Negotiable
Undetermined
Undetermined
England, United Kingdom
Summary: The GRC Lead & Business Analyst is tasked with overseeing the Governance, Risk, and Compliance (GRC) framework while performing business analysis to improve risk management and regulatory compliance. This role involves risk assessment, compliance audits, and collaboration with various departments to implement best practices. The position requires a strategic approach to align GRC initiatives with business objectives and enhance operational efficiency. The GRC Lead will also drive projects related to governance and assurance across the organization.
Key Responsibilities:
- Develop, implement, and maintain GRC policies, frameworks, and procedures aligned with industry standards and regulatory requirements.
- Conduct workshops to gather requirements for risk assessments and security reviews.
- Maintain a risk register and track risk management initiatives.
- Lead third-party/vendor risk assessments and ensure supplier security and compliance.
- Manage compliance audits and coordinate with internal/external auditors.
- Conduct compliance monitoring and provide periodic reports on adherence to policies.
- Gather and analyze business requirements for GRC initiatives.
- Identify gaps in current GRC processes and recommend improvements.
- Plan, coordinate, and lead internal and external compliance audits.
- Serve as a liaison between business units, IT, legal, and compliance teams.
Key Skills:
- Strong knowledge of GRC frameworks and regulatory requirements (ISO 27001, NIST, SOC 2, GDPR, HIPAA, PCI DSS).
- Experience in conducting compliance audits and risk assessments.
- Proficiency in business analysis and process optimization.
- Ability to develop and implement assurance programs.
- Excellent communication and stakeholder management skills.
- Experience with GRC tools and software solutions.
- Strong analytical and problem-solving skills.
Salary (Rate): undetermined
City: undetermined
Country: United Kingdom
Working Arrangements: undetermined
IR35 Status: undetermined
Seniority Level: undetermined
Industry: Other