GRC, Privacy & Security Awareness Manager
Job description
GRC, Privacy & Security Awareness Manager at Bamboohr.
About the role
Bamboohr is seeking a GRC, Privacy & Security Awareness Manager to lead the development and execution of governance, risk, compliance, and security awareness programs across the entire organization. This role is responsible for building a culture of security and compliance awareness among all employees, ensuring that the company consistently meets regulatory obligations and internal policy standards. The manager will design and implement training initiatives, manage privacy programs, and coordinate with cross-functional teams to embed risk-aware practices into daily business operations. This position reports directly to senior leadership and plays a critical part in safeguarding the company's data assets, maintaining regulatory standing, and protecting the organization's reputation in the marketplace. The ideal candidate will bring a strategic mindset combined with hands-on experience in managing enterprise-wide awareness campaigns that drive measurable improvements in organizational security posture.
Key facts
What you'll do
Design and deliver a comprehensive security awareness training program for all employees across every department and organizational level, ensuring consistent coverage and engagement.
Develop and maintain comprehensive governance frameworks that align with industry standards and regulatory requirements for the organization.
Create clear privacy policies and procedures that ensure the protection of customer and employee personal data at all times.
Conduct regular risk assessments to identify vulnerabilities in business processes and recommend appropriate mitigation strategies and controls.
Coordinate compliance audits and prepare detailed documentation to demonstrate adherence to applicable laws, regulations, and internal governance standards.
Lead incident response awareness training so staff can recognize and report security threats promptly and correctly.
Build and manage a library of training materials including presentations, guides, videos, and interactive learning modules.
Collaborate with IT and legal teams to ensure security policies reflect current threat landscapes and regulatory changes.
Measure the effectiveness of awareness programs through surveys, assessments, feedback collection, and tracking of training completion rates across the organization.
Serve as the primary point of contact for privacy and security inquiries from employees and external stakeholders.
Requirements
Bachelor's degree in information technology, cybersecurity, business administration, or a related field is required.
Minimum of five years of experience in governance, risk, compliance, or information security roles within a technology company.
Proven track record of designing and delivering security awareness programs that achieved measurable engagement and behavior change.
Strong understanding of data protection regulations including GDPR, NDPR, and other applicable privacy laws.
Excellent written and verbal communication skills with the ability to translate technical concepts into accessible language.
Experience managing compliance audits and preparing reports for internal and external stakeholders.
Ability to work independently and manage multiple projects with competing priorities in a fast-paced environment.
Familiarity with risk management frameworks such as ISO 27001, NIST, or COBIT is strongly preferred.
Nice to have
Certified Information Systems Security Professional or similar industry-recognized certification in the information security field.
Experience working in fintech or payment processing industries with specific knowledge of financial regulations.
Previous management experience leading a small team of compliance or security professionals effectively.
Knowledge of security orchestration tools and platforms used for awareness campaign tracking, reporting, and metrics.
Skills & tools
Proficiency in Microsoft Office Suite including PowerPoint and Excel for training development and metrics reporting.
Experience with learning management systems and training delivery platforms for employee onboarding and awareness programs.
Familiarity with GRC software platforms for policy management, risk tracking, and compliance documentation.
Understanding of data loss prevention tools and privacy management platforms used in enterprise environments.
Ability to use survey and feedback tools to measure training effectiveness and employee engagement.
Knowledge of collaboration platforms such as Slack or Microsoft Teams for distributing awareness content.
Practical notes
This role is based in Lekki, Lagos and requires on-site presence during standard business hours.
The manager will work closely with the legal, IT, and human resources departments on a regular basis.
Candidates should expect to travel occasionally to other company offices or attend industry conferences and workshops.
All employment terms, compensation details, and conditions will be discussed during the interview process with the hiring team.
Bamboohr values diversity and encourages candidates from all backgrounds to apply for this position.