Job Description
We are seeking an experienced Senior GRC Specialist to lead and strengthen the Bank's Governance, Risk, and Compliance framework. The successful candidate will be responsible for ensuring compliance with regulatory requirements, industry standards, and internal governance policies while driving enterprise risk management initiatives. The role requires close collaboration with business, IT, Information Security, Internal Audit, Compliance, and regulatory authorities to maintain a strong control environment.
Key Responsibilities
- Develop, implement, and maintain Governance, Risk & Compliance (GRC) policies, standards, frameworks, and procedures.
- Lead enterprise-wide risk assessments and maintain the organization's risk register.
- Identify, assess, monitor, and report operational, technology, cybersecurity, and compliance risks.
- Ensure compliance with banking regulations, regulatory requirements, and internal governance policies.
- Perform control assessments and gap analyses to evaluate the effectiveness of security and compliance controls.
- Coordinate internal audits, external audits, and regulatory examinations, ensuring timely remediation of findings.
- Track audit observations, compliance issues, and risk mitigation plans through closure.
- Prepare governance reports, compliance dashboards, and executive-level risk reports.
- Ensure compliance with PCI DSS (Payment Card Industry Data Security Standard) requirements and support PCI DSS assessments, audits, evidence collection, and remediation activities.
- Collaborate with business and IT teams to implement and maintain PCI DSS security controls across payment environments.
- Support compliance initiatives related to ISO 27001, NIST CSF, COBIT, and other applicable regulatory and security frameworks.
- Conduct third-party and vendor risk assessments.
- Review new projects, systems, and technology initiatives from governance, risk, and compliance perspectives.
- Promote risk awareness by delivering GRC and compliance training across the organization.
- Stay current with emerging regulatory requirements and recommend improvements to governance and compliance processes.
Requirements
- Bachelor's degree in Information Technology, Information Security, Computer Science, Cybersecurity, Risk Management, Business Administration, or a related field.
- 9+ years of experience in Governance, Risk & Compliance within the banking or financial services industry.
- Strong knowledge of banking regulations and regulatory compliance requirements.
- Hands-on experience with Enterprise Risk Management (ERM), IT Risk, Operational Risk, and Compliance Management.
- Experience managing internal and external audits and regulatory inspections.
- Experience with GRC platforms such as RSA Archer, ServiceNow GRC, MetricStream, or equivalent.
- Strong understanding of Information Security Governance and internal control frameworks.
- Experience with PCI DSS compliance programs, assessments, remediation, and audit coordination.
- Excellent analytical, documentation, communication, and stakeholder management skills.