Senior Security GRC Program Manager
We are seeking an experienced Senior Security GRC Program Manager to establish and scale enterprise security, compliance, risk, and privacy programs. You will own ISO 27001 & SOC 2 certifications end-to-end, manage automated GRC platforms (Vanta/Drata), lead technology risk frameworks, and partner with cross-functional leadership to embed robust security controls across the organization.
We are seeking a Senior Security Governance, Risk & Compliance (GRC) Program Manager to lead and develop enterprise security, compliance, risk, and privacy programs across a fast-growing technology organization.
This role requires a blend of strategic governance design and hands-on execution. You will establish scalable governance frameworks, maintain continuous audit readiness, manage vendor risk, and partner with cross-functional stakeholders to ensure security controls are embedded into business and technology operations.
Key Responsibilities
Security Governance & Compliance
• Own and maintain the Information Security Management System (ISMS).
• Directly own and manage end-to-end certification and compliance programs, including ISO 27001 and SOC 2 (Type I & Type II).
• Manage compliance automation platforms such as Vanta, Drata, or equivalent tools.
• Coordinate external auditors, manage evidence collection, and drive continuous audit readiness.
Technology Risk Management
• Establish and maintain enterprise technology risk management frameworks and risk registers.
• Conduct risk assessments covering cloud environments, applications, infrastructure, third parties, and AI/ML technologies.
• Develop governance reporting, risk metrics, KRIs, and executive dashboards.
Security Assurance & Operations Governance
• Design and oversee control testing, vulnerability management SLAs, and penetration testing coordination.
• Monitor remediation activities arising from audits, assessments, and internal reviews.
• Partner with Engineering and Product teams to embed security requirements into tech delivery lifecycles.
Vendor & Customer Security Assurance
• Build and maintain Third-Party Risk Management (TPRM) frameworks and conduct vendor due diligence.
• Handle complex customer security reviews, security questionnaires, and trust documentation.
Privacy & Security Awareness
• Operationalize privacy requirements (data mapping, retention, DPIA, cross-border data governance).
• Govern security awareness training programs and access review controls.
Qualifications
Required:
• 8+ years of hands-on experience in Security Governance, Technology Risk Management, GRC, and Security Compliance.
• Demonstrated track record as the DIRECT OWNER of ISO 27001 and SOC 2 (Type I & II) audits from preparation through to issuance.
• Hands-on experience operating compliance automation platforms (Vanta, Drata, or equivalent).
• Proven expertise in establishing Risk Registers, KRIs, Vendor Risk Management frameworks, and answering Customer Security Reviews.
• Strong working knowledge of security frameworks: ISO 27001, SOC 2, NIST CSF, and CIS Controls.
• Outstanding stakeholder management and communication skills.
Preferred:
• Experience in SaaS, fintech, or modern cloud-native environments.
• Exposure to GDPR, HIPAA, PCI-DSS, or AI Governance frameworks.
• Relevant certifications: CISSP, CISM, CRISC, CIPM, or ISO 27001 Lead Implementer/Auditor.
Due to the high volume of applications we are experiencing, our team will only be in touch with you if your application is shortlisted.
About the job
Contract Type: Perm
Specialism: Tech & Transformation
Focus: Security
Industry: Technology
Salary: Negotiable
Workplace Type: Hybrid
Experience Level: Mid Management
Location: Ho Chi Minh City
FULL_TIMEJob Reference: W6AJ0Q-FE53CC60
Date posted: 19 August 2026
Consultant: An Tran
ho-chi-minh-city tech-transformation/security 2026-08-19 2026-10-18 technology Ho Chi Minh City Ho Chi Minh City VN Robert Walters https://www.robertwalters.com.vn https://www.robertwalters.com.vn/content/dam/robert-walters/global/images/logos/web-logos/square-logo.png true