GRC Specialist at Optasia enhancing compliance and security protocols for fintech platform operations across departments. Supporting audits, risk assessments, and security awareness training.
Responsibilities
Maintain and enhance the company’s Information Security Management System (ISMS) aligned to ISO 27001:2022.
Support the planning, execution, and maintenance of SOC 2 Type II controls and evidence collection.
Prepare and maintain compliance documentation (policies, procedures, guidelines, control matrices, risk registers).
Coordinate and track compliance across departments, ensuring timely closure of audit findings and corrective actions.
Act as the point of contact for internal and external audits (ISO 27001, SOC 2, customer and partner audits).
Support and manage Customer Audit activities — including responding to security and compliance questionnaires, coordinating input from multiple departments, collecting, and validating evidence, and ensuring timely and accurate responses.
Prepare structured evidence packages, liaise with control owners, and manage communications with auditors and customers.
Conduct internal control reviews and readiness assessments ahead of certification or customer audits.
Participate in regular risk assessments and reviews of security controls.
Assist in maintaining the risk register, monitoring remediation plans, and validating control effectiveness.
Coordinate and deliver security awareness initiatives for employees (e-learning, workshops, newsletters).
Promote a risk-aware culture and support departmental champions to strengthen overall security posture.
Monitor changes in applicable regulations, standards, and best practices (ISO, SOC, GDPR, etc.) and recommend updates.
Support automation and digitalization of compliance activities through GRC platforms and dashboards.
Contribute to incident and issue management reviews to ensure lessons learned are captured and controls improved.
Requirements
At least 3 years of experience in GRC, Information Security, or Audit roles.
Solid understanding of ISO 27001, SOC 2, and general IT security control frameworks (NIST, COBIT, etc.).
Strong organizational skills and ability to coordinate across departments.
Excellent written and verbal communication in English.
Experience supporting or participating in audits and compliance assessments.
Strong customer-facing and communication skills, with the ability to interact confidently with clients, auditors, and internal stakeholders.
Conceptual understanding of key security technologies such as EDR, UTM/Firewall, SIEM, and Vulnerability Management systems to evaluate related controls and compliance evidence.
Benefits
💸 Competitive remuneration package
🏝 Extra day off on your birthday
💰 Performance-based bonus scheme
👩🏽⚕️ Comprehensive private healthcare insurance
📲 💻 All the tech gear you need to work smart
🎌 Be a part of a multicultural working environment
🎯 Meet a very unique and promising business and industry
🌌 🌠 Gain insights for tomorrow market’s foreground
🎓 A solid career path within our working family is ready for you
📚 Continuous training and access to online training platforms
🥳 CSR activities and festive events within any possible occasion
🍜 Enjoy comfortable open space restaurant with varied meal options every day
🎾 🧘♀️ Wellbeing activities access such as free on-site yoga classes, plus available squash court on our premises
Manager in Individual Insurance Canada to oversee business risk and regulatory change operations. Responsible for compliance integration and project management with cross - functional teams.
Compliance Assistant Manager at Western Alliance Bank handling regulatory compliance oversight and guidance. Leading compliance assessments, collaborating with stakeholders, and supporting compliance programs.
Global Regulatory Compliance Intern assisting with documentation for country registration and tracking international market entry processes. Engaging in regulatory compliance tasks with a focus on various global standards and practices.
Independent contractor analyzing whistleblower reports and compliance matters in the energy sector. Relieving operational workload for General Counsel in sensitive investigations.
Compliance Manager ensuring AML, CTF, and regulatory compliance at YouTrip’s fintech operations. Collaborating with stakeholders while managing compliance frameworks and policies for high growth.
Regulatory Lead managing data requests and shaping regulatory strategy for VodafoneThree. Collaborating across teams to ensure accurate and compelling regulatory responses and representation.
Detail - oriented professional supporting SOX compliance and access governance across the Vodafone Cloud & Infrastructure landscape. Partnering with stakeholders to ensure robust governance and smooth audit cycles.
Office Administrator supporting Global Financial Crime team with administrative tasks and project management. Ensuring proper communication, coordination, and support for multiple initiatives.
GRA CMC Lead driving regulatory strategies for pharmaceutical and vaccine products. Collaborating with cross - functional teams and directly influencing drug approvals through negotiations.
Manager of Regulatory Affairs driving regulatory strategies for product launches and compliance. Collaborating with cross - functional teams to enhance product development and advertising campaigns.