Governance, Risk and Compliance Specialist

icon Malta
icon Legal & Corporate
JOB DESCRIPTION

Ref#8730

 

GRS Recruitment is excited to announce a fantastic opportunity for a Permanent Governance, Risk and Compliance Specialist to join a reputable legal company based in Malta. Our client is well-known for their commitment to providing exceptional legal services, and they are now seeking an experienced professional to support their Governance, Risk, and Compliance initiatives.
 
DUTIES AND RESPONSIBILITIES
 
ISO Compliance:
  • Develop, implement, and maintain ISO management systems across the relevant legal entities.
  • Ensure compliance with ISO standards (e.g., ISO 27001, ISO 9001) and relevant regulations.
  • Conduct regular audits and assessments to evaluate compliance with ISO frameworks.
  • Prepare and present ISO compliance reports to senior management and relevant committees.
Cybersecurity Compliance:
  • Develop, implement, and maintain GRC frameworks that align with cybersecurity standards and regulations (e.g., NIST, ISO 27001, GDPR).
  • Conduct regular audits and assessments to ensure compliance with cybersecurity policies and practices and provide remediation guidance.
  • Prepare and present cybersecurity compliance reports to senior management and relevant committees.
  • Stay current on best practices and technological advancements, acting as a point of reference for security assessments and regulatory compliance.
  • Contribute to the development of appropriate security KPIs, objectives, and strategies to improve the firm’s security posture and maturity. Develop reporting metrics, dashboards, and evidence artifacts to communicate with business stakeholders periodically.
Governance:
  • Establish and enforce governance frameworks and policies aligned with ISO standards.
  • Monitor compliance with internal policies and regulatory requirements.
  • Prepare and present governance reports (including compliance monitoring reports) to senior management and relevant committees and provide remediation guidance.
  • Collaborate with internal and external stakeholders to address and resolve compliance issues identified in the compliance monitoring reports.
  • Stay updated on relevant laws, regulations, and standards that impact the firm.
Risk Management:
  • Identify and assess firm related risks, including those related to information security, data privacy, and technology operations.
  • Develop and implement risk mitigation strategies and action plans to address identified vulnerabilities.
  • Monitor the effectiveness of risk management practices.
  • Maintain the firm’s risk registers.
  • Attend and contribute to internal risk committees, providing insights and recommendations.
  • Prepare and present risk reports to senior management and relevant committees and provide remediation guidance.
  • Act as the Risk Officer of any of the legal entities.
  • Assist firm members in supplier onboarding risk assessment processes.
Training and Awareness:
  • Conduct training sessions and workshops to raise awareness of ISO standards and GRC requirements across the firm.
  • Develop educational materials and resources to support ongoing learning.
  • Provide guidance on and assist firm members with GRC-related matters.
  • Support the development of a risk-aware culture within the firm.
CANDIDATE PROFILE
  • Minimum of 3-5 years of experience in risk management or IT audit, ideally in a GRC capacity or comparable experience in the industry.
  • Bachelor’s degree in Business Administration, Information Technology, Cybersecurity, Law, or a related field.
  • Strong knowledge of relevant regulatory requirements, industry standards, and best practices.
  • Solid experience in conducting risk assessments, developing controls, and monitoring effectiveness of controls.
  • Excellent analytical and problem-solving skills.
  • Strong communication and interpersonal skills.
  • Ability to work independently and as part of a team.
  • Proficiency in using GRC software and tools.
Requirements - Advantageous
  • Relevant certifications such as CISM, CRISC, CISA, CISSP, or similar.
  • Experience with the Digital Operational Resilience Act (DORA).
COMPANY BENEFITS
 
  • Competitive salary and benefits package.
  • Opportunities for professional growth and development.
  • A supportive and collaborative work environment.
  • The chance to make a meaningful impact on our firm’s success.
Due to the high volume of applications received at GRS Recruitment, only shortlisted candidates will be responded to.
 
If you meet the requirements and are ready to take the next step in your career, we encourage you to apply for this exciting opportunity!
Job Summary
  • icon
    21 February 2025
  • icon
    Permanent
  • 8730
  • sarah@grsrecruitment.com