Governance, Risk and Compliance Officer
Computer Software
About the role
We are looking to hire a skilled GRC officer who will be responsible for assessing the effectiveness, efficiency, and security of our IT systems, while ensuring compliance against industry standards, best practices, and internal processes and procedures. As part of his duties, he will be responsible for overseeing compliance with and reporting to Management on how to mitigate possible risk.
Responsibilities
- Develop, review, monitor, and implement the company's information security management system, including processes, policies, systems, and procedures, and continuously improve the ISMS to keep up with changing regulatory
requirements
and industry best practices.
- Develop, review, and monitor the Firm's business continuity & disaster recovery plan and identify potential risks areas and ensure steps are taken to mitigate same.
- Investigate and report violations of processes, procedures and regulatory standards across the operations of the Firm including but not limited to engineering and operations departments with effective action plans in response to discoveries and compliance violations.
- Build an internal audit plan and schedule to cover all aspects as per the management needs.
- Prepare internal audit reports detailing findings, recommendations, and corrective actions.
- Plan and conduct regular audits and assessments to identify areas of non-compliance and develop corrective action plans.
- Monitor and report on compliance issues, including data breaches, security incidents, and regulatory changes, and take appropriate actions to address them.
- Ensure that compliance-related issues are communicated effectively to the leadership team and the board of directors.
- Provide guidance and training employees on security & compliance-related topics, based on the best practices and industry standards.
- Foster a culture of compliance within the organization, where all employees understand the importance of compliance and their role in maintaining it.
- Liaise with external auditors and regulators a…