The GRC Specialist will support the Information GRC team, reporting to the Sr. Director of IGRC within the Information Risk Management organization. This role is responsible for assisting with the execution of IT control training, remediation activities, and supporting IT compliance assessments. The ideal candidate will have strong IT audit experience, exceptional communication skills, hands-on knowledge of IT controls, extensive documentation capabilities, and the ability to work collaboratively to drive remediation and training initiatives.
What you will do :
- Assist in the execution of IT control training programs for IT and business stakeholders.
- Support remediation efforts for IT control deficiencies, including tracking, documentation, and follow-up.
- Collaborate with IT teams to analyze processes, risks, and controls, and recommend practical solutions for remediation.
- Maintain and update IT process and control documentation to support compliance with SOX, internal policy, and regulatory requirements.
- Act as a resource for IT audit engagements, supporting evidence collection, issue resolution, and communication with audit teams.
- Help assess alignment of IT controls with frameworks such as COBIT, ITIL, and NIST.
- Contribute to root cause analyses and identify opportunities for process improvement in IT risk and compliance programs.
- Support the IGRC team in project management for compliance assessments and remediation initiatives.
What you will need :
Bachelor’s or Technical Degree preferred (Computer Science, Information Systems, Business Administration, or related field). Equivalent industry experience with certifications or specialized training will be considered.Minimum of four years of IT audit, compliance, risk assurance, IT advisory, or internal audit experience.Strong understanding of IT controls, audit processes, and remediation best practices.Experience supporting IT control training and remediation activities.Certification in one or more of the following is desired : ITIL, ISO 27000, COBIT, CISSP, SANS, CISA, Security+, CMMC.Excellent communication, organizational, and documentation skills.Ability to work independently and collaboratively in a fast-paced environment.Preferred Skills :
Experience with regulatory compliance requirements (SOX, GDPR, HIPAA, etc.).Familiarity with enterprise risk management and IT service management (ITSM) practices.Proven ability to support process improvements in IT risk and compliance programs.