Associate GRC Consultant
This role is ideal for fresh graduates looking to build a foundation in cybersecurity.
Job Description:
The Associate Consultant supports the delivery of Governance, Risk, and Compliance (GRC) services, assisting senior team members in executing client projects.
Responsibilities:
-
Assist in gathering and analyzing data for GRC assessments.
-
Support the preparation of assessment reports, governance documentation, and client presentations.
-
Perform Assessments for cybersecurity regulations, frameworks (e.g., ISO 27001, NCA-Frameworks (ECC, CSCC, DCC), and best practices.
-
Collaborate with senior consultants on the development and implementation of policies, procedures, frameworks, etc.
-
Develop and implement policies, procedures, and controls that ensure compliance with laws, regulations, and industry standards.
-
Participate in client workshops and project meetings.
-
Liaise with cross-functional teams (GRC, IT, legal, audit, operations) to support secure and compliant business operations.
-
Evaluate third-party vendors for compliance with security standards and risk management requirements.
-
Provide input into enterprise risk management processes from a cybersecurity perspective.
-
Track and report key GRC metrics and issues to stakeholders and executive leadership.
Minimum Requirements:
-
Bachelor's degree in Cybersecurity, Information Technology, or related fields.
-
Basic understanding of cybersecurity concepts, risk management, and compliance standards.
-
Optional: Certifications such as CompTIA Security+, ISO 27001 Foundation, SSCP & ITIL or equivalent are a plus.
Competencies:
-
Strong analytical and problem-solving skills.
-
Willingness to learn and adapt in a dynamic environment.
-
Effective communication skills (verbal and written).
-
Attention to detail in documentation and reporting.
-
Team-oriented mindset with a proactive attitude.