Job DescriptionThis is full-time onsite role based in our Bethlehem office.
Why This Role Matters
At Hansen, we're looking for a hands-on, high-impact security GRC professional to help us scale and mature our governance, risk, and compliance practices globally. You'll design, implement, and evolve security governance initiatives, drive data protection efforts, own business continuity readiness, and be a visible force for change across the organisation. This is a rare opportunity to blend autonomy, innovation, and execution in a role that touches every corner of the business.
We're looking for a builder, a strategic problem-solver, and a passionate security evangelist who thrives on making security integral to how we work.
What You'll Do
- Risk Management: Lead and conduct cybersecurity risk assessments aligned with Hansen's risk framework, identifying key findings and treatment actions. Ensure all risks related to security controls are documented, tracked, and remediated with accountability. Communicate risk status and third-party assessment outcomes to relevant stakeholders.
- Governance & Compliance: Develop, maintain, and enforce security policies and standards aligned with ISO 27001, SOC, NIST, and regulatory requirements. Support internal and external audits, certifications, and compliance monitoring, ensuring controls operate effectively and remediation is followed up.
- Information Security Management System (ISMS): Operate and continuously improve the ISMS, maintaining governance documentation, risk registers, and management reporting to meet audit and regulatory expectations.
- Data Protection & Identity Management: Implement and monitor data protection controls, conduct regular user access reviews to ensure least privilege, and validate that security mechanisms are correctly configured and effective.
- Security Awareness: Lead security awareness programs and campaigns to build a strong security culture across the organisation, engaging stakeholders and measuring impact.
- Incident Response & Resilience Readiness: Maintain and test the incident response plan through simulations and exercises. Own the Business Continuity and Disaster Recovery (BCP/DR) planning, coordinating regular testing and improvements to ensure organisational resilience.
- Stakeholder & Third-Party Risk Management: Engage with internal teams, external auditors, regulators, and third-party vendors to manage cybersecurity risks, provide assurance, and oversee third-party security performance.
- Governance & Reporting: Support and optimise GRC toolsets for risk tracking, control monitoring, and reporting. Produce clear and actionable management information for leadership and regulatory submissions.
What You Bring
- Strong background in hands-on security governance, risk management, and compliance delivery.
- Proven experience implementing and managing technical and administrative data protection controls.
- Working knowledge of key frameworks (ISO 27001, NIST, GDPR, SOC2, ITGC, etc.).
- Experience leading BCP/DR programs and running real or simulated incident response scenarios.
- Exceptional communication skills - you can translate control language into business impact and vice versa.
- Past experience driving security awareness programs and influencing behaviour across departments.
- Demonstrated ability to self-start, self-direct, and innovate in ambiguous environments.
You're someone who (may) have:- Experience in a similar role working in the technology industry.
- Conducted Incident Response Tests and developed scenarios
- Configured data protection or data loss prevention controls in corporate IT environments.
If you are passionate about talent sourcing, candidate engagement, and supporting a high-quality recruitment process, we'd love to hear from you.
Contact Us
If you possess the desired skills and enthusiasm, please "Apply Now" via the link or visit our career page.