GRC Specialist (Governance, Risk and Compliance)

CIMMYT - International Maize and Wheat Improvement Center

Mexico

On-site

PHP 2,214,000 - 3,690,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Year-end bonus (40 days)
Vacation premium (56%)
Life and medical insurance
Supermarket coupons
Savings fund
Social Mexican benefits (IMSS, SAR /In

Job summary

CIMMYT - International Maize and Wheat Improvement Center is seeking a GRC Specialist to serve as the internal subject-matter expert for governance, risk, and compliance across the enterprise application ecosystem. You will own access management, SoD control, license reconciliation, data privacy, and audit readiness across Dynamics 365, Power Platform, ICERTIS, and SAP ecosystems.

The role requires 5+ years in IT GRC or IT audit, hands-on ERP SoD design experience, and strong stakeholder

Qualifications

  • Bachelor's degree in Information Systems, CS, or related field.
  • 5+ years in IT GRC or IT audit; 3+ on enterprise application platforms; ITGC design, testing, remediation.
  • Experience with Dynamics 365 security model and ERP SoD design or assessment.
  • Power Platform governance and license reconciliation.
  • Knowledge of data protection law and ISO 27001, NIST CSF, or COBIT.
  • Certifications such as CISA/CRISC/CISM/CIPP are a plus; CLM/HRIS/GRC tools advantageous.
  • Strong analytical skills and proficiency with reporting/dashboard tools; Power BI advantageous.
  • English proficiency.
  • Ticketing tools familiarity and D365 administration desirable.
  • Stakeholder management and communication without direct line authority.

Responsibilities

  • Own and operate the full-lifecycle Access Management procedure (request, approval, provisioning, modification, recertification, revocation).
  • Maintain the privileged access elevation model, log set, retention, and monitoring per platform.
  • Maintain cross-platform SoD conflict matrix and run risk-ranked assessments with remediation.
  • Review all accounts and reconcile reclaimed accounts to license entitlement.
  • Maintain entitlement register per platform and quantify license usage gaps.
  • Maintain data inventory and processing records, retention and disposal schedules.
  • Maintain ITGC matrix across platforms and drive corrective actions.
  • Coordinate audit readiness activities and track findings to closure.
  • Maintain GRC policy, ERP risk register, and dashboards.

Education

Bachelor's degree in Information Systems, Computer Science, or a related field
Stakeholder management
Communication skills

Tools

Dynamics 365 security model
Power Platform governance
Power BI
ICERTIS
Pathlock
Fastpath
SAP GRC
ServiceNow IRM
ERP SoD design

Job description

CIMMYT is a cutting edge, non-profit, international organization dedicated to solving tomorrow's problems today. It is entrusted with fostering improved quantity, quality, and dependability of production systems and basic cereals such as maize, wheat, triticale, sorghum, millets, and associated crops through applied agricultural science, particularly in the Global South, through building strong partnerships. This combination enhances the livelihood trajectories and resilience of millions of resource-poor farmers, while working towards a more productive, inclusive, and resilient agrifood system within planetary boundaries.

For more information, visit cimmyt.org.

The GRC Specialist will serve as the internal subject-matter expert for governance, risk, and compliance across CIMMYT's enterprise application ecosystem (Dynamics 365 F&O, HR and Customer Engagement, Power Platform, ICERTIS Contract Intelligence, and Sapience HR), responsible for operating a single cross-platform GRC framework covering access control and segregation of duties, licensing and entitlement governance, data privacy, and audit readiness, under the supervision of the ERP Program Manager and in coordination with the CIMMYT ERP team, KMIT, and control and process owners across the institution.

