- Conduct thorough assessments of IT and business processes to identify risks and vulnerabilities, ensuring alignment with industry best practices and regulatory requirements.
- Develop and implement GRC frameworks, policies, and procedures tailored to the specific needs and risk appetite of each client.
- Lead and facilitate workshops and training sessions to educate stakeholders on GRC principles, tools, and methodologies.
- Perform gap analyses between current state and desired GRC maturity levels, providing actionable recommendations for improvement.
Desired Candidate Profile
Possesses a Bachelor's degree in Information Technology, Cybersecurity, Business Administration, or a related field.
Holds relevant certifications such as CISA, CISM, CRISC, or CISSP, demonstrating a strong understanding of GRC principles.
Demonstrates a minimum of 10 years of experience in IT audit, risk management, or compliance roles within the financial services or healthcare industries.
Exhibits a proven track record of implementing GRC frameworks and managing related projects from inception to completion.