Senior Information Security Risk Manager (GRC)

Freedom Broker ArmeniaYerevanstaffampublished 10/01/2026
Must-have:FinTechSecuritySeniorLead

Freedom Broker Armenia  is an investment company with access to the US, European and CIS stock markets. Freedom Broker Armenia is a part of the Freedom Holding Corp. International public holding (FRHC), registered in the USA, state of Nevada, specializing in providing investment services in the global stock markets.We are committed to maintaining the highest standards of cybersecurity, regulatory compliance, and operational resilience while delivering innovative financial services to our clients. As part of our growing security and governance team, we are looking for an experienced Senior Information Security Risk Manager (GRC) to lead and strengthen our governance, risk, and compliance function.

Lead information security risk management processes, including risk identification, assessment, treatment, and monitoring in accordance with ISO/IEC 27005

Develop, maintain, and improve the Information Security Management System (ISMS) in line with ISO/IEC 27001 requirements

Ensure compliance with regulatory and industry requirements, including KVKK, SPK regulations, SOX, and internal company standards

Develop, review, and maintain information security policies, standards, and procedures (20+ document portfolio)

Organize and conduct internal security audits and support external audits, including ISO 27001, SOX ITGC, and regulatory inspections

Manage the Third-Party Risk Management (TPRM) program, including assessments of critical vendors, SaaS providers, and outsourcing partners

Collaborate closely with Legal, Compliance, Internal Audit, IT, and business units on information security and compliance matters

Prepare quarterly risk and compliance reports for Executive Management and the Board

Participate in incident investigations from a regulatory impact and notification perspective

Lead and oversee the Security Awareness program and measure its effectiveness

6+ years of experience in GRC, information security risk management, or compliance, including at least 2 years in a senior or managerial role

Strong knowledge of ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27005, NIST CSF, and NIST 800-53 frameworks

Hands-on experience with internal and external audits, including participation in at least 5 completed audits as lead auditor or auditee

Experience developing and implementing information security policies and procedures (15+ document portfolio)

Good understanding of SOX ITGC, KVKK, and GDPR requirements

Experience working with regulators and external auditors, including Big4 or equivalent firms

English proficiency at B2 / Upper-Intermediate level or higher, including reporting and professional communication

Experience preparing executive-level reporting and presenting to senior management or the Board

Professional certifications such as ISO 27001 Lead Auditor/Lead Implementer, CRISC, CISM, CISSP, or COBIT

Experience in the financial services or fintech sector

Knowledge of Armenian, Russian languages 

Experience with governance, risk, and compliance (GRC) platforms and automation tools