Jr Cybersecurity GRC Engineer

  • Fixed-term contract
  • Full-time
  • Less than 2 years of experience (Entry level)
  • Bachelor degree
  • Cyber Security Manager/Expert

Mission

JOB PURPOSE: 

The Jr Cybersecurity GRC Engineer supports the Governance, Risk, and Compliance (GRC) function by assisting in the implementation and maintenance of essential security policies and compliance activities. This role bridges the gap between technical operations and regulatory standards, ensuring the organization’s cybersecurity posture remains robust under the guidance of the GRC team.

Profile

RESPONSIBILITIES/DUTIES 

Governance, Policy & Compliance

Support the development, review, and periodic maintenance of information security policies, standards, and internal procedures.

Facilitate the communication of security policies across departments to ensure workforce alignment and organizational adherence.

Assist in the collection, organization, and preservation of compliance evidence required for both internal and external audits.

Contribute to the tracking of audit findings, helping to coordinate the timely remediation of identified gaps.

Risk Management & Assessment

Participate in the identification, assessment, and formal documentation of information security risks throughout the infrastructure.

Maintain updated risk registers, ensuring all mitigation plans are documented and tracked for stakeholder review.

Monitor the execution of risk treatment actions, providing regular status updates to the GRC Engineer.

Conduct due diligence support for third-party and vendor risk assessments to ensure alignment with security requirements.

Control Monitoring & Reporting

Evaluate the operational effectiveness of security controls to identify potential vulnerabilities or performance gaps.

Prepare periodic reports, dashboards, and executive summaries regarding GRC activities and compliance status.

Document GRC workflows meticulously to ensure high-quality, audit-ready records for all security activities.

Recommend incremental improvements to existing GRC processes, tools, and methodologies to enhance operational efficiency.

Security Operations Governance & Compliance Support

Support alignment of Security operations with security policies, standards, and regulatory requirements.

Assist in maintaining Security procedures and playbooks (e.g., logging, detection, incident response).

Support review of detection use cases and monitoring coverage from a compliance perspective.

Assist in ensuring logging and monitoring controls meet audit requirements.

Safety Responsibilities:

Promote a positive safety culture within the workplace and attend any safety-related meetings or briefings as required within the job role.

Comply with the requirements of RDMC RQHSE Policy and Safety Management System.

Be mindful that Safety, Security, and Environmental protection are everyone’s responsibility. All staff members are accountable for reporting and intervening in any Safety, Security, or Environmental violations.

ESSENTIAL QUALIFICATIONS, KNOWLEDGE & EXPERIENCE

QUALIFICATIONS: 

Bachelor’s degree in Information Security, Computer Science, IT, or a related field.

CompTIA Security+, ISC2 Certified in Cybersecurity, ISO 27001 Foundation, or OCEG (GRCP/GRCA) is an advantage.

KNOWLEDGE: 

Foundational understanding of cybersecurity standards (e.g., ISO 27001, NIST, IEC 62443, GDPR).

Knowledge of risk management concepts and the information security lifecycle.

Familiarity with IT infrastructure, network security concepts, and common enterprise audit processes.

Advanced proficiency in Microsoft Office 365 (Excel, PowerPoint, Word) and basic experience with GRC/Audit management software.

EXPERIENCE: 

0-3 years of progressive experience in IT, Information Security, or cybersecurity-related roles.

DESIRED BEHAVIORS & EXPERIENCES

Possesses a strong aptitude for digging into granular data to identify the underlying causes of security indicators.

Maintains a high level of precision in documentation, ensuring that no regulatory or policy detail is overlooked.

Exhibits a proactive interest in emerging cybersecurity threats and modern regulatory landscapes (e.g., AI-driven security).

Capable of bridging technical and non-technical departments to foster a security-conscious workplace culture.

Security-first mindset with a high sense of integrity, responsibility, and ethical conduct.

Resilient and organized while handling workload pressure, capable of balancing multiple tasks while meeting deadlines.