IT GRC Specialist
Company not specified · Gulberg, Lahore, Pakistan
About The Role
Sukuk Technologies is looking for an IT Governance, Risk & Compliance (IT GRC) Specialist with around 03-05 years of relevant experience. Key Responsibilities Implement, and continuously improve the IT Governance Framework , Establish and maintain the IT Risk Management Framework and IT Risk Register ; identify, assess, monitor, and report technology risks across applications, infrastructure, cloud, databases, third parties, availability, capacity, and technology lifecycle. Develop, review, and maintain IT policies, standards, SOPs, and controls covering areas such as change/release management, incident/problem management, SDLC, access governance, backup and recovery, asset management, vendor management, and IT operations. Establish and assess IT General Controls (ITGC) , identify control gaps, coordinate remediation with IT teams, maintain supporting evidence, and ensure appropriate segregation of duties. Coordinate internal and external IT audits , including evidence collection, audit readiness, management responses, tracking of findings, remediation actions, ownership, and closure deadlines. Govern and monitor IT Service Management (ITSM) processes based on ITIL/ISO 20000 principles, including incident, problem, change, service request, SLA, capacity, availability, and continual service improvement. Oversee governance of third-party technology vendors, business continuity and disaster recovery. Develop and report IT governance KPIs/KRIs and management dashboards covering technology risks, audit findings, controls, SLA performance, system availability, major incidents, changes, vendor performance, and BCP/DR readiness to the CTO and relevant governance committees. Qualifications & Preferred Certifications Bachelor’s degree in Information Technology, Computer Science, Information Systems, or a related discipline, with 3–5 years of relevant experience in IT Governance, IT Risk, IT Audit, IT Controls, or IT Service Management . Preferred certifications knowledge: SAMA , ISO/IEC 38500, and ISO/IEC 20000 . Role Focus: This is an IT Governance, Risk & Compliance role, not a Cybersecurity GRC role . Cybersecurity-specific activities such as SOC operations, vulnerability management, penetration testing, SIEM, security architecture, threat management, and ownership of cybersecurity controls remain with the Cybersecurity function. What we offer: Annual Increment Annual Performance Bonus Provident Fund Medical OPD/IPD/Maternity Social Insurance Paid Leaves Leave Encashment Paid Certifications Engagement Activities Reward & Recognition Corporate Gifts Annual Tour Team Hangouts Collaborative & Fostering Culture
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
