Information Security GRC Team Lead
The Information Security GRC Team Lead at LeoVegas is a key individual responsible for ensuring good governance and compliance with regulatory requirements, as well as the adoption of security industry practices across the group. The role focuses on GRC and security awareness training, working alongside internal IT, privacy, risk, tech compliance, legal, and platform teams.
This position involves providing leadership to the team, ensuring alignment with the organisation's broader business objectives, and managing performance to ensure effective risk management and security governance. The role requires a strong communicator and risk advisor who is focused on identifying and mitigating risks through best practices.
- Develop and implement the organisation's GRC strategy together with the Head of Information Security.
- Maintain a roadmap of team activities based on projects, department goals, and regulatory requirements.
- Contribute to the development of security KPIs, objectives, and strategies to improve the group's overall security posture and maturity.
- Conduct security maturity assessments and lead or conduct other risk assessments and analyses.
- Detect gaps in security processes and product portfolios, determine associated risks, and recommend remediation.
- Assist the Risk Management function in maintaining the group's Security Risk Register.
- Develop, maintain, and implement the group's Information Security policies, standards, and guidelines.
- Manage and lead regulatory audits, external auditor and regulatory-body relationships, and licensed market entry projects.
- Participate in and contribute to security certification projects.
- Manage and lead vendor onboarding due diligence and supplier monitoring processes.
- Assist with the development, maintenance, and testing of business continuity and disaster recovery plans.
- Develop and implement the organisation's security awareness and education programs.
- Provide leadership and direction to security team members, ensuring the team is equipped, motivated, and aligned with business and regulatory objectives.
- Lead onboarding of new analysts.
- Provide guidance and leadership to internal stakeholders on security requirements and governance frameworks.
- Collaborate cross-functionally to embed security into all areas of the organisation's operations and foster a security-first culture.
- Minimum of 5-7 years of experience in Information Security, with a strong focus on Governance, Risk, and Compliance (GRC) (required).
- Proven experience in managing and leading security teams, with the ability to set direction, manage performance, and mentor junior analysts (required).
- Hands-on experience with business continuity and disaster recovery, vendor risk management, IT audits, and regulatory compliance (required).
- Strong knowledge of information security frameworks such as NIST, ISO 27001, and COBIT (required).
- Excellent communication and interpersonal skills, with the ability to engage and influence stakeholders at all levels (required).
- Proven leadership skills with experience in team development, mentorship, and strategic planning (required).
- Strong analytical and problem-solving skills, with the ability to assess complex security risks and propose actionable solutions (required).
- In-depth understanding of regulatory requirements such as GDPR, PCI-DSS, and SOC 2 (required).
- Hybrid work policy
- 4 weeks of Workation (T&C apply)
- Well-being allowance to support your active lifestyle
- Private health insurance
- Discounts across a range of retailers, gyms, bars & restaurants
- Employee assistance program
LeoVegas Group is a Swedish mobile-first iGaming company founded in 2011, headquartered in Stockholm with its main operational hub in Sliema, Malta. A pioneer of mobile casino, it operates online casino and sportsbook products across regulated markets through brands including LeoVegas, BetUK, Expekt, Pink Casino and GoGo Casino. In 2022 the group was acquired by MGM Resorts International and now serves as MGM's international online-gaming arm, having previously been listed on Nasdaq Stockholm.