Job Summary
GRC
Bachelor\'s degree in Information Security, Computer Science, Information Technology, Risk Management, or a related field. 8+ years of experience in Governance, Risk, and Compliance (GRC), Information Security, Audit, or Risk Management. Strong knowledge of: ISO/IEC 27001 ISMS requirements and controls NIST Cybersecurity Framework (CSF) NIST SP 800-53 and related NIST standards SOC 1 and SOC 2 audit frameworks Risk assessment methodologies and control testing Experience in developing and maintaining security policies, standards, and procedures. Familiarity with compliance management and GRC tools. Excellent analytical, documentation, and stakeholder management skills. Preferred Qualifications Professional certifications such as: CISSP ,CISA ,CRISC ,ISO 27001 Lead Implementer or Lead Auditor Experience with cloud security frameworks (Azure, AWS, Google Cloud). Knowledge of additional compliance frameworks such as PCI DSS, GDPR, HIPAA, or CSA CCM. Experience supporting enterprise-scale security and compliance programs.
Key Responsibilities
We are seeking a skilled and motivated Governance, Risk, and Compliance (GRC) professional to support the organization\'s information security, risk management, and compliance initiatives. The ideal candidate will have hands-on experience with industry frameworks and standards including ISO/IEC 27001, NIST Cybersecurity Framework (CSF), NIST 800-series publications, SOC 1, and SOC 2. The role involves conducting risk assessments, managing compliance programs, supporting audits, and driving continuous improvement of security controls. Key Responsibilities Support the development, implementation, and maintenance of the organization\'s GRC program. Conduct information security risk assessments and ensure identified risks are appropriately tracked and remediated. Assist in maintaining compliance with ISO 27001 requirements, including support for certification audits and surveillance audits. Evaluate and assess security controls against NIST frameworks and industry best practices. Coordinate and support SOC 1 and SOC 2 audits, including evidence collection, control testing, and remediation activities. Monitor compliance requirements and recommend improvements to policies, standards, and procedures. Perform gap assessments against regulatory and industry frameworks. Track remediation activities and collaborate with stakeholders to ensure timely closure of identified findings. Support third-party/vendor risk assessments and due diligence activities. Develop compliance reports, risk dashboards, and metrics for management review. Facilitate internal audits and coordinate with external auditors and certification bodies. Promote security awareness and governance best practices across the organization.
Skill Requirements
Bachelor\'s degree in Information Security, Computer Science, Information Technology, Risk Management, or a related field. 8+ years of experience in Governance, Risk, and Compliance (GRC), Information Security, Audit, or Risk Management. Strong knowledge of: ISO/IEC 27001 ISMS requirements and controls NIST Cybersecurity Framework (CSF) NIST SP 800-53 and related NIST standards SOC 1 and SOC 2 audit frameworks Risk assessment methodologies and control testing Experience in developing and maintaining security policies, standards, and procedures. Familiarity with compliance management and GRC tools. Excellent analytical, documentation, and stakeholder management skills. Preferred Qualifications Professional certifications such as: CISSP ,CISA ,CRISC ,ISO 27001 Lead Implementer or Lead Auditor Experience with cloud security frameworks (Azure, AWS, Google Cloud). Knowledge of additional compliance frameworks such as PCI DSS, GDPR, HIPAA, or CSA CCM. Experience supporting enterprise-scale security and compliance programs.