Job Title: Governance, Risk & Compliance (GRC) Manager — Internal Audit Lead
Department: Financial Services
Overview:
SymphonyAI is poised at the forefront of digital transformation, establishing itself as the leading enterprise AI SaaS company for key growth industries such as retail, financial services, manufacturing, and more. Founded in 2017, SymphonyAI has expanded to serve over 2,000 enterprise customers worldwide, supported by a team of 2,500 professionals across more than 30 countries. Our Financial Services vertical is seeking a GRC Manager to lead our global internal audit program and maintain our established ISO certifications and SOC 2 attestation. This role is essential for ensuring compliance and driving continuous improvement across our integrated management systems.
About the Role:
As a GRC Manager at SymphonyAI Financial Services, you will run our internal audit program, ensuring the integrity of certifications including ISO 9001, ISO/IEC 27001, and ISO 22301, as well as SOC 2 attestations for AWS and Azure environments. You will spearhead efforts toward obtaining ISO/IEC 42001 certification for AI governance, while executing audits, managing findings, and preparing for external assessments. This visible role involves collaboration with various departments and providing critical guidance on control design and effectiveness.
Job Description
Key Responsibilities:
Internal Audit Programme:
- Own and execute the annual internal audit plan covering ISO 9001, ISO/IEC 27001, ISO 22301, and SOC 2 (Type II) requirements globally.
- Conduct risk-based internal audits of business processes, technical controls, and cloud infrastructure.
- Produce actionable audit reports; present findings and recommendations to senior leadership.
- Manage closure of nonconformities, observations, and corrective/preventive actions.
Management Systems (IMS):
- Maintain and improve the integrated management system and associated documentation.
- Facilitate management reviews, control self-assessments, and risk assessments.
- Map and harmonize controls across frameworks to enhance audit efficiency.
- Support the design and integration of the AI management system (AIMS).
External Audit & Certification Maintenance:
- Coordinate with external auditors and certification bodies for audit scheduling and remediation.
- Prepare stakeholders for audit interviews and maintain certification integrity.
- Lead audit-readiness activities for ISO/IEC 42001 certification.
Cloud & Technical Compliance:
- Assess cloud security and change management controls within AWS and Azure environments.
- Collaborate with engineering teams to automate compliance checks.
- Apply AI tools and automation to enhance audit processes and reporting.
- Evaluate disaster recovery testing against ISO 22301 standards.
Risk, Governance & Advisory:
- Support risk management processes, including third-party risk assessments.
- Advise on control implications for new products and organizational changes.
- Deliver training on management system requirements and audit expectations.
AI-First Ways of Working:
- Use AI tools extensively in daily work activities to enhance audit efficiency.
- Promote AI-enabled GRC processes across the team.
- Remain updated on emerging AI capabilities and adopt approved tools.
Required Qualifications & Experience:
- 5+ years' experience in GRC, internal audit, or information security compliance.
- Certified Lead Auditor in ISO/IEC 27001; additional qualifications in ISO 9001 or ISO 22301 preferred.
- In-depth knowledge of AWS and Azure services for credible technical audits.
- Understanding of AI/ML technologies and the associated risks.
- Demonstrated use of AI tools in audit processes.
Desirable:
- Professional certifications like CISA, CISM, CRISC, CISSP.
- Experience in regulated environments such as financial services.
- Familiarity with GRC platforms and evidence automation tools.
- Knowledge of ISO/IEC 42001 and other frameworks.
What Success Looks Like in Year One:
- Successful delivery of the annual internal audit plan with zero certification lapses.
- Completion of external audits with no major nonconformities.
- Progress toward ISO/IEC 42001 certification with implementation in progress.
- Improved CAPA closure rates and reduced audit finding recurrence.
Diversity & Inclusion Statement:
We are committed to building a diverse and inclusive team and encourage candidates from all backgrounds to apply.
About Us
SymphonyAI is building the leading enterprise AI SaaS company for digital transformation across the most critical and resilient growth industries, including retail, consumer packaged goods, financial crime prevention, manufacturing, media, and IT service management. Since its founding in 2017, SymphonyAI today serves 1500+ Enterprise customers globally and has grown to 3,000 talented leaders, data scientists, and other professionals across over 30 countries.