استخدام IT GRC Analyst
شرح موقعیت شغلی
We are seeking a highly motivated and detail-oriented IT GRC (Governance, Risk, and Compliance) Analyst to join our team. In this critical role, you will help ensure our organization maintains compliance with regulatory requirements, effectively manages IT-related risks, and upholds strong governance practices. You will collaborate with various teams to identify, assess, and mitigate risks while implementing and maintaining policies, procedures, and controls to support our compliance and risk management objectives.
Key Responsibilities:
• GRC Framework Development: Assist in the development, implementation, and maintenance of the organization’s IT Governance, Risk, and Compliance (GRC) framework.
• Risk Assessment: Conduct IT risk assessments and assist in the identification, analysis, and prioritization of risks across the organization’s IT landscape.
• Compliance Monitoring: Monitor compliance with regulatory requirements, industry standards, and internal policies (e.g., GDPR, ISO 27001, SOC 2, PCI DSS).
• Policy Development: Collaborate with cross-functional teams to develop and maintain IT policies, procedures, and controls that mitigate risks and ensure compliance.
• Audit Support: Support internal and external audits by preparing documentation and coordinating audit activities related to IT governance and compliance.
• Risk Register Maintenance: Maintain and update the IT risk register, tracking, and reporting on risk mitigation efforts.
• Vendor Risk Management: Conduct third-party/vendor risk assessments to ensure compliance with organizational security and risk standards.
• Training and Awareness: Provide training and awareness programs to employees on IT compliance, risk management, and governance practices.
• Reporting: Assist in the development and reporting of key risk indicators (KRIs) and metrics for senior management.
• Industry Awareness: Stay up-to-date on industry trends, regulatory changes, and best practices in IT GRC.
Required Skills and Qualifications:
• Bachelor’s degree in Information Technology, Information Security, or a related field.
• 2+ years of experience in Governance, Risk, Compliance, or related IT roles.
• Strong understanding of regulatory frameworks and standards relevant to IT (e.g., GDPR, HIPAA, ISO 27001, SOC 2, NIST).
• Experience with IT risk assessment methodologies and tools.
• Proficiency in GRC tools or platforms (e.g., Archer, ServiceNow GRC, or similar).
• Strong analytical and problem-solving skills with a keen attention to detail.
• Excellent written and verbal communication skills, with the ability to convey complex information clearly to technical and non-technical audiences.
• Ability to manage multiple tasks and prioritize effectively in a fast-paced environment.
• Strong interpersonal skills and the ability to collaborate with cross-functional teams.
Preferred Qualifications:
• Relevant certifications such as CISA, CRISC, CISSP, or similar.
• Experience with third-party/vendor risk management.
• Familiarity with cloud security and compliance frameworks (e.g., AWS, Azure, or Google Cloud compliance).
• Experience in conducting internal or external audits.
Key Responsibilities:
• GRC Framework Development: Assist in the development, implementation, and maintenance of the organization’s IT Governance, Risk, and Compliance (GRC) framework.
• Risk Assessment: Conduct IT risk assessments and assist in the identification, analysis, and prioritization of risks across the organization’s IT landscape.
• Compliance Monitoring: Monitor compliance with regulatory requirements, industry standards, and internal policies (e.g., GDPR, ISO 27001, SOC 2, PCI DSS).
• Policy Development: Collaborate with cross-functional teams to develop and maintain IT policies, procedures, and controls that mitigate risks and ensure compliance.
• Audit Support: Support internal and external audits by preparing documentation and coordinating audit activities related to IT governance and compliance.
• Risk Register Maintenance: Maintain and update the IT risk register, tracking, and reporting on risk mitigation efforts.
• Vendor Risk Management: Conduct third-party/vendor risk assessments to ensure compliance with organizational security and risk standards.
• Training and Awareness: Provide training and awareness programs to employees on IT compliance, risk management, and governance practices.
• Reporting: Assist in the development and reporting of key risk indicators (KRIs) and metrics for senior management.
• Industry Awareness: Stay up-to-date on industry trends, regulatory changes, and best practices in IT GRC.
Required Skills and Qualifications:
• Bachelor’s degree in Information Technology, Information Security, or a related field.
• 2+ years of experience in Governance, Risk, Compliance, or related IT roles.
• Strong understanding of regulatory frameworks and standards relevant to IT (e.g., GDPR, HIPAA, ISO 27001, SOC 2, NIST).
• Experience with IT risk assessment methodologies and tools.
• Proficiency in GRC tools or platforms (e.g., Archer, ServiceNow GRC, or similar).
• Strong analytical and problem-solving skills with a keen attention to detail.
• Excellent written and verbal communication skills, with the ability to convey complex information clearly to technical and non-technical audiences.
• Ability to manage multiple tasks and prioritize effectively in a fast-paced environment.
• Strong interpersonal skills and the ability to collaborate with cross-functional teams.
Preferred Qualifications:
• Relevant certifications such as CISA, CRISC, CISSP, or similar.
• Experience with third-party/vendor risk management.
• Familiarity with cloud security and compliance frameworks (e.g., AWS, Azure, or Google Cloud compliance).
• Experience in conducting internal or external audits.
مهارتهای مورد نیاز
- GRC
- IT
حداقل سابقه کار
- کمتر از سه سال
جنسیت
- مهم نیست
وضعیت نظام وظیفه
- مهم نیست