GRC Operations Specialist
Own and improve third-party risk management and security awareness programs, coordinate GRC operations, and use AI tools to increase efficiency. Support audits, risk assessments, certifications, policy management, and business continuity.
Responsabilidades
- Manage the third-party risk program, including vendor assessments, supplier records, annual follow-ups, and end-to-end workflows.
- Manage the security awareness program, including employee training and phishing simulations; maintain its scope, content, cadence, and performance.
- Plan and track GRC projects and periodic and annual activities.
- Improve GRC efficiency through innovation, automation, research, and AI tools.
- Support internal and external audits, risk assessments, certifications, policy management, and business continuity.
Requisitos
- At least 3 years of experience in cybersecurity or GRC.
- Experience with cyber, IT, or third-party risk management.
- Experience developing and implementing security awareness and training programs, including testing such as phishing simulations.
- Hands-on daily use of AI tools, including chatbots and AI-assisted development of scripts, automations, or internal tools.
Se valora
- Familiarity with frameworks, standards, regulations, and certifications such as SOC 2, ISO, NIST, CIS, DORA, or GDPR.
- Experience with GRC software and risk, vendor, policy, awareness, training, or phishing platforms.
- Experience in financial services or digital assets.
- Understanding of technology and product development practices.