Senior GRC (governance | risk & compliance) specialist
Closing on: Dec 25, 2026
We invite applications from suitably qualified individuals for the post of Senior GRC (governance, risk & compliance) specialist. The selected candidate will report to the Head of cyber security operations.
Responsibilities
- Delivering GRC consultancy services including data classification consultation, policy development, gap analysis, risk assessments, privacy assessments, ISO 27001 implementation, PDPA consultation, and BCMS implementation.
- Supporting internal compliance initiatives by developing, maintaining, and reviewing organisational policies, procedures, and controls in line with relevant standards and regulatory requirements.
- Collaborating with cross-functional teams to integrate GRC practices into broader business and IT processes, enhancing overall governance and security posture.
- Staying informed about evolving regulations, compliance trends, and cybersecurity threats – providing strategic recommendations for continuous improvement.
- Mentoring and guiding junior GRC analysts in their professional development, fostering a culture of knowledge sharing and continuous learning within the team.
Requirements
- 3-7 years of experience in a GRC role or similar, with a focus on information security, risk management, and compliance. In depth understanding of GRC frameworks such as ISO 27001, ISO 27701, PDPA, NIST, and relevant industry standards.
- Proven experience in conducting risk assessments, internal audits, and compliance reviews, with a track record of leading successful initiatives.
- Extensive knowledge of data protection laws such as GDPR, with hands-on experience ensuring regulatory compliance.
- Strong understanding of security controls and risk mitigation strategies, with the ability to develop practical solutions.
- Excellent analytical, organisational, and communication skills, with the ability to convey complex concepts to a variety of audience.
- Proven ability to work independently and lead cross-functional teams effectively.
- Professional certifications such as CISA, CISM, CRISC, ISO 27001 lead implementer/auditor, or equivalent are highly desirable.
- Bachelor’s degree in information security, IT, or a related field; advanced degrees are a plus.
Benefits
- Competitive compensation: Attractive salary and a comprehensive benefits package.
- Cutting-edge exposure: Exposure to cutting-edge technologies and high-impact projects.
- Inclusive culture: A dynamic and inclusive environment where your ideas and contributions are genuinely valued.
- Career advancement: Opportunities for growth and professional development in a rapidly evolving industry.
About the company
Connex Information Technologies (Pvt) Ltd, a leading technology services and solutions distributor, dedicated to helping organizations navigate complex and evolving landscapes.
When applying
If you’re up for the challenge, please send your resume to [email protected] or click on the advert to apply. Please state the position you’re interested in as in the subject line of your email.
Company: Connex Information Technologies Pte Ltd
Company email: [email protected]
Job Location: Colombo
Job Category: Cybersecurity / Information Security
Job Type: Full Time
