About this role
Reward Gateway|Edenred is a leading digital platform and global market leader in benefits and employee engagement. We help our clients and their leaders to transform employee experience that will attract, engage and retain top talent through employee benefits, An opportunity has become available for a motivated and passionate Information Security professional to assume the role of Senior Manager: Governance, Risk and Compliance. You will define and lead the GRC strategy and operating model, ensuring that governance, risk management, compliance, security, and resilience are embedded into the way the company operates and grows. This role owns the integrated control framework, multi-standard certifications, enterprise risk, business continuity, and key regulatory readiness programs (including NIS 2, EU AI Act for AI governance/compliance), while acting as a trusted advisor to the Leadership Team. You will continue to build and lead our high-performing GRC function, manage the GRC team and budget, and deliver automation-driven, data-backed oversight that enables innovation and commercial agility. Lead, manage, and develop the GRC team, including hiring, coaching, performance management, and succession planning. Champion a culture where governance, risk and compliance are seen as business enablers, not blockers. Manage our control framework, covering ISO 27001, 22301, 9001, 14001, SOC2 Type 2, PCI DSS & CE+. Implement and manage ISO 42001 within the integrated management system, ensuring alignment with organisational objectives. Partner with our Cyber Security, IT, Product and Engineering Teams to ensure that information security governance and policies remain effective, aligned with risk appetite, and embedded into day-to-day operations. Own and mature the Vendor Risk Management (VRM) framework, including vendor criticality tiers, onboarding, due diligence, and ongoing monitoring. Manage and test Business Continuity Plans (BCPs) across critical business services, locations, and supporting technology. Own the enterprise risk management framework, methodology, and tools. Lead regular Information Security and AI Risk Board meetings, ensuring clear risk ownership, documented decisions, and timely follow-up on agreed actions. Use KPIs to monitor GRC process performance, drive continuous improvement, and evidence the value and maturity of the GRC function. Support the creation, enhancement, and maintenance of technical and procedural documentation (policies, standards, guidelines, and work instructions).