13h ago
New

GRC SPECIALIST

OtherIt Specialist
1 views0 saves0 applied

Quick Summary

Overview

RESPONSIBILITIES Develop, implement, and maintain comprehensive GRC frameworks, policies, standards, and procedures in alignment with industry best practices (e.g., ISO 27001, NIST, COBIT, PCI DSS,

Technical Tools
OtherIt Specialist

Responsibilities

~1 min read
  • →Develop, implement, and maintain comprehensive GRC frameworks, policies, standards, and procedures in alignment with industry best practices (e.g., ISO 27001, NIST, COBIT, PCI DSS, GDPR, PIPEDA, etc.).
  • →Conduct regular risk assessments to identify, evaluate, and prioritize information security risks. Develop and monitor risk mitigation strategies and controls.
  • →Perform vendor risk assessments, evaluating the security posture of third-party service providers and ensuring their compliance with our security standards and contractual obligations.
  • →Lead and support internal and external audits, ensuring timely and accurate responses to auditor requests and findings.
  • →Monitor changes in regulatory landscapes and industry standards, assessing their impact on the organization and recommending necessary adjustments to policies and controls.
  • →Collaborate with various departments (IT, Legal, Operations, HR) to embed GRC principles into business processes and foster a culture of compliance.
  • →Manage and track compliance activities, including the remediation of identified gaps and vulnerabilities.
  • →Prepare and present GRC reports and metrics to the Information Security Manager and other stakeholders, providing insights into the organization's risk and compliance status.
  • →Stay up-to-date with emerging threats, vulnerabilities, and cybersecurity trends.



 

Requirements

~1 min read
  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field.
  • 3-5 years of experience in a dedicated GRC, information security, or IT audit role.
  • Solid understanding of cybersecurity frameworks and standards such as ISO 27001, NIST CSF, COBIT, ITIL.
  • Familiarity with privacy regulations relevant to Canada (e.g., PIPEDA) and global regulations (e.g., GDPR) if applicable to the business.
  • Proven experience in conducting risk assessments and developing risk mitigation strategies.
  • Experience performing vendor risk assessments.
  • Strong analytical, problem-solving, and decision-making skills.
  • Excellent written and verbal communication skills, with the ability to articulate complex technical concepts to non-technical audiences.
  • Ability to work independently and collaboratively in a fast-paced environment.
  • Proficiency in both English and French is highly desirable.
  • Preferred Qualifications:
    • Relevant industry certifications such as CISA, CISM, CRISC, CISSP.
    • Knowledge of cloud security principles and compliance requirements (e.g., AWS, Azure, GCP)

Location & Eligibility

Where is the job
India
On-site within the country
Who can apply
IN

Listing Details

Posted
October 6, 2026
First seen
October 6, 2026
Last seen
October 6, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
56%
Scored at
October 6, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

GRC SPECIALIST