  • Own and operate the full-lifecycle Access Management procedure (request, approval, provisioning, modification, recertification, revocation), and close gaps against each platform.
  • Maintain the privileged access elevation model (justification, approval, duration limits, session logging, post-use review) and the required log set, retention, and monitoring per platform.
  • Maintain the consolidated cross-platform segregation-of-duties (SoD) conflict matrix, run riskranked assessments, agree remediation or mitigating controls with process owners, and operate recurring SoD reporting.
  • Periodically review all accounts (active, dormant, duplicate, generic, shared, service, external), remediate orphaned accounts, and reconcile reclaimed accounts to license entitlement.
  • Maintain an entitlement register per platform, reconcile licenses against actual usage and quantify the gap, assess how security role design drives license tier, and operate request, approval, and reclamation controls so reclaimed accounts convert into recovered cost.
  • Maintain the data inventory and processing record, define and apply retention and disposal schedules, and enable data subject request handling within statutory timeframes.
  • Maintain and test the IT general controls (ITGC) matrix (access, change management, program development, computer operations) across all platforms; report deficiencies, require appropriate corrective actions from process and control owners, challenge inadequate or delayed remediation responses, and track remediation to closure.
  • Keep the evidence base continuously audit-ready, run readiness assessments before scheduled audits, act as coordination point during internal and external audit fieldwork, and track prior findings to closure.
  • Maintain the GRC policy and procedures set with owners and review cycles, the ERP/IT risk register on the institutional scale, and automated key risk and control indicators reporting breaches as they occur.
  • Assess interface controls (completeness, reconciliation, failure alerting, connector privileges) and the control environment of vendors with system or data access, including KMIT, reviewing assurance reports, contractual security, breach notification and audit rights, and relevant service levels.
  • Operate the exception register with expiry dates, contribute to change advisory and incident root-cause analysis, and train control owners on their obligations.
  • Deliver monthly progress reports and the quarterly GRC dashboard to the ERP Program Manager and governance bodies, escalating material findings directly.
  • Perform other related tasks within the job level as may be requested by the immediate supervisor.
Requirements
  • Bachelor's degree in Information Systems, Computer Science, or a related field.
  • Minimum of 5 years of experience in IT GRC or IT audit, of which at least 3 on enterprise application platforms; ITGC design, testing, and remediation experience in an audited environment.
  • Hands-on experience with the Dynamics 365 security model (F&O roles, duties, and privileges; CE role-based security) and practical ERP SoD design or assessment.
  • Experience with Power Platform governance (environments, DLP policies, Dataverse security) and license reconciliation.
  • Working knowledge of data protection law and of ISO 27001, NIST CSF, or COBIT.
  • Experience preferred; CISA, CRISC, CISM, or CIPP certification an advantage; experience with ICERTIS or a comparable CLM platform, HRIS governance, a GRC tool (Pathlock, Fastpath, SAP GRC, ServiceNow IRM), or in multi-jurisdiction environments an advantage.
  • Strong analytical skills and proficiency with reporting and dashboard tools; Power BI or equivalent an advantage.
  • Full professional proficiency in English.
  • Familiarity with ticketing tools and D365 administration highly desirable.
  • Strong stakeholder management and communication skills without direct line authority, with the ability to interact professionally with internal clients across IT, Finance, HR, Legal, and vendor teams.
Benefits
  • year-end bonus (40 days)
  • vacation premium (56%)
  • life and medical insurance
  • supermarket coupons
  • savings fund
  • social Mexican benefits (IMSS, SAR / Infonavit)

Please note only short-listed candidates will be contacted.

Foreign national candidates must have legal documents to work in Mexico.

This position will remain open until filled.

CIMMYT is an equal opportunity employer. It fosters a multicultural work environment that values gender equality, teamwork, and respect for diversity.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

M26339 Cybersecurity Manager (Locally Recruited)
M26339 Cybersecurity Manager (Locally Recruited)

CIMMYT • Mexico

On-site
MXN 900,000 - 1,300,000
Year-end bonus (40 days)
Vacation premium (56%)
Life and medical insurance
+3
GRC Specialist: Data Privacy, Access & Audit Readiness
GRC Specialist: Data Privacy, Access & Audit Readiness

CIMMYT - International Maize and Wheat Improvement Center • Mexico

On-site
PHP 2,214,000 - 3,690,000
Year-end bonus (40 days)
Vacation premium (56%)
Life and medical insurance
+3
Cybersecurity Manager
Cybersecurity Manager

CIMMYT - International Maize and Wheat Improvement Center • Mexico

On-site
PHP 4,426,000 - 7,377,000
Year-end bonus
Vacation premium
Life and medical insurance
+3
Program Manager - Genetics Resources Program
Program Manager - Genetics Resources Program

CIMMYT - International Maize and Wheat Improvement Center • Mexico

On-site
PHP 3,320,000 - 5,533,000
Year-end bonus
Vacation premium
Life and medical insurance
+3
CLM Specialist (Contract Lifecycle Management) - Locally Recruited
CLM Specialist (Contract Lifecycle Management) - Locally Recruited

CIMMYT • Hinoba-an

On-site
PHP 796,000 - 1,326,000
Health insurance
M26336 Program Finance Business Partner (Locally Recruited)
M26336 Program Finance Business Partner (Locally Recruited)

CIMMYT • Mexico

On-site
MXN 700,000 - 900,000
Year-end bonus (40 days)
Vacation premium (56%)
Life and medical insurance
+3
Cyber Governance, Risk and Compliance Specialist
Cyber Governance, Risk and Compliance Specialist

Virtual Business Partners Pty. Ltd. • Cebu City

On-site
PHP 800,000 - 1,200,000
HMO + Dental/Optical
Christmas vacation
Electricity & Data subsidies
+3
Information Security Analyst, GRC & ISMS
Information Security Analyst, GRC & ISMS

GMV • España

Hybrid
PHP 600,000 - 800,000
Hybrid working model
Flexible working hours
Competitive compensation
+1
Program Finance Business Partner
Program Finance Business Partner

CIMMYT - International Maize and Wheat Improvement Center • Mexico

On-site
PHP 3,321,000 - 5,535,000
Senior GRC Analyst New India
Senior GRC Analyst New India

Litmos Limited • Hinoba-an

On-site
PHP 600,000 - 1,200,000