Senior Security Governance Risk and Compliance Manager

1 month ago


Stockholm, Stockholm, Sweden Spotify Full time
Job Title: Senior Security Governance, Risk, and Compliance Manager

Spotify is seeking a highly skilled Senior Security Governance, Risk, and Compliance (GRC) Manager to join the Security Studio. As a key member of the team, you will work closely with engineering teams and audit functions to drive the execution of tasks for the Security GRC Program.

Key Responsibilities:
  • Lead the SOC 2 compliance program and large-scale SOC 2 projects, identifying dependencies, defining success metrics, and ensuring timely delivery.
  • Design, implement, monitor, and maintain SOC 2 controls, collaborating with internal and external business partners.
  • Lead and handle all stages of SOC 2 audits, ensuring successful completion.
  • Resolve appropriate scope of SOC 2 audits, encompassing new and existing service offerings, their supporting infrastructure, and associated processes.
  • Lead and respond to customer security questionnaires, collaborating with internal teams, and drive questionnaire response automation.
  • Identify, assess, and advise on information security risks, processes, and controls to various business partners.
Requirements:
  • 5+ years of experience with SOC 2 compliance, including leading a SOC 2 compliance program, controls design, and implementation. Experience in the technology industry is preferred.
  • 5+ years of experience with security frameworks, SOC 2, ISO27001, NIST CSF, PCI-DSS, etc., security controls design and implementation, and security best practices.
  • Prior IT Audit experience in areas of SOC 2, ITGC, SOX is preferred.
  • CISA, CISM, CISSP or other related certifications are preferred but not required.
  • Experience with privacy frameworks, such as GDPR or CCPA.
  • Strong collaborator, with experience working on teams composed of both technical and non-technical members.
  • Demonstrated ability to lead large projects, problem-solve, multitask, and have excellent organizational skills.
  • Excellent written and verbal communication skills, with experience presenting to key stakeholders and partnering with internal collaborators and external auditors.
  • Thrives in a data-driven, fast-paced, and innovative environment.
Location:

This role is based in New York.



  • Stockholm, Stockholm, Sweden Spotify Full time

    Job SummarySpotify is seeking a Senior Security Governance, Risk, and Compliance (GRC) Manager to join the Security Studio. The successful candidate will work closely with our engineering teams and audit functions to drive SOC 2 compliance and other compliance and information security frameworks. Key responsibilities include leading the SOC 2 compliance...


  • Stockholm, Stockholm, Sweden Intrum Full time

    Job Title: Global Information Security Manager - IT Risk GovernanceAt Intrum, we're seeking a highly skilled Global Information Security Manager to join our team. As a key member of our Global Information Security function, you'll play a critical role in protecting our digital assets and managing IT risks.Key Responsibilities:Develop and maintain the IT risk...


  • Stockholm, Stockholm, Sweden Intrum Full time

    At Intrum, you will contribute to the company's goal of making a difference. You will do it in a highly international environment and in a supportive culture where effort counts.The Global Information Security Manager (GISM) – IT Risk Management, plays a crucial role in our efforts to protect digital assets and manage IT risks. This vital role involves...


  • Stockholm, Stockholm, Sweden Nordea Bank Full time

    Job Opportunity:We are seeking a highly skilled Lead Compliance Officer to join our Compliance Risk Governance team. As a key member of the team, you will play a crucial role in performing and advising on Compliance Risk identification and registration processes.About the Role:As the Lead Compliance Officer, you will be responsible for supporting the Group...


  • Stockholm, Stockholm, Sweden Spotify Full time

    Job DescriptionThe Senior Security GRC Manager will be responsible for leading the SOC 2 compliance program, designing and implementing security controls, and collaborating with internal and external business partners. The role requires a deep understanding of SOC 2 compliance, information security practices, and experience working with technology...

  • Senior Risk Manager

    4 weeks ago


    Stockholm, Stockholm, Sweden Nordea Bank Full time

    About the RoleWe are seeking a highly skilled Senior/Technology Risk Manager to join our team at Nordea Bank. As a key member of our Technology Risk Management unit, you will play a crucial role in driving initiatives to increase Technology risk awareness and ensure prudent risk and control management.Key ResponsibilitiesProvide advisory services to monitor...


  • Stockholm, Stockholm, Sweden Nordea Bank Full time

    At Nordea Bank, we are seeking a seasoned Regulatory Risk Governance Expert to join our Compliance Risk Governance team. This role offers an exciting opportunity to leverage your expertise in regulatory analysis and risk management to drive compliance excellence.About the RoleWe are looking for a highly skilled professional with a strong background in...


