HimalayasHimalayas logo
The Mill AdventureTA

Senior GRC Specialist

The Mill is a creative studio based in Malta, providing visual effects and animation services for the media and entertainment industry.

The Mill Adventure

Employee count: 201-500

Malta only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

The Mill Adventure is a scale-up with the ultimate mission of building awesome products that will change the way the iGaming industry operates. We started our journey in 2019, with the vision of building a technology driven organisation and creating a team consisting of the best of the best specialists in their respective fields.

Today, we provide a complete gaming platform, including licences and operations, for rapid deployment and success in iGaming. Our team of 130+ technology and iGaming experts is guided by passion for invention, operational excellence and commitment to improve the inefficient.

We trust and value our team and we strive to accommodate the right working conditions for each individual, in remote, office based or mixed models. We see the strength in being different and embrace the cultural diversity existing in our group.

As our business continues to grow, we are looking for a highly autonomous and experienced Senior / Lead GRC Specialist. In this role, you will not just maintain our GRC function—you will own it. Working closely with our CISO and security engineering team, you will be responsible for defining the road ahead: identifying our gaps, selecting the right frameworks, and taking full responsibility for our governance, risk, and compliance posture. We need a mature professional who knows how to listen to engineering teams, build pragmatic policies, and drive security without being a roadblock.

What You Will Do:

  • Establish the GRC Roadmap: Assess our current environment, identify gaps, and design a clear, actionable GRC roadmap aligned with our business goals. You tell us what we are missing and how to fix it.
  • Act as a Business Enabler: Eradicate the "security as a blocker" mentality. Partner actively with product and engineering teams during the design phases to find secure paths to "yes," ensuring our governance supports business velocity rather than slowing it down.
  • Lead Framework Implementation: Take full responsibility for managing and maturing our ISO 27001:2022 certification. Drive compliance initiatives for PCI DSS and prepare our posture for NIS2 requirements.
  • Drive Risk Management: Autonomously select and implement the most appropriate risk management frameworks. Own the risk register, lead risk assessments, and translate complex technical risks into clear business impacts and mitigation strategies.
  • Design Business-Aligned Governance: Design, write, and enforce information security policies and standards. Actively solicit feedback from engineering and business teams to ensure policies are practical and business-enabling.
  • Champion Security Culture: Own and evolve our security awareness program. Move us beyond boring, "check-the-box" compliance videos by creating engaging, context-aware training that actually resonates with engineers, product teams, and business operations.
  • Lead Audits & Compliance: Take the helm on all internal and external security-focused audits, assessments, and reviews. Act as the definitive subject matter expert for regulatory inquiries.

Requirements

You'll be a great fit if you have:

  • 5–8+ years of dedicated experience in Cyber GRC, Information Security, or Technology Risk.
  • Framework Expertise: Demonstrated, hands-on experience implementing and managing ISO 27001:2022 (mandatory). Deep knowledge of PCI DSS and familiarity with NIS2 is highly desirable.
  • iGaming Experience is a Strong Plus: A deep understanding of the technology-led, highly regulated iGaming environment is highly desirable. (If you don't have this, proven experience in similarly complex, fast-paced, and regulated sectors like fintech, SaaS, or payments is a great substitute).
  • An "Enabler" Mindset: The commercial awareness to understand that security exists to protect the business, not to halt it. You excel at finding pragmatic, secure workarounds rather than just throwing up red tape.
  • Strategic & Autonomous Execution: You don't need a checklist; you create the checklist. You have a track record of building or significantly maturing GRC functions from the ground up.
  • Mature Judgment: You possess the emotional intelligence to work alongside highly technical teams. You leave your ego at the door, listen to feedback, and focus on collaborative problem-solving.
  • Exceptional Communication: Strong analytical, risk assessment, and documentation skills, with the ability to articulate complex security concepts to both engineers and executive leadership.
  • Alignment with our Values: High integrity, ownership, transparency, and a continuous drive for performance and improvement.

Benefits

  • A lean, focused company, offering a flexible working environment
  • The opportunity to work with and learn form a highly skilled, talented team
  • A great company culture, where accountability is innate, transparency is key and competency is virtue
  • Being part of a small, tight knit, caring community
  • Work equipment of your choice
  • Private health insurance
  • Learning budget
  • Fitness benefit
  • Parking/transport or co-working allowance
  • Company wide and team based get togethers

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Experience

5 years minimum

Location requirements

Hiring timezones

Malta +/- 0 hours

About The Mill Adventure

Learn more about The Mill Adventure and their company culture.

View company profile

The Mill is a leading creative studio specializing in visual effects, animation, and immersive content for various platforms. Committed to pushing the boundaries of creativity, The Mill has established itself as a key player in the production and effects industry, offering innovative solutions to meet the demands of modern storytelling.

Founded with a vision to transform the landscape of visual media, The Mill is dedicated to collaboration and excellence. The Mill provides a range of services from concept to completion, employing cutting-edge technology and a team of talented professionals. Their portfolio includes work for some of the biggest brands and agencies, demonstrating their ability to deliver high-quality, impactful content across global markets.

Claim this profileThe Mill Adventure logoTA

The Mill Adventure

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

4 remote jobs at The Mill Adventure

Explore the variety of open remote roles at The Mill Adventure, offering flexible work options across multiple disciplines and skill levels.

View all jobs at The Mill Adventure

Remote companies like The Mill Adventure

Find your next opportunity by exploring profiles of companies that are similar to The Mill Adventure. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan