×
Regístrese Aquí para solicitar empleo o publicarlo X

M26333 - GRC Specialist; Governance, Risk and Compliance); Locally

Trabajo disponible en: 36585, Irapuato, Guanajuato, México
Empresa: Cimmyt
Tiempo completo puesto
Publicado en 2026-09-06
Especializaciones laborales:
  • TI/Tecnología
    Seguridad de la Información, Seguridad cibernética, Analista de negocios de TI
Descripción del trabajo
Puesto: M26333 - GRC Specialist (Governance, Risk and Compliance) (Locally recruited)
Description
CIMMYT is a cutting edge, non-profit, international organization dedicated to solving tomorrow's problems today. It is entrusted with fostering improved quantity, quality, and dependability of production systems and basic cereals such as maize, wheat, triticale, sorghum, millets, and associated crops through applied agricultural science, particularly in the Global South, through building strong partnerships. This combination enhances the livelihood trajectories and resilience of millions of resource-poor farmers, while working towards a more productive, inclusive, and resilient agrifood system within planetary boundaries.
For more information, visit cimmyt.org.

The GRC Specialist will serve as the internal subject-matter expert for governance, risk, and compliance across CIMMYT's enterprise application ecosystem (Dynamics 365 F&O, HR and Customer Engagement, Power Platform, ICERTIS Contract Intelligence, and Sapience HR), responsible for operating a single cross-platform GRC framework covering access control and segregation of duties, licensing and entitlement governance, data privacy, and audit readiness, under the supervision of the ERP Program Manager and in coordination with the CIMMYT ERP team, KMIT, and control and process owners across the institution.

Own and operate the full-lifecycle Access Management procedure (request, approval, provisioning, modification, recertification, revocation), and close gaps against each platform.
Maintain the privileged access elevation model (justification, approval, duration limits, session logging, post-use review) and the required log set, retention, and monitoring per platform.
Maintain the consolidated cross-platform segregation-of-duties (SoD) conflict matrix, run riskranked assessments, agree remediation or mitigating controls with process owners, and operate recurring SoD reporting.
Periodically review all accounts (active, dormant, duplicate, generic, shared, service, external), remediate orphaned accounts, and reconcile reclaimed accounts to license entitlement.
Maintain an entitlement register per platform, reconcile licenses against actual usage and quantify the gap, assess how security role design drives license tier, and operate request, approval, and reclamation controls so reclaimed accounts convert into recovered cost.
Maintain the data inventory and processing record, define and apply retention and disposal schedules, and enable data subject request handling within statutory time frames.
Maintain and test the IT general controls (ITGC) matrix (access, change management, program development, computer operations) across all platforms; report deficiencies, require appropriate corrective actions from process and control owners, challenge inadequate or delayed remediation responses, and track remediation to closure.
Keep the evidence base continuously audit-ready, run readiness assessments before scheduled audits, act as coordination point during internal and external audit fieldwork, and track prior findings to closure.
Maintain the GRC policy and procedures set with owners and review cycles, the ERP/IT risk register on the institutional scale, and automated key risk and control indicators reporting breaches as they occur.
Assess interface controls (completeness, reconciliation, failure alerting, connector privileges) and the control environment of vendors with system or data access, including KMIT, reviewing assurance reports, contractual security, breach notification and audit rights, and relevant service levels.
Operate the exception register with expiry dates, contribute to change advisory and incident root-cause analysis, and train control owners on their obligations.
Deliver monthly progress reports and the quarterly GRC dashboard to the ERP Program Manager and governance bodies, escalating material findings directly.
Perform other related tasks within the job level as may be requested by the immediate supervisor.

Requirements
Requirements:
Bachelor's degree in Information Systems, Computer Science, or a related field.
Minimum of 5 years of experience in IT GRC or IT audit, of which at least 3 on enterprise application platforms; ITGC design, testing, and remediation experience in an audited environment.
Hands-on experience with the Dynamics 365 security model (F&O roles, duties, and privileges; CE role-based security) and practical ERP SoD design or assessment.

Experience with Power Platform governance (environments, DLP policies, Dataverse security) and license reconciliation.
Working knowledge of data protection law and of ISO 27001, NIST CSF, or COBIT.
Experience preferred; CISA, CRISC, CISM, or CIPP certification an advantage; experience with ICERTIS or a comparable CLM platform, HRIS governance, a GRC tool (Pathlock, Fastpath, SAP GRC, Service Now IRM), or in multi-jurisdiction environments an advantage.
Strong analytical skills and proficiency with reporting and dashboard tools;
Power BI or equivalent an advantage.
Full professional proficiency in…
Para ver y solicitar empleos que acepten solicitudes de su ubicación o país, toque el botón a continuación para realizar una búsqueda.
(Si este trabajo está en su jurisdicción, entonces puede estar usando un Proxy o VPN para acceder a este sitio, para seguir avanzando, debe cambiar su conectividad a otro dispositivo móvil o PC).
 
 
 
Busque más trabajos aquí:
(Ingrese pocas palabras para obtener mejores resultados)
Localización
Aumentar el radio de búsqueda (millas)
0
200
Filtros
Nivel Educativo
Experiencia mínima requerida (años)
Publicado en los últimos:
Salario