GRC Specialist Role Summary: Hands-on Governance, Risk, and Compliance (GRC) specialist supporting a banking/financial services client’s information security program—owning control design/evidence, risk assessments, audit/regulatory support, and policy/process hygiene day to day (individual contributor; not a deputy CISO role).
Key Responsibilities:
- Support and maintain the information security governance framework, policies, standards, and control library
- Plan and execute security risk assessments
- track findings, remediation owners, and closure evidence
- Support regulatory and audit engagement (e.g., SOC 1/2, ISO 27001, PCI DSS, and BFSI/regulator-equivalent expectations as applicable)
- Gather, organize, and quality-check audit and compliance evidence across security, IAM, cloud, and engineering teams
- Maintain risk registers, control testing schedules, exceptions/waivers, and compliance reporting packs
- Support third-party/vendor risk reviews and ongoing due-diligence evidence where required
- Coordinate with DevSecOps, IAM/CIAM, and security operations teams to map technical controls to GRC obligations
- Contribute to GRC runbooks, process documentation, and continuous improvement of compliance workflows
- Escalate material risk, audit, or compliance issues to senior leadership with clear impact and recommended actions
Required Experience:
- 6+ years in information security GRC, IT risk, audit, or compliance (hands-on delivery; not pure program leadership)
- Experience supporting audits and control evidence in enterprise environments
- BFSI or other regulated-industry experience preferred (banking, payments, insurance, or capital markets)
- Comfortable working with technical teams (security engineering, cloud, IAM) to translate controls into testable evidence
Core Technical Expertise:
- Security governance, risk & compliance (GRC)
- Control frameworks and audits: ISO 27001, SOC 1/2, PCI DSS (as applicable)
- NIST CSF familiarity a plus
- Risk assessment, control testing, issue management, and remediation tracking
- Policy, standard, and procedure development/maintenance
- Audit evidence management and stakeholder coordination
- Third-party/vendor risk fundamentals (preferred)
- Familiarity with GRC tooling (e.g., ServiceNow GRC, Archer, or equivalent) preferred
Preferred Certifications:
- CISA, CISM, ISO 27001 Lead Auditor/Implementer, CRISC, or equivalent (as applicable)