Description
The GRC Analyst is responsible for supporting and managing the organization's Governance, Risk, and Compliance (GRC) activities to ensure compliance with information security, privacy, AI governance, and regulatory requirements. The role involves coordinating audits, conducting risk assessments, managing compliance initiatives, responding to client security due diligence, evaluating third-party risks, developing policies and procedures, and driving continuous improvement of the organization's governance framework.
Requirements
• Good understanding of Governance, Risk, and Compliance (GRC) principles.
• Knowledge of information security fundamentals and risk management concepts.
• Understanding of ISO management systems, particularly ISO 27001.
• Strong analytical and problem-solving skills.
• Excellent written and verbal communication skills.
• Strong documentation and report-writing abilities.
• Ability to manage multiple priorities and work effectively in a cross-functional environment.
• Good stakeholder management and interpersonal skills.
• Proficiency in Microsoft Office applications, particularly Excel, Word, and PowerPoint.
• Bachelor's degree in Information Technology, Computer Science, Cyber Security, Information Systems, Business Administration, or a related field.
• Basic understanding of cloud platforms such as AWS, Google Cloud Platform (GCP), and Oracle Cloud Infrastructure (OCI), including identity and access management, networking, storage, compute, and cloud security concepts.
• Familiarity with information security frameworks and standards such as ISO 27001, ISO 27701, ISO 42001, SOC 2, NIST Cybersecurity Framework, and CIS Controls.
• Understanding of privacy regulations such as GDPR, UK GDPR, DPDP Act, CCPA/CPRA, or similar global privacy laws.
• Knowledge of risk assessments, audit methodologies, supplier risk management, and security governance.
• Familiarity with AI governance, responsible AI principles, and AI risk management is desirable.
Responsibilities
• Support and maintain the organization's compliance programs, including ISO 27001, ISO 27701, ISO 42001, ISO 9001, and other applicable standards and frameworks.
• Plan, coordinate, and support internal and external audits, including tracking observations, corrective actions, and continual improvement initiatives.
• Review and respond to client security questionnaires, RFPs, due diligence requests, and contractual security requirements.
• Conduct supplier and third-party risk assessments, including cloud services, SaaS platforms, AI tools, and technology vendors.
• Perform information security, privacy, AI, and business risk assessments, including DPIAs, AI Impact Assessments (AIIAs), and risk register maintenance.
• Develop, review, and maintain policies, procedures, standards, guidelines, and compliance documentation.
• Monitor applicable regulatory and industry requirements, including GDPR, UK GDPR, DPDP Act, CCPA/CPRA, and other relevant privacy and security regulations.
• Collaborate with Engineering, Infrastructure, Product, Legal, HR, Sales, and other business teams to implement security, privacy, and compliance controls.
• Support governance activities for cloud environments, AI solutions, and emerging technologies.
• Track compliance metrics, audit evidence, risk treatment plans, and management reports.
• Identify compliance gaps and recommend practical remediation and process improvement initiatives.
• Support security awareness and compliance training across the organization.
• Stay informed of emerging regulatory requirements, industry standards, cybersecurity threats, and best practices.
Benefits
- 29 paid annual leave days.
- 10 Festival holidays (including 1 optional Holiday for your special day through the year).
- Family Insurance Plan.
- Accident Insurance Plan.
- Regular Wellness Sessions.
- Regular Rewards & Recognition.
- Opportunity to participate in charity initiatives and volunteering.
- Opportunity to participate in Cultural and Sporting Events.
Apply Now