Role Overview
The GRC Specialist is responsible for supporting and maintaining an organization’s governance, risk management, and compliance programs across enterprise and client environments. This role focuses on translating regulatory, contractual, and security requirements into practical controls, policies, and processes that reduce risk while enabling business operations. The GRC Specialist will work closely with security, IT, legal, audit, and business stakeholders to assess risk, support compliance initiatives, and ensure alignment with recognized frameworks, regulatory requirements, and organizational objectives.
Key Responsibilities
- Support the development, implementation, and maintenance of governance, risk, and compliance programs across enterprise and client environments.
- Conduct risk assessments, gap analyses, and control evaluations aligned with frameworks such as NIST, ISO 27001, CIS, SOC 2, HIPAA, PCI DSS, and other applicable standards.
- Assist in the development, review, and enforcement of security policies, standards, procedures, and guidelines.
- Support internal and external audits by gathering evidence, tracking findings, and assisting with remediation efforts.
- Maintain risk registers, compliance documentation, and control inventories, ensuring accuracy and audit readiness.
- Perform vendor and third‑party risk assessments, including security questionnaires and risk reviews.
- Collaborate with technical teams to map security and privacy requirements to implemented controls.
- Track regulatory and contractual requirements and support ongoing compliance monitoring.
- Prepare reports, metrics, and executive‑level summaries related to risk posture and compliance status.
- Contribute to continuous improvement initiatives to strengthen governance maturity and risk management practices.
Qualifications
- Strong understanding of governance, risk management, and compliance principles within cybersecurity and information security domains.
- Hands‑on experience with risk assessments, compliance reviews, and control validation activities.
- Familiarity with security and compliance frameworks such as NIST CSF/RMF, ISO 27001, CIS Controls, SOC 2, and regulatory requirements as applicable.
- Experience supporting audits and compliance initiatives, including evidence collection and remediation tracking.
- Strong analytical and documentation skills, with the ability to translate technical and regulatory requirements into clear, actionable guidance.
- Ability to collaborate effectively with technical and non‑technical stakeholders.
- Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or a related field.
- Relevant certifications such as CGRC, CISA, CRISC, Security+, ISO 27001 Lead Implementer, or similar are preferred.
Ideal Candidate Profile
The ideal candidate is detail‑oriented, methodical, and comfortable working at the intersection of security, compliance, and business operations. They understand how governance and risk programs support security outcomes and can balance compliance requirements with practical implementation.