About the role
The GRC & Compliance Analyst supports the organization's Governance, Risk & Compliance, Information Security, Data Privacy, and Process Governance programs through documentation management, compliance tracking, evidence preparation, reporting, and administrative coordination. The role works closely with the GRC Manager – Information Security & Data Privacy and serves as the primary support for controlled documentation, audit readiness, compliance records, action tracking, and recurring governance activities. This is a documentation-intensive role requiring strong attention to detail, organization, follow-through, and the ability to work across multiple departments.
Key responsibilities
- Maintain the organization's controlled-document repository, including policies, procedures, guidelines, standards, templates, and forms
- Manage document numbering, version control, approval records, effective dates, review dates, and document history
- Review documents for compliance with approved templates and document-control requirements
- Track scheduled policy and procedure reviews and follow up with document owners on updates and approvals
- Maintain ISMS records, compliance trackers, risk registers, exception logs, audit findings, and corrective-action registers
- Collect, organize, and validate documentary evidence for ISO/IEC 27001, client assessments, internal reviews, and external audits
- Assist in preparing audit schedules, evidence folders, meeting materials, and follow-up trackers
- Support the preparation of client security questionnaires, RFP security requirements, and due-diligence requests
- Maintain privacy-related records, registers, agreements, assessments, and compliance documentation
- Maintain incident logs, corrective and preventive action trackers, and follow up with assigned owners
About you
- Bachelor's degree in Business Administration, Information Technology, Information Systems, Legal Management, Industrial Engineering, Quality Management, or a related field
- 2–4 years of relevant experience in compliance, document control, information security, data privacy, quality management, audit support, process documentation, or a related function
- Excellent documentation and records-management skills
- Strong attention to detail and accuracy
- Strong organizational and follow-through skills
- Ability to manage multiple trackers, deadlines, and recurring requirements
- Good written English and business communication
- Strong working knowledge of Microsoft Office, particularly Word, Excel, and PowerPoint
- High level of confidentiality and discretion when handling sensitive information
- Experience working with controlled documents, trackers, audit evidence, or compliance records is an advantage