaS, product, or high-growth company.
Demonstrable experience building or maturing ERM frameworks and risk registers – not only maintaining established processes.
Hands-on experience developing risk mitigation plans and working with stakeholders to translate identified risks into concrete actions.
Hands-on experience with Business Continuity Planning (BCP), operational resilience, and crisis management.
Practical experience or strong working knowledge of EU technology regulation and AI Governance, such as the EU AI Act, GDPR, CRA, ISO/IEC 42001, NIST AI RMF, or similar frameworks.
Familiarity with GRC tools, workflow automation, dashboards, and data-driven risk reporting.
Strong stakeholder management and communication skills, with the ability to influence and collaborate with teams at different levels of risk-management maturity.
A business-enabler mindset and the ability to balance risk considerations with business needs and strategic priorities.
Strong written and spoken English (B2+), with confidence communicating with international stakeholders.
As a plus:
Experience working in an international environment with exposure to European, UK, and/or US regulatory or corporate governance practices.
Experience preparing risk reporting for senior leadership or an independent Board of Directors.
Professional certifications in risk management, business continuity, information security, or compliance.
What you'll do
- Maintain and further develop enterprise risk registers across business, product, facilities, and company-wide risks.
- Partner with risk owners across MacPaw to develop practical mitigation plans and integrate them into team priorities and OKRs.
- Strengthen Business Continuity Planning (BCP) and operational resilience across core and non-core business functions, including incident and crisis-management preparedness.
- Contribute to MacPaw’s AI Governance practices by supporting the AI system inventory, classification under the EU AI Act, and review processes for new AI use cases together with Legal, Compliance, and Product teams.
- Support information security and company-wide audits, including SOC2 and ISO-related activities within your area of expertise.
What they require
- Solid experience in Enterprise Risk Management (ERM), GRC, or risk management, ideally within a technology, SaaS, product, or high-growth company.
- Demonstrable experience building or maturing ERM frameworks and risk registers – not only maintaining established processes.
- Hands-on experience developing risk mitigation plans and working with stakeholders to translate identified risks into concrete actions.
- Hands-on experience with Business Continuity Planning (BCP), operational resilience, and crisis management.
- Practical experience or strong working knowledge of EU technology regulation and AI Governance, such as the EU AI Act, GDPR, CRA, ISO/IEC 42001, NIST AI RMF, or similar frameworks.
The company behind CleanMyMac, Setapp, ClearVPN, and a growing ecosystem of products used by millions of people worldwide.