IT GRC Manager & Change Management Secretary
الوصف الوظيفي
About the Role
As an integral member of our dynamic and forward-thinking team, you will play a pivotal role in shaping the governance, risk, and compliance (GRC) framework while ensuring seamless change management processes across our global operations. This position offers a unique opportunity to contribute to our mission of leveraging cutting-edge technology to drive sustainability and enhance the well-being of individuals and organizations. With a presence in over five countries and a rapidly expanding team, we are committed to fostering innovation, collaboration, and excellence in every aspect of our work.
Key Responsibilities
Governance, Risk, and Compliance (GRC) Management
In this role, you will be responsible for developing, implementing, and maintaining robust IT governance, risk, and compliance frameworks that align with industry best practices and regulatory requirements. Your duties will include:
- Procedure Development & Implementation: Drafting, updating, and maintaining technical Standard Operating Procedures (SOPs), IT policies, and data governance standards to ensure alignment with Service Level Agreements (SLAs) and organizational objectives.
- Compliance Mapping: Conducting comprehensive mapping of internal IT procedures to global compliance frameworks, including ISO 27001, SOC 2, and NIST, as well as client-specific security mandates to ensure adherence to contractual obligations.
- Team Training & Awareness: Designing and delivering training programs to educate engineering, helpdesk, and operations teams on new compliance protocols, ensuring a consistent understanding and application of policies across all departments.
- Compliance Monitoring & Enforcement: Establishing and overseeing continuous audit mechanisms to verify that managed services teams adhere to approved procedures and regulatory standards.
- Gap Analysis & Remediation: Performing regular gap analyses on critical IT controls, such as access management, patch management, and backup systems, to identify vulnerabilities and recommend corrective actions. Tracking remediation plans and reporting progress to the Service Manager to ensure timely resolution of compliance issues.
Change Management Secretariat
In addition to your GRC responsibilities, you will serve as the Change Management Secretary, playing a crucial role in overseeing and facilitating the Change Advisory Board (CAB) process. Your duties will include:
- CAB Administration: Scheduling and managing CAB meetings, preparing agendas, and documenting outcomes to ensure structured and efficient decision-making processes.
- Change Request Review: Evaluating change requests for completeness, including documentation, client impact assessments, and rollback plans, to mitigate risks associated with production deployments.
- Change Ledger Maintenance: Maintaining a comprehensive master IT Change Ledger to ensure full auditability and traceability of all production changes, facilitating transparency and accountability.
- Policy Enforcement: Enforcing change management policies and escalating unauthorized or emergency updates to the Service Manager for immediate review and approval.
Qualifications & Skills
Professional Experience
- Minimum of 3 to 5 years of hands-on experience in IT Governance, Risk, and Compliance (GRC), IT audit, or IT change management, with a preference for candidates who have worked in Managed Service Provider (MSP) or client-facing environments.
- Practical familiarity with industry-recognized compliance frameworks, including ISO 27001, SOC 2, NIST, or ITIL, and the ability to apply these standards to real-world scenarios.
- Proficiency in using IT Service Management (ITSM) tools such as SMAX, ServiceNow, or Jira to streamline change management processes and compliance tracking.
Education & Certifications
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Business Administration, or a related field.
- Preferred Certifications: ITIL Foundation or Practitioner (highly preferred), along with certifications such as CISA (Certified Information Systems Auditor) or CRISC (Certified in Risk and Information Systems Control).
Why Join Our Team?
We offer a compelling and rewarding career opportunity in a collaborative and innovative environment. As part of our team, you will benefit from:
- A competitive salary package commensurate with your experience and expertise.
- Flexible working hours to support a healthy work-life balance.
- Access to ongoing training and development programs designed to enhance both your technical and soft skills.
- Comprehensive programs focused on personal and professional growth, ensuring continuous learning and career advancement.
- A young, dynamic, and inclusive workplace culture that fosters creativity, teamwork, and mutual respect.
- Opportunities to work alongside a specialized and highly skilled team dedicated to driving excellence in IT governance, risk management, and change management.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.