Execute IT risk management and compliance activities across the organization.
Develop and maintain risk criteria; identify, analyze, and evaluate information security risks.
Conduct IT risk assessments to identify risks across information systems, infrastructure, and cloud environments.
Perform ongoing risk assessments and support the development and execution of a dynamic risk assurance plan focused on high‑risk areas (internal and external).
Facilitate and coordinate internal and external control testing activities, including SOX-related efforts.
Collaborate with IT stakeholders to oversee IT General Controls and drive improvements to meet SOX audit requirements.
Review evidence of control effectiveness to evaluate the quality and performance of implemented controls.
Assist management in addressing complex audit issues with internal and external auditors.
Support the full policy lifecycle, ensuring IT and security policies are regularly reviewed and updated.
Participate in SDLC or project lifecycle stages to ensure the effective implementation of security controls.
Assess vendor information security risk profiles using questionnaires, organizational policies, industry standards, and best practices.
Promote cybersecurity awareness through internal communication channels to strengthen the organization’s security culture.
Collaborate with cross‑functional teams to embed security awareness into business functions and ongoing projects.
requirements-expected :
Bachelor’s degree in Information Systems, Computer Science, or equivalent professional experience.
3+ years of relevant experience in Information Security, IT Risk Management, IT Compliance, or a related technology field.
Knowledge of IT external standards such as SOX.
Preferred certifications - CISA
Experience with GRC platforms (preferred).
Strong written and verbal communication skills with the ability to lead difficult conversations and influence stakeholders.
Effective interpersonal and group communication skills, including negotiation, influencing, presentations, motivation, change management, and training capabilities.
Demonstrated consulting skills with experience coaching and mentoring others.