GRC Specialist Role Summary: Hands-on Governance, Risk, and Compliance (GRC) specialist supporting a banking/financial services client’s information security program—owning control design/evidence, risk assessments, audit/regulatory support, and policy/process hygiene day to day (individual contributor; not a deputy CISO role).
Key Responsibilities:
Support and maintain the information security governance framework, policies, standards, and control library Plan and execute security risk assessments; track findings, remediation owners, and closure evidence Support regulatory and audit engagement (e.g., SOC 1/2, ISO 27001, PCI DSS, and BFSI/regulator-equivalent expectations as applicable) Gather, organize, and quality-check audit and compliance evidence across security, IAM, cloud, and engineering teams Maintain risk registers, control testing schedules, exceptions/waivers, and compliance reporting packs
Support third-party/vendor risk reviews and ongoing due-diligence evidence where required Coordinate with DevSecOps, IAM/CIAM, and security operations teams to map technical controls to GRC obligations Contribute to GRC runbooks, process documentation, and continuous improvement of compliance workflows Escalate material risk, audit, or compliance issues to senior leadership with clear impact and recommended actions
Required Experience: 6+ years in information security GRC, IT risk, audit, or compliance (hands-on delivery; not pure program leadership) Experience supporting audits and control evidence in enterprise environments BFSI or other regulated-industry experience preferred (banking, payments, insurance, or capital markets) Comfortable working with technical teams (security engineering, cloud, IAM) to translate controls into testable evidence
Core Technical Expertise: Security governance, risk & compliance (GRC) Control frameworks and audits: ISO 27001, SOC 1/2, PCI DSS (as applicable); NIST CSF familiarity a plus Risk assessment, control testing, issue management, and remediation tracking Policy, standard, and procedure development/maintenance Audit evidence management and stakeholder coordination Third-party/vendor risk fundamentals (preferred) Familiarity with GRC tooling (e.g., ServiceNow GRC, Archer, or equivalent) preferred
Preferred Certifications CISA, CISM, ISO 27001 Lead Auditor/Implementer, CRISC, or equivalent (as applicable)