  • Stockholm, Stockholm, Sweden Intrum Full time

    Job Title: Global Information Security Manager - IT Risk ManagementAt Intrum, we're seeking a highly skilled Global Information Security Manager to join our team. As a key member of our Global Information Security function, you will play a critical role in protecting our digital assets and managing IT risks.Key Responsibilities:Develop and maintain the IT...

  • Security GRC Manager

    3 weeks ago


    Stockholm, Stockholm, Sweden Spotify Full time

    Job Description:Spotify is seeking a Senior Security Governance, Risk, and Compliance (GRC) Manager to join the Security Studio. This role will work closely with our engineering teams and audit functions. The ideal candidate will have a deep understanding of SOC 2 compliance, information security practices, and experience working with technology teams.Key...


  • Stockholm, Stockholm, Sweden Nordea Bank Full time

    Job Description:We are seeking a Senior Risk Management Specialist to join our Business Banking team in Poland. This role will involve leading and performing audits to assess governance, risk management, and control processes in the Business Banking area.About the Role:Plan and execute audit projects, following up on previous audit findings in accordance...

  • Security Strategist

    2 weeks ago


    Stockholm, Stockholm, Sweden Stillfront Full time

    About the RoleWe are seeking a seasoned Cybersecurity Executive to lead our information security efforts and drive risk management across our global digital ecosystem.ResponsibilitiesDevelop and execute a comprehensive information security strategy that aligns with our business objectives and risk appetite.Oversee the implementation of security measures to...


  • Stockholm, Stockholm, Sweden Nordea Bank Full time

    Job DescriptionWe are seeking a highly motivated Technical Risk and Compliance Expert to join our team in Stockholm, Sweden. The ideal candidate will have strong stakeholder management skills, a strong cultural awareness, and a dynamic approach.About the RoleThe successful candidate will play a valuable role in supporting the business by driving activities...


  • Stockholm, Stockholm, Sweden H&M Group Full time

    Cyber Security GRC RoleWe are seeking a highly skilled Cyber Security GRC professional to join our team at H&M Group. As a key member of our Cyber Security GRC unit, you will play a crucial role in embedding defined standards and regulatory frameworks within information and IT security.Key Responsibilities:Develop and maintain a structured approach to cyber...


  • Stockholm, Stockholm, Sweden Nordea Bank Full time

    Job ID: 26965 Are you passionate about technology risk and compliance? At Nordea, we're looking for a skilled Application and IT Risk Manager to strengthen our relationship between business and technology. As an Application and IT Risk Manager, you'll drive compliance in our applications, ensuring they meet Nordea's requirements and customer needs....


  • Stockholm, Stockholm, Sweden Intrum Full time

    About the RoleIntrum is seeking an experienced Senior Financial Governance Manager to join our team. As a key member of our organization, you will be responsible for enhancing financial governance and ensuring that robust controls are in place.Job Description:The Senior Financial Governance Manager will be responsible for driving behavioural changes towards...


  • Stockholm, Stockholm, Sweden Stillfront Full time

    Stillfront Group is on a mission to safeguard its global digital ecosystem and ensure the highest level of information security across all gaming experiences. We are seeking an experienced Chief Information Security Officer (CISO) to lead our cybersecurity efforts.Your MissionDevelop and execute a comprehensive information security strategy that aligns with...


  • Stockholm, Stockholm, Sweden TUI Full time

    About the JobWe are seeking a highly skilled Security Operations Manager to join our team at TUI. As a key member of our security team, you will be responsible for conducting country security risk assessments, owning the destination level risk matrix, and working closely with our business units to monitor and evaluate security-related data.Key...


  • Stockholm, Stockholm, Sweden Intrum Full time

    At Intrum, you will have the opportunity to make a meaningful contribution to the company’s success by playing a key role in enhancing financial governance and ensuring the effectiveness of internal controls.About the Role:The ICFR Governance Specialist will be responsible for driving the design, implementation, and maintenance of robust internal controls...


  • Stockholm, Stockholm, Sweden H&M Group Full time

    Job Title: Cyber Security GRC LeadAbout the Role:We are seeking an experienced Cyber Security GRC Lead to join our team at H&M Group. As a key member of our Cyber Security unit, you will play a crucial role in embedding defined standards and regulatory frameworks within information and IT security.Key Responsibilities:Develop and maintain a robust and...


  • Stockholm, Stockholm, Sweden AXA Group Full time

    Discover Your OpportunityWe are seeking a skilled Compliance Risk Manager to join our team in Stockholm, Sweden. In this role, you will be responsible for developing and driving our compliance function for the Nordic countries.You will work closely with the Head of Compliance and Regulatory Affairs, Europe and the Legal Counsel, Nordic Region to implement...