GRC Specialist
Core
Design, develop, and support Identity & Access Management (IAM) operations while strengthening security controls and reducing unauthorized access risks.
Role type
Senior GRC & IAM Engineer
Builds
Functional, scalable, and secure IAM operations
Domain
Information Security / GRC / Risk Management
Required skills
Information Security governance frameworks (COBIT, ISO 27001), risk assessment methodologies (OCTAVE, NIST SP 800-30), security policy review, gap analysis, network protocols, software development background, systems administration
Preferred skills
Data Privacy Impact Assessments (DPIAs), AI and Data Governance projects, CRISC/CISA/CEH certifications
Technologies
COBIT, ISO 27001, OCTAVE, NIST SP 800-30
Responsibilities
Support development and improvement of Information Security governance framework; Recommend and implement changes to strengthen security controls; Review and audit security policies and procedures; Monitor compliance with legal and industry standards; Perform risk assessments and identify mitigation actions; Support audits and gap analyses; Coordinate company-wide security controls; Contribute to Data Privacy, AI Governance, and Data Governance initiatives
Seniority
Senior, hands-on IC