Senior GRC Specialist – Human Risk
Gem dette job og hold din søgning organiseret
Opret en gratis konto for at gemme job, oprette underretninger og vende tilbage til denne fortegnelse fra dit dashboard.
Security is About Managing Risk. People Are Part of That Risk.
At TDC NET, we operate critical infrastructure that millions of Danes rely on every day. While technology, processes, and security controls are essential, security incidents still occur where people, processes, and technology intersect.
We are looking for a Senior GRC Specialist to strengthen how TDC NET identifies, manages, and governs security risks influenced by human actions, decisions, and behaviors.
About the job
This is not a traditional awareness role focused on training, communications, or employee engagement initiatives. Instead, you will drive TDC NET's Human Risk agenda from a security and risk management perspective, identifying where human actions, decisions, or operating practices create security vulnerabilities and control weaknesses.
As part of our Governance, Risk & Compliance (GRC) team, you will also contribute to risk management, governance, compliance, audits, and ISMS activities across TDC NET.
Your Mission
Reduce human-related security risk by reinforcing security behaviours, improving decision-making, and embedding effective security controls into the way TDC NET operates every day.
You will work closely with leaders, risk owners, operational teams, and security specialists to turn behavioural insights into measurable risk reduction and improved organizational resilience.
Key Responsibilities
Drive Human Risk Reduction and Security Capability
- Act as the subject matter lead for human-related security risks within TDC NET's Security Risk Management framework, ensuring risks arising from human actions and decision-making are identified, assessed, treated, and monitored through established governance processes.
- Develop and coordinate risk-based communications, awareness activities, guidance, and interventions that address identified security risks and strengthen control effectiveness.
- Develop and maintain metrics, KPIs, and reporting that provide insight into human-related security risks, control effectiveness, and risk reduction, enabling data-driven decisions and continuous improvement across TDC NET.
Partner Across the Business
- Advise leaders, risk owners, and operational teams on how human factors influence security risk and control effectiveness.
- Facilitate workshops and discussions that support risk-informed decision-making.
- Challenge existing practices and identify opportunities to improve security resilience and control effectiveness.
Contribute Across Governance, Risk & Compliance
- Embed human-risk considerations into TDC NET's security governance, risk management, and compliance processes.
- Support risk assessments, audits, regulatory engagements where human factors influence risk exposure or control effectiveness.
- Contribute to the continuous development of the ISMS, security controls, and broader GRC framework.
About the Team
You’ll join the Governance, Risk & Compliance team within Security.
We're a team of specialists who help TDC NET make informed decisions about risk, security, and compliance. Our work spans everything from risk management and governance to audits, regulatory requirements, supplier assurance, and the ongoing development of our security framework.
What brings us together is a shared ambition to make security practical, effective, and relevant for the business. We work closely with colleagues across TDC NET, challenge each other professionally, and value open dialogue, pragmatism, and a healthy dose of curiosity.
“You'll have the opportunity to be in charge of your area, shape how we work, and collaborate with experienced colleagues who are committed to protecting critical infrastructure while keeping things practical and grounded.”
Thomas Behr-Rasmussen, Senior Director, Security Governance, Risk & Compliance
About you
You are likely someone who:
- Understands how human behaviour influences security outcomes.
- Can influence stakeholders without relying on formal authority.
- Communicates complex topics in a clear and pragmatic manner.
- Is comfortable engaging both leadership teams and operational stakeholders.
- Combines strategic thinking with practical execution.
Experience We Value
- You bring experience from several of the following areas:
- Information Security, Security Governance, or Security Risk Management
- Human Risk Management, Security Behavior, or Security Awareness
- GRC, Audit, Compliance, or Regulatory Assurance
- ISMS and ISO 27001-based environments
- Working in critical infrastructure or other highly regulated sectors
Why Join TDC NET?
This role offers a rare opportunity