Salmon Group logo

GRC Lead

Salmon Group
Posted 6 hours ago
EuropeRemoteLegal & Compliance
Is this job info correct?

๐ŸŒ Remote | UTC+8 | Core collaboration hours: 12:00โ€“6:00 PM Manila Time

Salmon is a technology-driven financial company building a banking and lending platform across Southeast Asia, starting in the Philippines.

We combine global fintech expertise with deep local market knowledge to make financial services simple, accessible, and useful for millions of people across the region.

7M+ app downloads. 2M+ monthly active users. 7,000+ partner stores. US$310M+ raised from leading global investors.

Manila-based, globally distributed, and hybrid-first โ€” our team spans 45+ countries.

If you want to solve complex problems at scale and impact how millions of people access and manage money, come build with us.

Southeast Asia's fintech moment starts here.

About the role:

You'll own information security risk management, control assurance, and ISO 27001 ISMS governance across a regulated group spanning banking, consumer finance, and technology.

What you'll do:

  • Form an independent view of security risk and challenge whether proposed controls actually address it, working directly with the Group CISO

  • Assess control design and operating effectiveness across areas such as IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure development

  • Turn risk and control data into clear, decision-ready reporting for governance forums

What you'll own:

  • Own the security risk process end to end: assessment, treatment, acceptance, monitoring, and reporting

  • Maintain the risk register and challenge risk assessments and treatment plans so residual risk, ownership, and remediation status stay current

  • Maintain the security control framework, test controls using evidence, data, sampling, or technical validation, and drive remediation with control owners

  • Maintain the ISO 27001 ISMS: policies and standards, Statement of Applicability, risk records, control evidence, exceptions, and key security registers

  • Track control deficiencies, findings, exceptions, and remediation actions

  • Define KRIs and control metrics, and flag where management decisions or escalation are needed

What makes you a strong fit:

  • Strong practical experience in information security risk management: inherent and residual risk, treatment, acceptance, control effectiveness, risk appetite

  • Enough technical depth to critically assess controls across IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure development

  • Hands-on experience reviewing or testing controls, with the ability to distinguish a documented control from an effective one

  • Working knowledge of ISO 27001, with the ability to turn complex risk and control information into concise management reporting

  • Comfortable working with GRC platforms, structured risk and control registers, and evidence management

What we offer:

Ownership and flexibility

  • Fully remote work with core collaboration hours from 12:00 to 6:00 PM Manila time (UTC+8)

  • Company-provided tools and equipment

Health and time off

  • Medical insurance support for you and your family through co-funding or reimbursement, depending on your location and subject to policy limits

  • Access to an internal mental health support specialist

  • 22 vacation days, Philippine public holidays, and 15 sick days

Growth and team experience

  • Opportunities to learn and share your expertise through internal expert meetups, external conferences, speaking opportunities, and industry publications

  • Company-sponsored trips to Manila to meet and work with your team in person

  • High-performing teams can earn a dedicated beach house week in Southeast Asia

We believe strong teams are built by people with different backgrounds, experiences, and points of view. Salmon is an equal opportunity employer, and we make hiring decisions based on skills, experience, and potential.

Similar jobs