Manage internal and external security audit activities, including audit planning, coordination, tracking of audit findings, and ensuring the timely implementation and closure of remediation actions. Support compliance monitoring and continuous improvement efforts relating to ISO/IEC27000 certification and other regulatory requirements.
Manage and ensure authorised access governance in accordance with organisational and regulatory requirements, including reviewing, approving, revoking, and tracking access rights and exceptions where required.
Maintain the cybersecurity risk register, perform cybersecurity risk assessments, monitor risk mitigation plans, and follow up on remediation actions to ensure identified risks are addressed within stipulated timelines. Escalate significant risks to Management where necessary.
...
Basic familiarity with Technology Risks and Controls, Governance, Risk and Compliance tools
Basic knowledgeable in GRC tools configuration preferably with implementation experience in automating GRC processes using tools like Archer and Service now
Basic knowledge in the integration of the GRC tools with external data sources through API's and database integrations
...