GRC Analyst (Governance, Risk & Compliance)

APPIT Software Inc.

Dubai

On-site

AED 150,000 - 200,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

APPIT Software Inc. is looking for an experienced compliance specialist to manage and maintain compliance programs across various frameworks such as ISO 27001 and SOC 2. The role involves coordinating audits and risk assessments, developing information security policies, and preparing compliance reports for stakeholders.

The ideal candidate will have over 4 years of relevant experience and strong knowledge of auditing processes. Familiarity with GRC platforms is a plus. This position is located in Dubai, United Arab Emirates.

Qualifications

  • 4+ years of experience in GRC, IT audit, or information security compliance roles.
  • Strong working knowledge of ISO 27001, ISO 27002, SOC 2, NIST CSF and regional frameworks (NESA IAS).
  • Experience managing audit cycles end-to-end including scoping, evidence collection and remediation tracking.
  • Understanding of risk management methodologies (FAIR, NIST RMF, ISO 31000).
  • Excellent written and verbal communication skills.

Responsibilities

  • Manage and maintain compliance programs across ISO 27001, SOC 2, NESA and GDPR frameworks.
  • Conduct enterprise risk assessments and maintain the risk register.
  • Coordinate internal and external audit activities.
  • Develop, review and update information security policies.
  • Perform third-party vendor risk assessments and manage the vendor security review lifecycle.

Skills

ISO 27001
SOC 2
Risk Assessment
Audit Management
NIST CSF
Vendor Risk Management
Policy Development

Tools

ServiceNow GRC
OneTrust
Archer

Job description

Responsibilities
  • Manage and maintain compliance programs across ISO 27001, SOC 2, NESA and GDPR frameworks.
  • Conduct enterprise risk assessments and maintain the risk register, tracking risk treatment plans to completion.
  • Coordinate internal and external audit activities, manage evidence collection and ensure timely remediation of findings.
  • Develop, review and update information security policies, standards and procedures aligned with business objectives.
  • Perform third‑party vendor risk assessments and manage the vendor security review lifecycle.
  • Prepare compliance reports and risk dashboards for executive leadership and board‑level stakeholders.
Requirements
  • 4+ years of experience in GRC, IT audit, or information security compliance roles.
  • Strong working knowledge of ISO 27001, ISO 27002, SOC 2, NIST CSF and regional frameworks (NESA IAS).
  • Experience managing audit cycles end‑to‑end including scoping, evidence collection and remediation tracking.
  • Understanding of risk management methodologies (FAIR, NIST RMF, ISO 31000).
  • Familiarity with GRC platforms such as ServiceNow GRC, OneTrust or Archer.
  • Excellent written and verbal communication skills with the ability to translate technical risks for business audiences.
Nice to Have
  • CISA, CRISC or ISO 27001 Lead Auditor certification.
  • Experience with UAE NESA and DIFC data protection regulations.
  • Knowledge of PCI DSS compliance requirements.
Skills
  • ISO 27001, SOC 2, Risk Assessment, Audit Management, NIST CSF, Vendor Risk Management, Policy Development.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Consultant Information Security GRC
Senior Consultant Information Security GRC

Paramount Computer Systems • Dubai

On-site
AED 300,000 - 600,000
GRC Analyst: Lead Compliance, Risk & Audit (ISO 27001/SOC 2)
GRC Analyst: Lead Compliance, Risk & Audit (ISO 27001/SOC 2)

APPIT Software Inc. • Dubai

On-site
AED 150,000 - 200,000
Senior Consultant – Information Security (GRC)
Senior Consultant – Information Security (GRC)

Paramount Computer System • Dubai

On-site
AED 350,000 - 500,000
GRC Delivery Manager
GRC Delivery Manager

Intertec Softwares Pvt Ltd • Dubai

On-site
AED 300,000 - 540,000
Travel opportunities
Senior GRC Specialist
Senior GRC Specialist

United Arab Emirates University, Department of Family Medicine • Abu Dhabi

On-site
AED 180,000 - 240,000
Senior InfoSec GRC Consultant – ISO 27001 & Risk
Senior InfoSec GRC Consultant – ISO 27001 & Risk

Paramount Computer System • Dubai

On-site
AED 350,000 - 500,000
Security Governance, Risk, Compliance Lead
Security Governance, Risk, Compliance Lead

Sokin • United Arab Emirates

On-site
AED 350,000 - 550,000
Operational Risk & GRC Lead
Operational Risk & GRC Lead

TASC Outsourcing • Abu Dhabi

On-site
AED 300,000 - 450,000
Assistant Manager – Public Sector | ERS (GRC)
Assistant Manager – Public Sector | ERS (GRC)

KPMG Fakhro • Abu Dhabi

On-site
AED 300,000 - 480,000
GRC Implementation Engineer
GRC Implementation Engineer

Intertec Softwares Pvt Ltd • Dubai

On-site
AED 180,000 - 320,000