Job description
GRC – ITRO Risk & Compliance Officer
Summary of Duties:
- Project Management: Drive and meet project milestones with a customer-focused mindset.
- GRC Expertise: Proficient in NIST, ISO 27001:2013, SOX ITGC, Cloud Compliances, SIG, and more.
- Advisory Role: Lead IT Risk & Compliance, manage audits, compliance, and risk programs.
- Communication: Simplify complex GRC issues for business stakeholders.
- Framework Development: Build and manage a resilient GRC foundation.
- Compliance & Audits: Ensure SLA adherence, timely audits, and manage external audits.
- IRM Solutions: Strategy and implementation of IRM technology solutions.
- Documentation: Oversee high-level document design and conduct solution workshops.
Skills:
- Mandatory: Alyne GRC experience in Policy & Compliance Management, Risk Management, Audit Management, Cloud controls matrix (CCM), ISO27001.
- Desirable: Experience with other GRC tools, excellent documentation, presentation, communication, and stakeholder management skills.
Education:
- Essential: Bachelor’s degree in computer science, information systems, or related field.
- Desirable: Security certifications (ISO 27001, CISA, CISM, CEH, CISSP, CRISC, CGEIT, CCSK), GRC product vendor certifications, Alyne GRC Certifications.
Experience:
- Total IT GRC: Over 12 years.
- Alyne GRC: 3-5 years, including technology implementation, upgrades, and processes.
- Additional Skills: Scripting, coding, tool configurations, integrations.