Job Description:
This is a 5 - month contract (renewable) with our client in the Fintech industry
We are seeking an experienced IT Governance, Risk, and Compliance (GRC) Specialist to lead third-party security risk evaluations, conduct impact assessments, and safeguard our organizational risk posture. Working in a hybrid setup, you will evaluate external vendor risks, ensure alignment with global compliance frameworks, and present actionable risk intelligence directly to senior leadership.
Key Responsibilities
- Third-Party Risk Management: Identify, assess, and mitigate security risks introduced by external vendors, suppliers, and third-party service providers.
- Risk Assessments & Audits: Conduct comprehensive Risk Impact Assessments, vendor due diligence, third-party audits, and contract reviews for security compliance.
- Governance Framework Alignment: Ensure third-party ecosystem compliance against leading frameworks (NIST, ISO 27001, PCI-DSS).
- Executive Advisory: Articulate complex security risks, audit findings, and remediation plans clearly to senior leadership and key stakeholders.
Minimum Requirements
- Experience: 7–10 years of dedicated GRC experience with a proven track record of conducting formal Risk Impact Assessments and vendor due diligence.
- Education: 3-Year IT-related Degree (NQF Level 7).
- Required Certifications: Must hold one or more of the following: CISA, CISM, or CISSP.
- Framework Mastery: Deep, practical knowledge of NIST, ISO, and PCI-DSS standards.