GRC Analyst
CapitalSage Holdings
Remote
Key Responsibilities:
- Support the implementation and maintenance of information security policies, standards, procedures and control frameworks.
- Assist with information security and cybersecurity risk assessments and maintain the Group's risk register.
- Support compliance assessments against applicable regulatory, contractual and industry requirements.
- Coordinate the collection, validation and maintenance of audit and compliance evidence.
- Support internal and external information security audits and regulatory assessments.
- Assist with the implementation and maintenance of the Information Security Management System (ISMS) and ISO 27001 requirements.
- Track security control effectiveness, compliance gaps, audit findings and remediation actions.
- Maintain accurate records of security policies, controls, risks, exceptions and compliance obligations.
- Support third-party/vendor security assessments and due diligence activities.
- Prepare periodic GRC reports, dashboards, KPIs and KRIs for management review.
- Support information security awareness, policy compliance and staff communication activities.
- Monitor changes in applicable cybersecurity, data protection and regulatory requirements and escalate relevant impacts.
- Follow up with control owners and stakeholders on outstanding remediation and compliance actions.
- Relevant degree or equivalent professional qualification in Cybersecurity, Information Technology, Computer Science, Engineering or a related discipline.
- Relevant professional certifications will be an advantage and should align with the specific role.
- Demonstrable practical experience relevant to the position.
- Strong communication, analytical, documentation and stakeholder-management skills.
- Ability to operate in a regulated, technology-driven and multi-business environment.
- ISO/IEC 27001 Foundation / Internal Auditor – preferred
- CISA – Certified Information Systems Auditor – advantage
- CRISC – Certified in Risk and Information Systems Control – advantage
- ISO/IEC 27001 Lead Implementer or Lead Auditor – advantage
- CISM – Certified Information Security Manager – advantage
- Data Protection/Privacy certification or training – advantage
- PCI DSS training/certification – advantage
Industry Standard