Role Overview
The GRC Team Member will support the organization's Governance, Risk, and Compliance initiatives by ensuring adherence to regulatory requirements, managing security risks, and maintaining compliance with internal and external standards. The role involves policy management, risk assessments, audit coordination, and ensuring effective security governance across the business
Key Responsibilities:
- Assist in creation, review, and maintenance of security policies, SOPs, and compliance frameworks.
- Support implementation of governance practices aligned with ISO 27001, SOC 1& 2, NIST, or applicable standards.
- Monitor compliance with IT and cybersecurity governance requirements.
- Conduct periodic IT and cyber risk assessments and maintain risk registers.
- Identify gaps in controls and track remediation activities with stakeholders.
- Assist in internal audits, external audits, regulatory inspections, Control testing
- Coordinate evidence collection and control testing for compliance frameworks.
- Track audit findings and ensure timely closure of non‑conformities.
- Support compliance reporting for leadership and regulators.
- Maintain documentation related to policies, processes, risk registers, compliance checklists, and audit evidence.
- Ensure version control and timely updates to all GRC documents.
- Support security awareness and training programs.
- Collaborate with IT, Cyber Security, HR, Vendor Management, and Business Units for GRC-related initiatives.
- Work with platforms like ITSM, Zabbix, Splunk or equivalent tools.
- Maintain dashboards and metrics for governance, risk, and compliance reporting.
- Create Reports, PPT, Documents related to GRC Activities.
- Review Architecture Design, Network Diagram
Required Skill:
- 4-10 years of relevant experience
- Strong understanding of IT Security fundamentals
- Experience with risk management, compliance monitoring, and audit processes
- Knowledge of standards like ISO 27001, SOC 1 &2, NIST, as applicable
- Good analytical, documentation, and reporting skills
- Basic understanding of cloud security (AWS/Azure/GCP) is a plus
- Certifications preferred: ISO 27001 LA/LI, CISA, CRISC, CISM
- Good command of English communication is required