HMV Engineering logo

Technology GRC Manager

HMV EngineeringHamilton House, Block 2, Plassey Business Park, Castletroy, Limerick, V94 YHD65 days ago
IT
Limerick

Description

Technology GRC Manager    

Reporting to: Head of IT Security  
Function: IT 
Location: Cork or Limerick 

About H&MV Engineering 

H&MV Engineering is a global leader in high-voltage electrical engineering, powering the transition to a sustainable future. We’re at the cutting-edge of renewable energy, data centres, and complex utility projects - powered by a commitment to continuous improvement and innovation. 

Our foundation is built on safety, collaboration, and respect. These values shape how we work, how we lead, and how we grow. And at H&MV Engineering, growth isn’t just a goal—it’s a mindset. 

We invest in our people, offering opportunities to develop, lead, and shape the future of energy. We value passion, motivation, and problem-solving skills, and we believe that diverse perspectives fuel better outcomes. 

We’re not here to keep up—we’re here to lead. 

About the Role: 

We are seeking an experienced risk management professional to lead and develop a growing Technology GRC function as we expand internationally. This senior role will build a practical, business-aligned information security risk management capability, supported by strong governance and compliance practices. 

The successful candidate will own the identification, assessment, management and reporting of information security risks across the organisation. They will ensure risk decisions are visible, evidence-based and aligned to the ISO 27001 Information Security Management System, while supporting readiness for emerging European regulation. 

Key Responsibilities 

Risk Governance and Framework Management 

  • Lead the development, maintenance and continuous improvement of the organisation’s information security risk management framework. 

  • Ensure risk management practices align with ISO 27001 and relevant control and regulatory frameworks. 

  • Define clear governance structures for risk identification, assessment, ownership, escalation, treatment and acceptance. 

  • Develop practical policies, standards, procedures and governance artefacts that support consistent, proportionate risk management. 

  • Translate regulatory, audit and framework requirements into clear risk activities, controls and reporting. 

Information Security Risk Management 

  • Own the information security risk process and platform, including identification, assessment, scoring, treatment planning, review and reporting. 

  • Maintain the information security risk register, ensuring risks have clear owners, actions, target dates and treatment decisions. 

  • Work with technology, security, business and operational teams to assess risks arising from projects, suppliers, systems, regulatory change and control gaps through a standardised methodology.  

  • Oversee third-party information security risk, working with procurement, technology, security and business stakeholders to ensure supplier risks are identified, assessed, owned and managed through the risk framework and project lifecycles.  

  • Support risk-based decision-making by providing clear analysis, challenge and recommendations to risk owners and senior stakeholders. 

  • Coordinate risk treatment activity and track remediation through to closure or formal acceptance. 

  • Develop practical risk reporting that highlights key themes. 

Compliance, Assurance and Regulatory Readiness 

  • Ensure compliance and assurance activity is risk-led, proportionate and aligned with business priorities. 

  • Support compliance with ISO 27001, internal policies, customer requirements and emerging European cyber regulation. 

  • Plan and support control assessments, gap analyses, maturity reviews, audits, customer assurance reviews and regulatory assessments. 

  • Maintain clear evidence of control operation, risk treatment and compliance status for audit, management and regulatory purposes. 

  • Track audit findings, control gaps and remediation actions, ensuring each is linked to the appropriate risk position and treatment plan. 

  • Support the organisation’s readiness for forthcoming European regulatory obligations, including NIS2-related expectations where applicable. 

Team Leadership and Development 

  • Manage, develop and grow a small GRC team. 

  • Set clear priorities, roles and ways of working, ensuring delivery is structured, visible and aligned to business risk. 

  • Coach and mentor team members, building capability in stakeholder management, risk assessment, risk reporting, governance, compliance and audit readiness. 

  • Create a positive, accountable and collaborative team culture that supports continuous improvement and professional growth. 

  • Identify future resourcing, skills and process needs as the risk management and GRC function matures. 

Stakeholder Engagement 

  • Act as a trusted risk and GRC partner to IT Operations, security, legal, procurement, data protection, operations and business teams. 

  • Build strong stakeholder relationships so risk management is understood, supported and embedded into day-to-day decision-making. 

  • Provide pragmatic advice that balances risk appetite, regulatory expectations, security good practice and business practicality. 

  • Help leadership understand information security risk in a clear, concise and actionable way. 

  • Promote a culture where risk is owned by the business and supported by clear governance, evidence and accountability. 

Experience and Skills Required 

  • Significant experience in a GRC function or information security risk management, ideally in a technology, engineering, infrastructure or regulated environment. 

  • Strong working knowledge of ISO 27001 and experience supporting or operating an Information Security Management System. 

  • Experience designing or operating risk management processes, including assessment, scoring, treatment planning, reporting and governance forums. 

  • Experience with control frameworks, audit management, compliance reporting and remediation tracking. 

  • Awareness of European cyber and data protection regulation, with the ability to translate expectations into practical risk and governance actions. 

  • Experience managing or mentoring team members on/offshore and building capability in a developing function. 

  • Excellent communication, documentation and stakeholder management skills, with the ability to explain risk clearly to technical and non-technical audiences. 

  • Ability to work independently, prioritise competing demands and bring clarity to complex requirements. 

Desirable Experience 

  • ISO 27001 Lead Implementer or Lead Auditor. 

  • CISM, CRISC, CISSP, CISA or equivalent professional certification. 

  • Experience with NIS2 readiness, third-party risk management, supply chain assurance, GDPR, DORA or other European regulatory frameworks. 

  • Experience using GRC platforms and/or Third-party monitoring platforms.  

Candidate Profile 

This role would suit a confident, experienced risk management professional who enjoys building structure, improving maturity and influencing across an organisation. The ideal candidate will be practical, collaborative and outcome-focused, with the ability to turn risk, governance and compliance requirements into meaningful risk reduction and business value. 

They will be comfortable operating at both strategic and hands-on levels: setting direction, engaging senior stakeholders, developing their team and embedding risk management through clear governance, proportionate compliance and practical assurance activity. 

H&MV Engineering is an Equal Opportunity Employer 

We value diversity and are committed to creating an inclusive environment for all employees. 

Ready to energise your career? 

Join our inclusive team and help build a brighter, more sustainable future—one project at a time. 

 

 

About HMV Engineering

More Jobs at HMV Engineering

HMV Engineering logo

Payroll Assistant - Cork

HMV EngineeringHamilton House, Block 2, Plassey Business Park, Castletroy, Limerick, V94 YHD64 days ago
Finance
HMV Engineering logo

Quality Compliance Coordinator

HMV EngineeringHamilton House, Block 2, Plassey Business Park, Castletroy, Limerick, V94 YHD65 days ago
Quality
HMV Engineering logo

Mechanical Engineer Internship

HMV EngineeringHamilton House, Block 2, Plassey Business Park, Castletroy, Limerick, V94 YHD66 days ago
Engineering