
IT GRC Manager, Logistics
$ 1 - $ 1 / month
Checking job availability...
Original
Simplified
Job Description
Governance:
- Drive IT governance programs, including policies, processes, and controls.
- Ensure alignment of IT strategy with business goals and regulatory requirements.
Risk Management:
- Identify, assess, and mitigate IT risks through regular risk assessments and audits.
- Develop and manage the IT risk register, tracking risks and ensuring mitigation strategies are implemented.
Compliance:
- Ensure IT processes and systems comply with industry standards, regulations, and internal policies (e.g., ISO 27001, NIST, GDPR, PDPA, SOX).
- Oversee IT audits and assessments, acting as the key point of contact for auditors and regulators.
GRC Tools and Reporting:
- Develop metrics and dashboards to monitor governance, risk, and compliance performance.
- Deliver clear reporting to senior management on risk exposure, compliance status, and governance maturity.
Training and Awareness:
- Provide ongoing training and awareness to employees on IT GRC policies, frameworks, and best practices.
- Promote a risk-aware culture throughout the organization.
Job Description
Governance:
- Drive IT governance programs, including policies, processes, and controls.
- Ensure alignment of IT strategy with business goals and regulatory requirements.
Risk Management:
- Identify, assess, and mitigate IT risks through regular risk assessments and audits.
- Develop and manage the IT risk register, tracking risks and ensuring mitigation strategies are implemented.
Compliance:
- Ensure IT processes and systems comply with industry standards, regulations, and internal policies (e.g., ISO 27001, NIST, GDPR, PDPA, SOX).
- Oversee IT audits and assessments, acting as the key point of contact for auditors and regulators.
GRC Tools and Reporting:
- Develop metrics and dashboards to monitor governance, risk, and compliance performance.
- Deliver clear reporting to senior management on risk exposure, compliance status, and governance maturity.
Training and Awareness:
- Provide ongoing training and awareness to employees on IT GRC policies, frameworks, and best practices.
- Promote a risk-aware culture throughout the organization.