Lead Group GRC manager
Become the driving force behind Evidi’s governance, risk, and security excellence - across the Nordics and beyond
Evidi is strengthening its corporate governance and hiring a Lead Group GRC Manager to shape and scale our group‑wide GRC framework across the Nordics and beyond.
This is a rare opportunity to build a modern GRC function in a fast‑growing tech company with strong ambitions.
In this role, you will drive how governance, risk, and security are embedded into Evidi’s operating model. You’ll influence strategic decisions, strengthen organisational resilience, and ensure we operate securely, efficiently, and in line with regulatory expectations.
If you’re motivated by turning governance into real business value, this is your chance to create a scalable framework with clear, measurable impact—and leave your mark on Evidi’s next growth chapter.
Key Responsibilities
Governance, Risk & Compliance
Maintain and improve Evidi’s GRC framework, policies, controls, and routines.
Lead GRC projects across entities, including integrations and regulatory implementation.
Ensure compliance and recertification for ISO 27001/9001 and key regulations (GDPR, NIS2, DSA, EU AI Act).
Run governance routines: risk assessments, monitoring, reporting, committees, and awareness.
Information Security
Maintain and develop the ISMS in line with the CISO’s strategy.
Strengthen security capabilities (incident response, vulnerabilities, IAM, architecture, data protection, endpoints, continuity).
Drive security governance, risk visibility, compliance, and security culture.
Audit, Risk & Supplier Management
Act as Group Lead Auditor for internal and supplier audits.
Lead risk and assurance processes, reporting, and mitigation follow‑up.
Strengthen supplier governance and third‑party risk management.
Qualifications
Bachelor’s degree in IT/computer science or equivalent experience.
ISO 27001 Lead Implementer/Auditor certification (preferred)
Solid expertise in information security, ISO standards, audits, risk management, and compliance.
Knowledge of GDPR, NIS2, AI Act, DSA, and governance frameworks.
Strong communication, stakeholder management, and coordination skills.
Experience in Microsoft‑based environments and cross‑entity/international projects (a plus)
Why Work with us?
Work on impactful product development with modern tech and great autonomy.
Collaborate with a skilled, friendly team in a supportive environment.
Flexible work arrangements – We’re a geographically distributed team, and we support remote and hybrid work styles. You can be located in Norway or countries within the European Union / European Economic Area.
Opportunity for skills development and personal development
Great freedom and opportunity to influence your own working life
We care.
Good pension and insurance schemes
We are Evidi
Our values and attitudes create competitiveness and opportunities. We dare to demand challenges. We love to solve problems. We exceed expectations. We do more than others, and deliver to many of Norway's most ambitious businesses. We are happy to share the solutions. We contribute with everything from strategy and consulting, to development, integration and management of critical IT solutions.
More than just tech people
We are enthusiastic and committed.
And there has never been any doubt that our people are our most important resource.
We care.
#About the profession #About colleagues and customers #About partners #and the society we live in.
- Department
- Corporate Governance
- Role
- Lead Group GRC manager
- Locations
- Multiple locations
- Remote status
- Hybrid
- Employment type
- Full-time