As a Cybersecurity GRC, this position plays an vital role to support the implementation and management of governance, risk, and compliance initiatives that safeguard the organization's information assets. This role involves assisting in the execution of cybersecurity policies, conducting risk assessments, participating in audits, and evaluating third-party risk. You will contribute to aligning business objectives with security best practices and regulatory standards such as ISO 27001, NIST, and ITGC.
Requirements
- Support the implementation of GRC frameworks (ISO 27001, NIST, COBIT) across various functions.
- Assist in drafting and updating cybersecurity policies, procedures, and control documentation.
- Conduct and document basic IT/cybersecurity risk assessments and internal control reviews.
- Maintain portions of the risk register and support the tracking of mitigation plans and KRIs.
- Assist in internal/external audit activities, including control testing and evidence collection.
- Perform initial third-party risk reviews and support due diligence documentation.
- Track audit findings and help monitor remediation efforts to closure.
- Contribute to compliance with global cybersecurity regulations (SOX, GDPR, DPDP, PCI-DSS).
- Help prepare GRC dashboards and reports for internal stakeholders.
- Collaborate with IT, legal, privacy, and compliance teams to support GRC initiatives.
- Stay current on regulatory changes and industry standards impacting cybersecurity.
- Support security awareness campaigns and participate in user training initiatives.
- Work with GRC tools (e.g., Archer, ServiceNow GRC, or Excel-based trackers) to manage workflows and data.
- Assist in the design, implementation, and maintenance of cybersecurity GRC frameworks (ISO 27001, NIST, COBIT, etc.)
Benefits
- Generous Paid Time Off
- 401k Matching
- Retirement Plan
- Tuition Reimbursement