Job Summary    This role reports to the Information Security Governance, Risk and Compliance (GRC) Senior Director and partners across Product, Technology, Operations, Legal, Compliance, and Business teams to strengthen and mature Bottomline's information security, risk, and compliance programs. As the Information Cyber GRC Manager, you will serve as a strategic leader responsible for driving governance, risk management, compliance oversight, and client assurance initiatives. You will build trust and confidence among customers, regulators, auditors, and executive leadership regarding Bottomline's security posture while leading a team of GRC professionals. This role requires a forward-looking mindset, including the ability to assess and manage emerging risks associated with Artificial Intelligence (AI) and support the responsible adoption of AI technologies across the organization.  Essential Functions and Responsibilities:  | - Governance: Lead the development, maintenance, and execution of the information security governance program, including policies, standards, and controls aligned with regulatory requirements and industry frameworks (e.g., SWIFT, NACHA, PCI DSS, NIST, GLBA).Â
- Risk Management: Own the cyber risk management program, including oversight of the risk register, risk assessments, risk treatment plans, and executive reporting. Review and approve risk acceptance decisions using a risk-based approach.Â
- Compliance & Regulatory Oversight: Lead compliance activities and assessments to ensure adherence to regulatory, contractual, and industry requirements. Drive audit readiness and remediation efforts across the organization.Â
- Client & Security Assurance: Oversee customer security and compliance engagements, including due diligence reviews, security questionnaires, contract reviews, and client assurance activities. Act as a trusted advisor on information security and risk matters.Â
- People Leadership: Lead, mentor, and develop a team of Cyber GRC professionals. Establish priorities, manage performance, allocate resources, and drive execution of strategic and operational objectives while fostering a high-performing team culture.Â
- AI Governance & Innovation: Lead the evaluation and governance of Artificial Intelligence (AI) technologies and associated risks across the organization. Establish AI risk assessment practices, support responsible AI adoption, and stay at the forefront of emerging AI capabilities, regulatory developments, and industry trends to enhance security, compliance, and operational effectiveness.Â
 |
 Required Experience & Qualifications - Bachelor’s degree in risk management, cybersecurity, technology or equivalentÂ
Preferred Experience & Qualifications - Professional certifications such as CISSP, CISM, CRISC, CISA, CGRC, or equivalent. Â
- Strong knowledge of regulatory and industry frameworks including SWIFT, NACHA, PCI DSS, NIST, and GLBA. Â
- Experience with AI governance frameworks, AI risk management, and emerging regulatory requirements related to Artificial Intelligence. Â
- Experience leveraging automation, analytics, and AI-driven capabilities within security, risk, and compliance programs.Â
Note: This job description is not intended to be an exhaustive list of all duties, responsibilities, or qualifications associated with the position. |