Senior GRC Specialist
Listed on 2026-08-24
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant, IT Business Analyst
Job Description
The GRC (Governance, Risk, and Compliance) Specialist is responsible for overseeing UAEU’s information security governance, risk management, and compliance activities. Acting as a key enabler for the Information Security Manager, this role ensures adherence to regulatory requirements, institutional policies, and international standards, while supporting risk assessment, mitigation planning, and audit readiness. The position involves identifying, analyzing, and reporting on compliance gaps, coordinating internal and external audits, and providing actionable recommendations to improve the University’s risk posture.
The role requires in-depth knowledge of regulatory frameworks, risk management methodologies, and best compliance practices, with a focus on embedding governance into IT and business processes, maintaining operational transparency, and continuously enhancing UAEU’s cybersecurity and compliance posture.
- Support the Information Security Manager in implementing and maintaining UAEU’s GRC framework aligned with ISO/IEC 27001:2022, UAE IA Standards, and applicable government regulations.
- Develop, review, and update information security, governance, and compliance policies, standards, procedures, and guidelines.
- Conduct information security, IT, and operational risk assessments and maintain the risk register.
- Monitor compliance with internal policies, UAE cybersecurity regulations, UAE Data Protection Law, and international standards.
- Coordinate and support internal and external audits, ensuring evidence and documentation meet regulatory and standard requirements.
- Track and follow up on audit findings, risk mitigation plans, and corrective actions to ensure timely closure.
- Conduct third-party and vendor risk assessments, review contracts, and monitor ongoing compliance.
- Provide actionable recommendations to management on risk treatment, compliance gaps, and governance improvements.
- Facilitate GRC awareness, education, and training programs for staff and stakeholders.
- Conduct control gap assessments and recommend practical remediation plans
- Prepare periodic compliance, risk, and governance reports for the Information Security Manager, senior management, and regulatory bodies.
- Collaborate with IT, security, and business units to embed governance, risk management, and compliance practices into processes.
- Perform continuous monitoring of regulatory and standards changes to update policies and processes accordingly.
- Ensure that UAEU’s operations maintain alignment with legal, contractual, and regulatory requirements.
- Promote continuous improvement of UAEU’s governance, risk management, and compliance posture.
- Perform any additional duties or responsibilities related to GRC as assigned by the Information Security Manager or management.
The GRC (Governance, Risk, and Compliance) Specialist is responsible for overseeing UAEU’s information security governance, risk management, and compliance activities. Acting as a key enabler for the Information Security Manager, this role ensures adherence to regulatory requirements, institutional policies, and international standards, while supporting risk assessment, mitigation planning, and audit readiness. The position involves identifying, analyzing, and reporting on compliance gaps, coordinating internal and external audits, and providing actionable recommendations to improve the University’s risk posture.
The role requires in-depth knowledge of regulatory frameworks, risk management methodologies, and best compliance practices, with a focus on embedding governance into IT and business processes, maintaining operational transparency, and continuously enhancing UAEU’s cybersecurity and compliance posture.
- Support the Information Security Manager in implementing and maintaining UAEU’s GRC framework aligned with ISO/IEC 27001:2022, UAE IA Standards, and applicable government regulations.
- Develop, review, and update information security, governance, and compliance policies, standards, procedures, and guidelines.
- Conduct information security, IT, and operational risk assessments and maintain the risk register.
- Monitor compliance with internal…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).