Skip to main content
LeoVegas Mobile Gaming Group

Information Security GRC Team Lead

Software Engineering & Technology

ABOUT THE ROLE


The Information Security Department at LeoVegas forms part of the Legal & Compliance team and focuses its activities in 4 main areas of Information Security: Governance, Risk, and Compliance (GRC), Security Operations (SECOPS), Incident response (CSIRT), and Security Awareness Training (SAT).

 

The Information Security GRC Lead is a key individual in a small team focusing on GRC and SAT, working alongside Internal IT, Privacy, Risk, Tech Compliance, Legal, Platform, and other teams. This individual is responsible for ensuring good governance and compliance with regulatory requirements, as well as the adoption of good security industry practices across LeoVegas Group. The role also includes providing leadership to the team, ensuring alignment with the organization’s broader business objectives, and managing the team’s performance to ensure effective risk management and security governance. This position calls for a strong communicator and risk advisor, focused on identifying and mitigating risks through best practices.

 

YOU WILL BE RESPONSIBLE FOR:

  • Develop and implement the organization's GRC strategy together with the Head of Information Security, ensuring governance, risk, and compliance efforts stay aligned with overall business objectives, and maintain a roadmap of team activities based on projects, department goals, and regulatory requirements.

  • Contribute to the development of security KPIs, objectives, and strategies to improve the Group's overall security posture and maturity.

  • Conduct security maturity assessments and lead/conduct other risk assessments and analyses, contributing to the identification and mitigation of security risks across the organization.

  • Detect gaps in security processes and product portfolios, determine associated risks, an recommend remediation.

  • Assist the Risk Management function in maintaining the Group's Security Risk Register.

  • Develop, maintain, and implement the Group's Information Security policies, standards, and guidelines.

  • Manage and lead regulatory audits, external auditor and regulatory-body relationships, and licensed market entry projects, assisting Tech Compliance and other teams as required.

  • Participate in and contribute to security certification projects.

  • Manage and lead vendor onboarding due diligence and supplier monitoring processes.

  • Assist with the development, maintenance, and testing of business continuity and disaster recovery plans.

  • Develop and implement the organization's security awareness and education programs, and contribute to the broader employee training program on Information Security.

  • Provide leadership and direction to security team members, ensuring the team is equipped, motivated, and aligned with business and regulatory objectives; lead onboarding of new analysts.

  • Provide guidance and leadership to internal stakeholders on security requirements and governance frameworks.

  • Collaborate cross-functionally to embed security into all areas of the organization's operations and foster a security-first culture.

 

OUR SUCCESSFUL CANDIDATE WILL HAVE THE FOLLOWING:

  • Minimum of 5-7 years of experience in Information Security, with a strong focus on
    Governance, Risk, and Compliance (GRC).

  • Proven experience in managing and leading security teams, with the ability to set
    direction, manage performance, and mentor junior analysts.

  • Hands-on experience with business continuity and disaster recovery, vendor risk
    management, IT audits, and regulatory compliance.

  • Strong knowledge of information security frameworks (NIST, ISO 27001, COBIT, etc.).

  • Excellent communication and interpersonal skills, with the ability to engage and
    influence stakeholders at all levels.

  • Proven leadership skills with experience in team development, mentorship, and
    strategic planning.

  • Strong analytical and problem-solving skills, with the ability to assess complex security
    risks and propose actionable solutions.

  • In-depth understanding of regulatory requirements such as GDPR, PCI-DSS, SOC 2, and others.

 

WHO WE ARE

At the core of LeoVegas Group is Team Leo. Our culture is our foundation and is what enables us to innovate, build, and lead as we trailblaze our way through the igaming industry. We’re a team of over 2000 innovators, initiators, and groundbreakers working in a fast-paced and agile environment across 19 offices worldwide.

 

BENEFITS

  • Hybrid work policy

  • 4 weeks of Workation (T&C apply)

  • Well-being allowance to support your active lifestyle

  • Private health insurance

  • Discounts across a range of retailers, gyms, bars & restaurants

  • We offer an employee assistance program that can provide help and guidance during challenging moments.

JOIN US!

In our pride, we empower our teammates to find their roar and run with their wildest ideas. We don’t wait for things to happen; we pounce and make it happen!

Would you be a good fit for the Leo Pride - give us a roar!

 

As our company working language is English, we’d like to see your CV in English, please

 
Apply now
Malta
Full-time
1 day ago