· Identifying, assessing, and mitigating potential risks across various areas of the organization, including IT security, business processes, and regulatory compliance.
· Developing, implementing, and maintaining GRC programs and processes to support compliance and risk management efforts.
· Assisting with internal and external audits, responding to audit findings, and ensuring corrective actions are implemented.
· User Access review
· Creating and maintaining policies and procedures related to governance, risk, and compliance.
· Conducting gap analysis and implementing frameworks and standards such as ISO 27001, GDPR, NIST, and SOX.
· Developing and revising policies, standards, processes, and guidelines for the organization. · Conducting vendor risk assessments against organizational security requirements.
· Continually testing and monitoring the effectiveness of security controls.
· Conducting research to aid threat assessment or risk mitigation activities.
· Assist the department in responding to inquiries from the business units about ongoing operational compliance
· Working with various teams and departments to ensure GRC practices are integrated into business operations.
