Key Responsibilities :
- Governance & Policy Management
Develop, implement, and maintain corporate governance policies and procedures.
Establish and monitor internal controls aligned with industry best practices and regulatory requirements.Facilitate executive and board-level reporting related to governance and compliance.Risk ManagementIdentify, assess, and monitor enterprise risks (operational, IT, financial, strategic, and reputational).
Collaborate with business units to design and implement risk mitigation strategies.Maintain and update risk registers and develop KRIs (Key Risk Indicators).Compliance OversightEnsure organizational compliance with applicable laws, regulations, and standards (e.g., SOX, GDPR, HIPAA, ISO 27001, NIST, PCI-DSS).
Conduct internal audits and risk assessments to evaluate process effectiveness.Prepare and respond to external regulatory audits and inspections.GRC Technology and ReportingLeverage GRC tools (e.g., RSA Archer, ServiceNow GRC, MetricStream) to manage risk and compliance data.
Generate dashboards, reports, and documentation to support audit readiness and decision-making.Provide training and guidance to stakeholders on GRC processes and tools.Stakeholder CollaborationAct as a liaison between IT, Legal, Compliance, Security, Internal Audit, and senior leadership.
Drive a culture of risk awareness and compliance across departments.Support third-party risk management efforts, including vendor assessments and due diligence.Qualifications :
Bachelor's degree in Business, Risk Management, Information Security, Compliance, or a related field (Master's preferred).5+ years of experience in GRC, internal audit, or enterprise risk / compliance roles.In-depth knowledge of regulatory frameworks (SOX, GDPR, HIPAA, ISO, etc.).Experience with GRC platforms (e.g., RSA Archer, LogicManager, OneTrust, or ServiceNow GRC).Strong analytical, problem-solving, and project management skills.Excellent communication and stakeholder engagement abilities.Certifications preferred : CISA, CRISC, CGEIT, CISM, or CISSP .