Sr. IT GRC Analyst
Avrioc Technologies · Abu Dhabi, Abu Dhabi Emirate, United Arab Emirates
Apply & track with Apply EdgeAvrioc and its associated entities operate across fintech, digital platforms, gaming, fitness, communication and related technology-enabled businesses. The group is committed to maintaining strong governance, risk management, regulatory compliance, information security and operational resilience across its products and services.The Sr. IT GRC Analyst will support the implementation and ongoing management of the technology governance, risk and compliance framework across Avrioc and its associated entities, including regulated and non-regulated business units.The role will focus on technology risk management, regulatory compliance, audit coordination, certification maintenance, third-party risk management, IT control reviews, evidence management and GRC reporting. The role requires close coordination with Technology, Cybersecurity, DevOps, Product, Compliance, Legal, Privacy, Finance, Operations and business teams to ensure that technology and business processes remain aligned with internal policies, applicable regulatory requirements and industry standards.Key ResponsibilitiesMaintain and update technology risk registers across Avrioc and its associated entities, including risk identification, assessment, ownership, treatment actions, residual risk and closure tracking.Support Risk and Control Self-Assessment activities and ensure timely reporting of control gaps, risk exposures and remediation status.Monitor technology risk indicators and provide periodic updates to GRC management and relevant stakeholders.Support ongoing compliance with applicable standards and frameworks, including PCI DSS, ISO 27001, ISO 20000, UAE IA, NIST, COBIT, ITIL and other relevant requirements.Support compliance with CBUAE and other applicable regulatory requirements for regulated entities and products, including technology risk, outsourcing, cybersecurity, operational resilience, business continuity and incident-reporting requirements.Coordinate internal audits, external audits, certification audits, customer audits, regulatory reviews and evidence-collection activities.Track audit findings, regulatory observations, risk-treatment actions, control gaps, policy exceptions and management action plans through closure.Maintain accurate GRC documentation, including policies, procedures, risk assessments, audit evidence, control trackers, compliance reports and management updates.Track regulatory and framework updates, assess applicability across relevant entities and support impact assessments.Work with IT, DevOps and Cybersecurity teams to review IT general controls, access controls, privileged access, change management, backup, logging, monitoring, vulnerability management and incident-management controls.Support third-party risk management, including vendor due diligence, risk assessment, contract-control review, ongoing monitoring, evidence tracking and renewal reviews.Support cloud, application, infrastructure, data, AI and integration risk assessments across group products and platforms.Support implementation and usage of GRC tools such as Vanta, Jira and other evidence-management or compliance automation platforms.Assist in preparing dashboards, reports and updates for management, auditors, regulators and internal stakeholders.Support employee awareness activities related to GRC, information security, risk management and compliance.Promote a culture of accountability, timely remediation, evidence-based control ownership and continuous improvement.Skills and AttributesGood understanding of technology risk management, IT governance, information security, compliance and audit practices.Knowledge of PCI DSS, ISO 27001, ISO 20000, NIST, COBIT, ITIL, UAE IA and CBUAE technology risk expectations.Understanding of IT general controls, access management, change management, incident management, vulnerability management, cloud governance and third-party risk management.Ability to support GRC activities across multiple entities, products and technology environments.Strong documentation, reporting, coordination and stakeholder-management skills.Ability to coordinate evidence collection and work with cross-functional technical and business teams.Ability to track multiple priorities, follow up with action owners and meet committed deadlines.Good analytical skills with attention to detail.Ability to work independently in a fast-paced and evolving environment.Commitment to maintaining confidentiality, integrity and availability of information.QualificationsBachelor’s degree in Information Technology, Computer Science, Information Security, Risk Management or a related field.Minimum 7 years of experience in IT GRC, technology risk, information security, audit, compliance or related functions.Experience in financial services, fintech, payments, digital platforms or regulated technology environments is preferred.Professional certifications such as CISA, CISSP, CISM, CRISC, ISO 27001 LA/LI, PCI DSS, COBIT or ITIL are preferred.Experience with GRC tools, audit-management platforms, Jira, Vanta or similar compliance automation tools will be an advantage.