GRC Lead

Posted 6 Hours Ago
Be an Early Applicant
5 Locations
Remote
Entry level
Fintech • Financial Services
The Role
Owns information security risk management, control assurance, and ISO 27001 ISMS governance across a regulated fintech group. Responsibilities include maintaining risk and control registers, assessing control design and effectiveness, testing evidence, tracking remediation, defining security metrics, and preparing governance reporting. The role partners closely with the Group CISO and control owners to challenge risk assessments, manage residual risk, and maintain security policies, exceptions, and compliance documentation.
Summary Generated by Built In

Salmon is a technology-driven financial company building a banking and lending platform across Southeast Asia, starting in the Philippines.

We combine global fintech expertise with deep local market knowledge to make financial services simple, accessible, and useful for millions of people across the region.

7M+ app downloads. 2M+ monthly active users. 7,000+ partner stores. US$310M+ raised from leading global investors.

Manila-based, globally distributed, and hybrid-first — our team spans 45+ countries.

If you want to solve complex problems at scale and impact how millions of people access and manage money, come build with us.

Southeast Asia's fintech moment starts here.

About the role:

You'll own information security risk management, control assurance, and ISO 27001 ISMS governance across a regulated group spanning banking, consumer finance, and technology.

What you'll do:

  • Form an independent view of security risk and challenge whether proposed controls actually address it, working directly with the Group CISO

  • Assess control design and operating effectiveness across areas such as IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure development

  • Turn risk and control data into clear, decision-ready reporting for governance forums

What you'll own:

  • Own the security risk process end to end: assessment, treatment, acceptance, monitoring, and reporting

  • Maintain the risk register and challenge risk assessments and treatment plans so residual risk, ownership, and remediation status stay current

  • Maintain the security control framework, test controls using evidence, data, sampling, or technical validation, and drive remediation with control owners

  • Maintain the ISO 27001 ISMS: policies and standards, Statement of Applicability, risk records, control evidence, exceptions, and key security registers

  • Track control deficiencies, findings, exceptions, and remediation actions

  • Define KRIs and control metrics, and flag where management decisions or escalation are needed

What makes you a strong fit:

  • Strong practical experience in information security risk management: inherent and residual risk, treatment, acceptance, control effectiveness, risk appetite

  • Enough technical depth to critically assess controls across IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure development

  • Hands-on experience reviewing or testing controls, with the ability to distinguish a documented control from an effective one

  • Working knowledge of ISO 27001, with the ability to turn complex risk and control information into concise management reporting

  • Comfortable working with GRC platforms, structured risk and control registers, and evidence management

What we offer:

Ownership and flexibility

  • Fully remote work with core collaboration hours from 12:00 to 6:00 PM Manila time (UTC+8)

  • Company-provided tools and equipment

Health and time off

  • Medical insurance support for you and your family through co-funding or reimbursement, depending on your location and subject to policy limits

  • Access to an internal mental health support specialist

  • 22 vacation days, Philippine public holidays, and 15 sick days

Growth and team experience

  • Opportunities to learn and share your expertise through internal expert meetups, external conferences, speaking opportunities, and industry publications

  • Company-sponsored trips to Manila to meet and work with your team in person

  • High-performing teams can earn a dedicated beach house week in Southeast Asia

We believe strong teams are built by people with different backgrounds, experiences, and points of view. Salmon is an equal opportunity employer, and we make hiring decisions based on skills, experience, and potential.

Skills Required

  • Strong practical experience in information security risk management, including inherent and residual risk, risk treatment, acceptance, control effectiveness, and risk appetite
  • Technical depth to assess controls across IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure development
  • Hands-on experience reviewing or testing security controls and evaluating control effectiveness
  • Working knowledge of ISO 27001 and information security management systems
  • Ability to translate complex risk and control information into concise management reporting
  • Experience working with GRC platforms, structured risk and control registers, and evidence management
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
1,189 Employees
Year Founded: 2022

What We Do

Salmon Group Ltd is a financial technology company serving Filipino consumers with modern, inclusive financial services. Its platform combines technology, product design, security, data analytics and customer care to make finance easier to access. Salmon offers consumer-focused products including short-term loans and digital banking services, with the broader mission of improving convenience, affordability and financial inclusion while operating securely around the clock.

Similar Jobs

Deepgram Logo Deepgram

Counsel

Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
Remote
28 Locations
150 Employees

Deepgram Logo Deepgram

Solutions Engineer

Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
Remote
EU
150 Employees

Deepgram Logo Deepgram

Senior Solutions Architect

Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
Remote
EU
150 Employees

Ruby Labs Logo Ruby Labs

Senior Creative Producer

Information Technology • Software
In-Office or Remote
16 Locations
28 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account