- Company Name
- Lenovo
- Job Title
- Security GRC Lead
- Job Description
-
Job Title: Security GRC Lead
Role Summary: Lead and execute a global Cyber Security Governance, Risk, and Compliance (GRC) strategy for a managed services and solutions portfolio. Drive alignment with international regulations, develop security frameworks, conduct risk management, and oversee compliance audits and certifications across multi‑location teams.
Expectations:
- Deliver end‑to‑end GRC programs that meet ISO27001, SOC 2, GDPR, NIST, CIS, and other standards.
- Translate regulatory requirements into actionable policies and controls, maintaining continuous compliance.
- Mentor and grow a distributed security team, fostering a culture of security excellence.
- Partner with C‑suite, product, and technical stakeholders to embed security in design, delivery, and operations.
- Manage audit readiness, certification processes, and external assessments.
- Lead cross‑functional initiatives and represent the organization in global forums.
Key Responsibilities:
1. Develop and implement the organization‑wide GRC strategy for managed services and solutions.
2. Ensure compliance with international, regional, and national cybersecurity regulations, adapting requirements into business processes.
3. Conduct ongoing risk analysis, align risk management with company appetite and business objectives.
4. Create, maintain, and enforce security policies, frameworks, controls, including third‑party and supply chain risk management.
5. Lead, mentor, and develop a multi‑location GRC team, promoting security and compliance culture.
6. Collaborate with product, technical, and business leaders to secure design, delivery, and operations.
7. Manage internal and external audits, certifications (ISO27001, SOC 2, GDPR), and regulatory assessments.
8. Represent the organization in cross‑functional and international forums; communicate risks, gaps, and compliance status to stakeholders.
Required Skills:
- Advanced knowledge of security frameworks (ISO27001, NIST, CIS, GDPR, SOC 2).
- Proven experience in cyber risk management within fast‑paced, global technology or managed services environments.
- Strong analytical, problem‑solving, and decision‑making abilities.
- Excellent written and spoken English; additional languages a plus.
- Strong stakeholder management, communication, and interpersonal skills across diverse cultures.
- Leadership ability to mentor and develop distributed teams.
Required Education & Certifications:
- Bachelor’s or Master’s degree in Information Security, Computer Science, or related field.
- Professional certification: CISSP, CISM, CRISC, or CISA (or equivalent).
---
Farnborough, United kingdom
On site
Senior
11-12-2025