Job Overview
We are looking for a Cybersecurity GRC professional to support cybersecurity governance, risk and compliance activities across the organization.
The role covers cyber risk assessments, security policies, compliance reviews, internal audits and security awareness activities. You will work closely with business and technology stakeholders to identify security risks, monitor controls and support compliance with cybersecurity policies and regulatory requirements.
Key Responsibilities
Cybersecurity Governance & Policy
- Support the development, review and implementation of information security policies, standards and guidelines.
- Monitor compliance with cybersecurity policies and identify areas of non-compliance.
- Manage security policy exceptions and risk deviation requests.
- Provide guidance to stakeholders on cybersecurity policies, standards and control requirements.
- Communicate policy updates and security requirements to relevant teams.
Cyber Risk Management
- Conduct and coordinate cybersecurity risk assessments across systems, applications and business functions.
- Review the effectiveness of cybersecurity controls and risk mitigation measures.
- Maintain the organization’s cybersecurity risk register and track identified risks through remediation.
- Monitor cybersecurity Key Risk Indicators (KRIs) and highlight emerging or significant risks.
- Prepare cybersecurity risk reports and support escalation of key risks to management.
- Track remediation activities and follow up with risk and control owners.
Compliance & Assurance
- Conduct independent reviews and testing of cybersecurity controls to assess compliance with internal policies and regulatory requirements.
- Support cybersecurity compliance assessments and thematic reviews.
- Identify control gaps and provide practical recommendations for improvement.
- Work with stakeholders to track corrective actions through to completion.
- Monitor changes to cybersecurity regulations, standards and industry requirements.
Audit Management
- Support internal and external cybersecurity audits.
- Coordinate audit preparation, documentation and evidence gathering with relevant stakeholders.
- Support stakeholders during audit fieldwork and clarification activities.
- Maintain an audit findings tracker and monitor remediation progress.
- Follow up on outstanding audit findings to support timely closure.
Security Awareness & Stakeholder Engagement
- Support cybersecurity awareness programmes, including phishing simulation exercises.
- Conduct briefings and awareness sessions on cybersecurity risks, policies and compliance requirements.
- Share updates on emerging cybersecurity risks, audit observations and control weaknesses.
- Work closely with technology, business, risk and compliance stakeholders on cybersecurity matters.
Requirements
- Minimum 2 to 3 years of relevant experience in Cybersecurity GRC, information security, IT risk or cybersecurity risk management.
- Experience in the majority of the following areas:
- Cybersecurity risk assessments
- Internal or IT security audits
- Information security policy development and implementation
- Cybersecurity compliance
- Phishing simulations / security awareness
- Experience maintaining risk registers, tracking remediation actions and supporting risk reporting.
- Good understanding of cybersecurity governance, risk and control principles.
- Familiar with cybersecurity regulatory and compliance requirements.
- Experience supporting control reviews, assurance testing or audit activities would be advantageous.
- Strong analytical and problem-solving skills.
- Good written and verbal communication skills.
- Strong stakeholder management and coordination skills.
Please send your detailed resume in MS Word format to ************* with
- Education Level
- Working experiences
- Each employment background
- Reason for leaving each employment
- Last drawn salary
- Expected salary
- Date of availability