Cyber Governance, Risk, Compliance and Reporting (GRC) Manager
Location: NTCC Heuston
Salary: Available upon request
Reports to: Head of Cyber Security
Iarnród Éireann / Irish Rail is seeking applications for those interested in the role of Cyber Governance, Risk, Reporting and Compliance (GRC) Manager. This pivotal role requires strategic vision, hands-on leadership, and a deep understanding of security standards, frameworks, and regulations. You will drive initiatives that enhance Iarnród Éireann’s security posture, aligned with industry best practices. This role is responsible for developing and overseeing the ICT governance, risk management, and compliance frameworks for IT systems across the organisation and OT systems in Rosslare Port and the CME. The role involves collaboration with multiple departments to monitor risk exposure, promote a culture of compliance, enhance cyber awareness and align governance practices with the organization’s strategic goals.
Role and Purpose
The GRC Manager ensures that the organization adheres to regulatory requirements, mitigates risks, and maintains internal policies and procedures in line with best practices. The role will also have responsibility for engaging with the NCSC and relevant regulatory authorities.
Key Responsibilities
Governance
- Maintain and enhance ICT’s Cyber governance framework, ensuring alignment with business goals and regulatory requirements
- Develop and enforce corporate governance policies and standards including data governance, information security, and ethical business practices
Risk Management
- Oversee the development and maintenance of ICT’s and OT’s Cyber risk register, ensuring accurate reporting and analysis
- Establish and maintain effective relationships with key stakeholders across the Group, acting as a trusted adviser and SME, to support management of Information Security risks
- Conduct periodic risk assessments and testing of internal controls to ensure adequacy and effectiveness
- Collaborate with business units to identify key risk areas and implement controls to mitigate those risks
- Ongoing reporting of Cyber risk status to relevant forums
Compliance
- Establish, develop and maintain ICT’s and OT’s compliance program to ensure adherence to relevant regulatory and legal standards, such as GDPR, NIST CSF 2.0 framework, NIS 2.0, CER, the AI Act and pending cyber legislations and regulations
- Manage and ensure organisational compliance to security policies including Asset Management, Identity access, Data Security, Vulnerability management, Pen testing, Red teaming
- Conduct compliance audits and investigations (Internally and externally at supplier level) to ensure defined controls are in line with policy and adhere to regulatory and organizational standards
- Monitor and interpret changes in laws and regulations that affect both ICT and OT in the organization and provide recommendations for necessary policy or process changes
- Coordinate and oversee internal and external audit processes to ensure continuous compliance and risk mitigation
Business Engagement
- Provide training and guidance to employees on governance, risk management, and compliance best practices
- Foster a security first culture by promoting awareness of policies, regulatory changes, and risk management initiatives
- Work with all PMO teams to promote and foster a security culture to ensure an understanding of Third-party risk, Business continuity and Disaster recovery processes
Reporting and Communication
- Prepare and present reports on governance, risk, and compliance matters to senior management, NTA, ARC and the board of directors
- Ensure clear communication and reporting mechanisms are in place for internal and external stakeholders
****This list is not exhaustive, please contact HR Shared Services for a full job description***
Essential
- Bachelor’s degree in Business Information Systems, Cyber Security, Risk Management, and/ or a related field (Master’s Degree Preferable)
- 5+ years of experience in governance, risk management, or compliance roles
- Strong knowledge of regulatory frameworks and compliance requirements relevant (e.g., GDPR, NIST CSF 2.0, IS0 27001, NIST CSF 2.0 Framework, PCI-DSS)
- Experience conducting risk assessments and managing risk registers
- Familiarity with GRC tools and software
- Strong analytical and problem-solving skills, with the ability to assess complex risks and implement solutions
- Excellent written and verbal communication skills, with the ability to influence and work effectively with senior management
- Detail-oriented with strong organizational and project management skills
- High level of integrity and ethical judgment, with a commitment to fostering a culture of compliance
- Ability to manage multiple tasks and projects while maintaining a high level of accuracy
- Ability to respond to regulatory or compliance-related incidents outside of normal business hours, if necessary
- Work closely with the DPO on GDPR matters
Desirable
- Certifications such as CISA, CISM or CRISC are desirable
A practical element and competency-based interview will form part of this selection process. Candidates may be shortlisted on the basis of their application/CV and relevant experience
If any applicants have special requirements, please advise Shared Services when forwarding your application.
If you are interested in applying for this role, applications including CVs should be forwarded to: Sharedservicesrecruit@irishrail.ie by COB Friday 24th January 2025.
Please contact HR Shared Services, Connolly HQ by mail at the above e-mail address for any queries regarding the above position.
At Iarnród Éireann Irish Rail we are committed to embedding diversity and inclusion in all that we do. This starts with how we recruit people. It is important to us that all individuals feel welcome to join our organisation and we take great care to ensure an even playing field for all.
We will strive to provide reasonable accommodation to all candidates where required and requested.
We are an equal opportunities employer and do not discriminate against any employee or applicant for employment because of race, ethnicity, sex, age, religion, sexual orientation, gender identity and/or expression or disability.