Senior Information Security Risk Manager (GRC)
Freedom Broker Armenia is an investment company with access to the US, European and CIS stock markets. Freedom Broker Armenia is a part of the Freedom Holding Corp. International public holding (FRHC), registered in the USA, state of Nevada, specializing in providing investment services in the global stock markets.We are committed to maintaining the highest standards of cybersecurity, regulatory compliance, and operational resilience while delivering innovative financial services to our clients. As part of our growing security and governance team, we are looking for an experienced Senior Information Security Risk Manager (GRC) to lead and strengthen our governance, risk, and compliance function.
Lead information security risk management processes, including risk identification, assessment, treatment, and monitoring in accordance with ISO/IEC 27005
Develop, maintain, and improve the Information Security Management System (ISMS) in line with ISO/IEC 27001 requirements
Ensure compliance with regulatory and industry requirements, including KVKK, SPK regulations, SOX, and internal company standards
Develop, review, and maintain information security policies, standards, and procedures (20+ document portfolio)
Organize and conduct internal security audits and support external audits, including ISO 27001, SOX ITGC, and regulatory inspections
Manage the Third-Party Risk Management (TPRM) program, including assessments of critical vendors, SaaS providers, and outsourcing partners
Collaborate closely with Legal, Compliance, Internal Audit, IT, and business units on information security and compliance matters
Prepare quarterly risk and compliance reports for Executive Management and the Board
Participate in incident investigations from a regulatory impact and notification perspective
Lead and oversee the Security Awareness program and measure its effectiveness
6+ years of experience in GRC, information security risk management, or compliance, including at least 2 years in a senior or managerial role
Strong knowledge of ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27005, NIST CSF, and NIST 800-53 frameworks
Hands-on experience with internal and external audits, including participation in at least 5 completed audits as lead auditor or auditee
Experience developing and implementing information security policies and procedures (15+ document portfolio)
Good understanding of SOX ITGC, KVKK, and GDPR requirements
Experience working with regulators and external auditors, including Big4 or equivalent firms
English proficiency at B2 / Upper-Intermediate level or higher, including reporting and professional communication
Experience preparing executive-level reporting and presenting to senior management or the Board
Professional certifications such as ISO 27001 Lead Auditor/Lead Implementer, CRISC, CISM, CISSP, or COBIT
Experience in the financial services or fintech sector
Knowledge of Armenian, Russian languages
Experience with governance, risk, and compliance (GRC) platforms and automation tools