TU PRÓXIMO CAPÍTULO
GRC Consultant
Sobre el puesto
• Lead strategic governance, compliance, risk management, audit, and resilience initiatives across Pismo's global operations
• Develop, maintain, and continuously improve governance frameworks, policies, standards, and procedures
• Support compliance with ISO 27001, SOC 1, SOC 2, PCI DSS, PCI PIN Security, data localisation requirements, and other applicable frameworks
• Conduct compliance assessments, gap analyses, and maturity reviews
• Coordinate internal and external audits and support remediation of findings
• Facilitate enterprise, operational, technology, and cybersecurity risk assessments
• Maintain risk registers and support risk treatment, monitoring, and reporting
• Collaborate with stakeholders to implement mitigation strategies and monitor risk exposure
• Prepare executive-level risk reporting and dashboards
• Support security due diligence, client assessments, and assurance requests
• Coordinate responses to regulatory inquiries and examinations
• Communicate Pismo's security, compliance, and resilience capabilities to clients and external stakeholders
• Prepare reports, executive summaries, and evidence packages for customer and regulatory reviews
• Drive continuous improvement through automation, AI-enabled processes, and operational efficiency programmes
• Support new compliance and security initiatives resulting from regulatory or business changes
• Contribute to security awareness and compliance maturity programmes
• Mentor junior GRC professionals and contribute to organisational knowledge sharing
• 5 years relevant work experience with a Bachelor's degree, or 2 years relevant work experience with an Advanced degree (e.g. Masters, MBA, JD, MD), or 0 years relevant work experience with a PhD; OR 8 years relevant work experience
• Preferred Bachelor's degree in Information Security, Cybersecurity, Risk Management, Information Technology, Law, Business Administration, or a related field
• Minimum 5 years of experience in Governance, Risk & Compliance, Information Security, Risk Management, Internal Audit, or related consulting roles
• Experience supporting audits, regulatory reviews, or certification programmes
• Strong understanding of risk management methodologies and information security governance principles
• Experience interacting with senior stakeholders and executive leadership
• Strong analytical, communication, presentation, and report-writing skills
• Professional certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor or Lead Implementer, or CGRC
• Experience in banking, payments, fintech, or other highly regulated industries
• Familiarity with cloud-native environments and modern software development practices
• Knowledge of privacy and data protection regulations
• Fully remote work arrangement
• Opportunity to create impact at scale
• Skills growth and professional development through meaningful challenges
• Scheduled-notice Visa office attendance may be required for remote positions