Enable job alerts via email!
Boost your interview chances
Create a job specific, tailored resume for higher success rate.
An established industry player is on the lookout for a Senior GRC Specialist to lead governance, risk, and compliance initiatives. This pivotal role involves developing and implementing frameworks that align with regulatory standards, conducting audits, and managing enterprise risks. You will collaborate with cross-functional teams to enhance security governance and ensure compliance with best practices. If you are passionate about risk management and compliance and have a strong background in cybersecurity, this opportunity offers a chance to make a significant impact in a dynamic environment.
Job Summary:
We are seeking a highly skilled **Senior GRC Specialist** to lead and enhance our governance, risk, and compliance (GRC) programs. In this role, you will be responsible for ensuring regulatory compliance, managing enterprise risks, and implementing security frameworks to protect organizational assets. You will work closely with cross-functional teams to establish policies, monitor controls, and drive strategic compliance initiatives.
Key Responsibilities:
Governance & Compliance:
- Develop, implement, and maintain GRC frameworks, policies, and procedures in alignment with industry best practices and regulatory requirements (e.g., ISO 27001, NIST, GDPR).
- Conduct internal audits, risk assessments, and control evaluations to ensure adherence to compliance standards.
- Collaborate with internal stakeholders to address regulatory requirements and maintain documentation for external audits.
- Provide guidance on compliance issues and emerging regulatory trends affecting the business.
Risk Management:
- Identify, assess, and mitigate enterprise risks, including cybersecurity, operational, and third-party risks.
- Develop risk mitigation strategies and monitor key risk indicators (KRIs).
- Lead business continuity planning and incident response initiatives.
- Support vendor risk management by evaluating third-party security and compliance postures.
Security & Controls:
- Ensure the effective implementation of security controls, policies, and frameworks across the organization.
- Conduct security awareness training and GRC-related workshops for employees.
- Monitor compliance with IT and data security standards, ensuring alignment with security best practices.
- Work closely with IT and security teams to enhance security governance and ensure proper risk oversight.
Qualifications & Requirements:
**Education:** Bachelors degree in Information Security, Risk Management, Business Administration, or a related field.
**Experience: ** Minimum **3-5 years** of experience in GRC, IT risk management, compliance, or cybersecurity.
**Certifications (Preferred):** CISA, CISM, CISSP, CRISC, or other relevant GRC certifications.
**Knowledge of Regulations & Frameworks:** Strong understanding of ISO 27001, NIST, GDPR, SOX, HIPAA, SOC 2, and other regulatory standards.
**Technical Skills:** Familiarity with GRC tools, risk assessment methodologies, and IT security principles.
**Soft Skills:** Excellent analytical, problem-solving, and communication skills; ability to work cross-functionally and influence stakeholders.