- Oversee the Cybersecurity and Risk function across different GE business sites, presence, and interests
- Assist in maintaining the IT governance structure using established frameworks
- Update governance documentation, track process adherence, and support standardization efforts
- Support the Power DT Sarbanes-Oxley compliance program by coordinating testing activities and managing documentation
- Maintain control narratives, risk-control matrices, test evidence, SOX status reports, and the SOX controls repository
- Track testing cycles, identify control gaps or weaknesses, and facilitate remediation efforts
- Lead deficiency identification, tracking, and resolution across GRC domains
- Document findings, assign remediation actions, monitor progress, perform root cause analysis, and escalte overdue or high-risk items
- Analyze deficiency trends and recommend preventive measures
- Support ERP control areas including Identity and Access Management/Privileged Access, SDLC/DevOps change, and IT operations
- Perform routine control testing, maintain evidence files, and support standardization initiatives
- Assist in drafting and updating IT policies and procedures for security, data management, and access control
- Coordinate policy reviews, track acknowledgments, and maintain policy repositories
- Assist with risk assessments, risk registers, and documentation of IT system risks including cybersecurity threats and data breaches
- Support internal and external audits by managing request lists, gathering evidence, organizing documentation, responding to inquiries, and tracking remediation
- Monitor regulations and laws including SOX, NIS2, and GDPR and update control and policy mappings
- Assist in developing training materials and coordinating compliance training sessions
- Build and maintain reports and dashboards on IT risk posture, compliance status, and control effectiveness
- Gather data, validate information, and prepare routine status updates for senior management
Requirements
- Bachelor's degree in Computer Engineering, Computer Science, Information Systems, or a related field (or equivalent experience)
- 1-3 years in IT GRC, IT Audit, or related fields
- Foundational knowledge of SOX ITGCs and application controls
- Any ERP exposure is beneficial
- Basic understanding of ERP systems such as SAP and Oracle
- Interest in learning Segregation of Duties (SoD) concepts, access controls, and configuration standards
- Ability to learn quickly and adapt in a fast-paced environment
- Strong curiosity, first-principles problem solving, and interest in process improvement and metrics-driven approaches
- Good problem-solving and analytical skills
- Strong written and verbal communication skills
- Ability to document findings clearly and communicate with technical and non-technical stakeholders
- Ability to work effectively in team environments and support cross-functional initiatives across IT, Finance, and business partners
- Basic familiarity with GRC concepts and willingness to learn GRC/security tooling and dashboards
- Interest in contributing to process improvements and automation initiatives
- Interest in pursuing certifications such as CISA, CISM, or CRISC
- Openness to learning COBIT frameworks and SOX requirements
- Willingness to learn audit processes and evidence management
- Ability to organize documentation, respond to routine requests, and support audit coordination
- Basic proficiency with data analysis tools
- Familiarity with Excel and willingness to learn Power BI or Tableau
- Interest in pursuing CISA certification within 1-2 years
- Foundational knowledge of CISM, CRISC, or COBIT frameworks beneficial
- Willingness to learn ISO 27001 standards
- Basic understanding of ERP systems, preferably Oracle EBS
- Willingness to develop knowledge of critical access controls, configuration standards, and automated control testing
- Exposure to Identity Governance and Administration platforms such as SailPoint or Saviynt is a plus
- Organizational skills and attention to detail for supporting audit processes
- Ability to assist with evidence gathering and maintain PBC (Provided by Client) lists
- Basic proficiency with data analysis and visualization tools
- Ability to support control analytics and KPI/KRI reports under guidance
- Strong attention to detail in data validation and documentation
Demonstrates foundational knowledge of IT Governance, Risk, and Compliance (GRC) principles, with a focus on Sarbanes-Oxley (SOX) compliance, risk assessments, and control testing. Proficient in documentation, data analysis, and communication with both technical and non-technical stakeholders.
Highest-signal resume keywords
- IT Governance, Risk, And Compliance (GRC)
- Sarbanes-Oxley (SOX) Compliance
- Control Testing And Remediation
- Data Analysis And Visualization
- Communication Skills
ATS Optimization Keywords
Hard Skills
- IT Audit
- Risk Assessments
- Control Narratives
- Risk-Control Matrices
- SOX ITGCs
- ERP Systems
- Identity And Access Management
- Data Analysis
- Documentation Management
- Root Cause Analysis
Soft Skills
- Problem-Solving
- Analytical Skills
- Attention To Detail
- Team Collaboration
- Curiosity
Certifications & Qualifications
Industry Keywords
- SOX
- NIS2
- GDPR
- COBIT
- ISO 27001
- Segregation Of Duties (SoD)
Tools & Technologies
- Excel
- Power BI
- Tableau
- Identity Governance And Administration Platforms
- GRC Tooling