Key Responsibilities
- Assist in developing, reviewing, and maintaining IT policies, procedures, and standards.
- Support implementation of governance frameworks (e.g., ISO 27001, NIST, PCI).
- Ensure alignment between business objectives and security/governance controls.
- Identify, assess, and document IT risks, and track mitigation actions and ensure risks are addressed within defined timelines.
- Ensure compliance with relevant standards such as: PCI, ISO 27001 / ISO 22301, and regulatory requirements (as applicable)
- Support internal and external audits (e.g., PCI audits, certification audits).
- Collect and validate compliance evidence.
- Coordinate internal audit activities and prepare documentation.
- Prepare GRC dashboards and reports for management.
Qualifications & Requirements
Education
- Bachelor's degree in information security, IT, Computer Science, or related field.
Experience
- 1–3 years of experience in GRC, or IT Security.
- Hands-on experience with compliance frameworks (PCI DSS,PCI CP preferred).
Certifications (Preferred)
- ISO 27001 Lead Implementer / Lead Auditor
- CRISC, or CGRC
- PCI DSS-related certifications (e.g., PCIP)
Technical Skills
- Knowledge of:
- Risk assessment methodologies
- Security controls and frameworks
- Audit processes and compliance requirements
Soft Skills
- Strong analytical and problem-solving skills
- Excellent communication and reporting skills
- Attention to detail
- Ability to work cross-functionally with IT, Audit, and information security