Randstadeos
GRC Analyst
GRC Analyst: E3
Tasks/Responsibilities
• Conducting thorough risk assessments and analyses to identify potential IT infrastructure
risks.
• Evaluating the effectiveness of existing IT controls and recommending improvements.
• Developing and maintaining risk registers for documentation, assessment, and monitoring.
• Ensuring IT operations comply with regulatory requirements and internal policies.
• Assisting in the development and maintenance of IT GRC policies, procedures, and
standards.
• Supporting internal and external audits, ensuring timely responses to audit findings.
• Collaborating with IT and business teams to develop risk mitigation strategies.
• Monitoring and reporting on the status of risk mitigation efforts and controls effectiveness.
• Conducting risk workshops and training sessions to promote a risk-aware culture.
• Analysing risk data and trends to identify potential areas of concern.
• Preparing detailed risk reports and dashboards for senior management and stakeholders.
• Interfacing with IT units and business partners for guidance and support.
• Conducting business impact analysis and assisting in the development of IT/InfoSec risk
register.
• Assisting with compliance projects and tasks.
• Working with Internal Audit and external consultants on security assessments and audits.
• Building and maintaining strong relationships with stakeholders.
Requirement
• Bachelor's degree in IT, Computer Science, Risk Management, or related field.
• Advanced degree or relevant certifications preferred.
• Strong understanding of IT GRC frameworks.
• Proficiency in risk assessment methodologies and tools. (SERVICE NOW)
• Excellent analytical and problem-solving skills.
• Effective communication and interpersonal skills.
• Ability to work independently and as part of a team.
• Minimum of 5 years in a privacy, information security, planning, administration, audit, or
resource and compliance management role. (mitigation)
• Project and change management skills and experience.
• Strong customer service orientation and ability to project this attitude to customers in remote
locations.
• Regular reports on Headspace's internal controls status.
• Overseeing selection, design, implementation, operation, and maintenance of GRC
technology for IT risk management activities.