GRC Consultant

2 weeks ago


Lahore, Punjab, Pakistan Ebryx LLC Full time 600,000 - 1,200,000 per year

Job Description – Associate GRC (Governance, Risk & Compliance) Consultant

Position Summary

The Associate GRC Consultant will support clients and internal teams in the implementation, assessment, and improvement of Governance, Risk, and Compliance programs. This entry- to mid-level role focuses on assisting in risk assessments, compliance audits, policy development, and control evaluations, while gaining exposure to leading frameworks and regulatory requirements. The candidate must have working knowledge of ISO 27001, SOC-2, PCI-DSS and other standards and regulatory frameworks.

Key Responsibilities


• Governance & Policy

o Assist in the development, review, and maintenance of IT and security policies, standards, and procedures.

o Support alignment of organizational policies with industry frameworks (ISO 27001, NIST, SOC-2, etc.).


• Risk Management

o Participate in risk assessments to identify, evaluate, and document risks across IT and business processes. o Assist in the design and monitoring of risk treatment and mitigation plans.

o Support third-party/vendor risk assessment activities.



Compliance

o Help track compliance with regulatory requirements (e.g., GDPR, HIPAA, PCI DSS, CCPA, SOC 2).

o Assist in preparing compliance reports, audit documentation, and evidence gathering.

o Collaborate with internal and client stakeholders during external or internal audits.


• Controls & Assurance

o Support assessment of IT general controls (ITGCs), application controls, and operational controls.

o Contribute to testing control effectiveness and documenting findings.

o Help with continuous monitoring activities and reporting.


• Client Engagement & Documentation

o Prepare deliverables such as risk registers, audit reports, policy drafts, and presentations.

o Participate in client workshops, interviews, and walkthroughs.

o Maintain accurate project documentation and follow up on action items.

Qualifications



Education:
Bachelor's degree in information security, Computer Science, Business, or related field.



Certifications
(Preferred / Plus): ISO 27001 Lead Implementer/Auditor, CISA, CRISC, CompTIA Security+, or working toward similar certifications.



Experience:

o 1–2 years of experience in IT audit, cybersecurity, risk management, or compliance.

o Familiarity with frameworks such as ISO 27001, NIST CSF, COBIT, or PCI DSS is a plus.



Skills:

o Strong analytical, problem-solving, and documentation skills.

o Ability to learn quickly and adapt to client needs.

o Good communication and presentation skills.

o Proficiency with MS Office; experience with GRC tools is advantageous.


  • GRC Business

    5 days ago


    Lahore, Punjab, Pakistan Liztek Full time 900,000 - 1,200,000 per year

    GRC Business & Technical Consultant – Onsite – ContractJoin our LinkedIn community:Role Summary:We are looking for a GRC Business & Technical Consultant to join our onsite team in Lahore on a contract basis. The consultant will play a pivotal role in evaluating and strengthening a newly built GRC system, ensuring that it aligns with business, compliance,...


  • Lahore, Punjab, Pakistan Ebryx LLC Full time 900,000 - 1,200,000 per year

    Job Description – Associate GRC (Governance, Risk & Compliance) ConsultantPosition SummaryThe Associate GRC Consultant will support clients and internal teams in the implementation, assessment, and improvement of Governance, Risk, and Compliance programs. This entry- to mid-level role focuses on assisting in risk assessments, compliance audits, policy...


  • Lahore, Punjab, Pakistan Liztek Full time

    GRC Technical SpecialistLocation:Onsite – Lahore, PakistanJob Type:Full-TimeJob DescriptionWe are seeking a highly skilled and technically adeptGRC Technical Specialistto join our team in Lahore. The ideal candidate will possess deep expertise inGovernance, Risk, and Compliance (GRC)frameworks, policies, processes, and tools, along with strong system,...


  • Lahore, Punjab, Pakistan Technical Full time 200,000 - 500,000 per year

    We are looking for Passionate Students and Recent Graduates for 2-Months Internship opportunity in Security Consultancy and Forensics Department. The internship provides hands-on exposure to Cybersecurity Basics, Network Security, GRC, and DFIR under the guidance of experienced professionals.


  • Lahore, Punjab, Pakistan NowVerse Full time 900,000 - 1,200,000 per year

    NowVerse is a leading IT consulting firm specializing in providing innovative and customized IT solutions to meet unique business challenges. Our team of experienced professionals delivers cutting-edge technology solutions that empower organizations to gain a competitive edge. We offer a range of services including IT consulting, project management, software...