← Back to jobs

GRC Lead

  • Remote
  • Sweden
  • English
  • Posted 18.09.26 09:23

Salmon is a technology-driven financial company building a banking and lending platform across Southeast Asia, starting in the Philippines.

We combine global fintech expertise with deep local market knowledge to make financial services simple, accessible, and useful for millions of people across the region.

7M+ app downloads. 2M+ monthly active users. 7,000+ partner stores. US$310M+ raised from leading global investors.

Manila-based, globally distributed, and hybrid-first — our team spans 45+ countries.

If you want to solve complex problems at scale and impact how millions of people access and manage money, come build with us.

Southeast Asia's fintech moment starts here.

About The Role

You'll own information security risk management, control assurance, and ISO 27001 ISMS governance across a regulated group spanning banking, consumer finance, and technology.

What You'll Do

Form an independent view of security risk and challenge whether proposed controls actually address it, working directly with the Group CISOAssess control design and operating effectiveness across areas such as IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure developmentTurn risk and control data into clear, decision-ready reporting for governance forums

What You'll Own

Own the security risk process end to end: assessment, treatment, acceptance, monitoring, and reportingMaintain the risk register and challenge risk assessments and treatment plans so residual risk, ownership, and remediation status stay currentMaintain the security control framework, test controls using evidence, data, sampling, or technical validation, and drive remediation with control ownersMaintain the ISO 27001 ISMS: policies and standards, Statement of Applicability, risk records, control evidence, exceptions, and key security registersTrack control deficiencies, findings, exceptions, and remediation actionsDefine KRIs and control metrics, and flag where management decisions or escalation are needed

What Makes You a Strong Fit

Strong practical experience in information security risk management: inherent and residual risk, treatment, acceptance, control effectiveness, risk appetiteEnough technical depth to critically assess controls across IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure developmentHands-on experience reviewing or testing controls, with the ability to distinguish a documented control from an effective oneWorking knowledge of ISO 27001, with the ability to turn complex risk and control information into concise management reportingComfortable working with GRC platforms, structured risk and control registers, and evidence management

What We Offer

Ownership and flexibility

Fully remote work with core collaboration hours from 12:00 to 6:00 PM Manila time (UTC+8)Company-provided tools and equipment

Health and time off

Medical insurance support for you and your family through co-funding or reimbursement, depending on your location and subject to policy limitsAccess to an internal mental health support specialist22 vacation days, Philippine public holidays, and 15 sick days

Growth and team experience

Opportunities to learn and share your expertise through internal expert meetups, external conferences, speaking opportunities, and industry publicationsCompany-sponsored trips to Manila to meet and work with your team in personHigh-performing teams can earn a dedicated beach house week in Southeast Asia

We believe strong teams are built by people with different backgrounds, experiences, and points of view. Salmon is an equal opportunity employer, and we make hiring decisions based on skills, experience, and potential.