Enable job alerts via email!

GRC Auditor

HR Ways

Karachi Division

On-site

PKR 2,000,000 - 2,750,000

Full time

Yesterday
Be an early applicant

Job summary

A recruitment firm is looking for a GRC Auditor to manage IT audits, ensuring compliance with internal policies and financial regulations. Candidates should have 3-5 years of experience in information security, strong knowledge of IT frameworks, and relevant certifications. This full-time role is based in Karachi and offers a structured working environment from Monday to Friday.

Qualifications

  • 3-5 years of experience in IT audit, information security, or similar roles.
  • Strong understanding of IT and security frameworks like COBIT, ISO27001.
  • Familiarity with financial regulations such as PCI-DSS, GDPR.

Responsibilities

  • Conduct IT risk assessments to identify vulnerabilities and compliance gaps.
  • Collaborate with teams to enforce security controls across all environments.
  • Prepare clear audit reports with findings and recommendations.

Skills

IT audit experience
Information security understanding
Compliance knowledge

Education

Certifications such as CISA, CISSP, or CISM

Tools

IT security frameworks like COBIT
ISO27001 knowledge

Job description

Client Introduction:

Our client is a financial wellness platform aiming to revolutionize how salaries are received and spent.

Job Description:

Purpose:

The GRC Auditor will plan, conduct, and report on audits of IT systems and business processes to ensure compliance with internal policies, industry standards, and regulations. This role is vital in identifying risks, enforcing governance, and ensuring adherence to information security frameworks and data protection laws within a regulated financial services environment.

Knowledge & Skills:

  • 3-5 years of experience in IT audit, information security, or similar roles in regulated financial services.
  • Certifications such as CISA, CISSP, or CISM are highly desirable.
  • Strong understanding of IT and security frameworks like COBIT, ISO27001.
  • Familiarity with financial regulations and standards such as PCI-DSS, GDPR.

Key Responsibilities:

  • Conduct IT risk assessments to identify vulnerabilities and compliance gaps.
  • Evaluate threat landscape and assess risk exposure.
  • Collaborate with IT Security, Infrastructure, DevOps teams to enforce security controls across all environments.
  • Design and execute audit plans to assess IT and cybersecurity controls.
  • Perform control testing for access management, data protection, change management, incident response, and disaster recovery.
  • Adjust audit methodologies based on risk and control maturity.
  • Assess compliance with standards like ISO/IEC 27001, COBIT, PCI-DSS, GDPR.
  • Coordinate with compliance and legal teams on regulatory expectations.
  • Prepare clear audit reports with findings and recommendations.
  • Communicate results to technical and non-technical stakeholders.
  • Maintain audit documentation per standards.
  • Follow up on remediation actions and monitor audit issues.
  • Guide control owners on best practices for improvements.

Behavioral Competencies:

  • Analytical and Critical Thinking
  • Integrity and Accountability
  • Effective Communication
  • Collaboration
  • Time Management
  • Ownership and Initiative

Other Details:

Work Mode: Onsite

Location: Karachi

Employment Type: Full-Time

Working Hours: 9am - 6pm, Monday - Friday

Experience Required: 5+ Years

About HR Ways:

HR Ways is an award-winning technical recruitment firm supporting software houses and IT product companies globally. We work with over 300 employers worldwide, including leading SaaS companies and startups. Visit our WhatsApp Channel or our website for more information.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.