Talent Apply
Log in
All jobs
IT

GRC Analyst

IO Tech Solutions Limited
Hong Kong
On-site

About this role

Job title: GRC Analyst

Job Description We are currently looking for a GRC Analyst to join a leading organisation in Hong Kong. This role will focus on Information Security Governance, Risk and Compliance, working closely with technology and business stakeholders to identify and manage security risks and ensure compliance with relevant standards and regulatory requirements.

Key Responsibilities

  • Support Information Security Governance, Risk and Compliance (GRC) activities across the organisation.
  • Conduct IT and Information Security risk assessments, control assessments and gap analyses.
  • Support the implementation and maintenance of ISO 27001 security controls and requirements.
  • Assist in reviewing security policies, standards, procedures and control frameworks.
  • Monitor security risks, exceptions and remediation actions, ensuring timely follow-up.
  • Support internal and external audits, including audit preparation, evidence collection and remediation tracking.
  • Assess applicable regulatory and compliance requirements and support their implementation within the organisation.
  • Prepare risk, compliance and security reports for management and relevant stakeholders.
  • Work closely with IT, cybersecurity and business teams to identify control gaps and recommend appropriate improvements.
  • Support ongoing security governance initiatives and maintain relevant risk and compliance documentation.

Requirements

  • Degree in Information Security, Cybersecurity, IT, Computer Science or a related discipline.
  • Min.2 years of relevant experience in GRC, Information Security, IT Risk, Technology Risk, IT Compliance or Security Governance.
  • Candidates with 8–10+ years of relevant Information Security / GRC / IT Risk experience are also welcome to apply for senior-level opportunities.
  • Practical experience with ISO 27001 is highly preferred.
  • Experience in risk assessment, control assessment, gap analysis or security compliance.
  • Knowledge of security frameworks such as NIST CSF, ISO 27001, COBIT or CIS Controls is an advantage.
  • Experience supporting security audits, regulatory assessments or compliance reviews.
  • Strong analytical, documentation and stakeholder management skills.
  • Good command of English and Cantonese; Mandarin is an advantage.

Required Skills

  • Reports
  • Cantonese
  • Gap Analysis
  • Support
  • Information Security
  • Management Skills
  • Regulatory Requirements
  • Mandarin
  • Analysis
  • Compliance
  • Reviews
  • Risk Assessment
  • Stakeholder Management
  • Computer Science
  • Security
  • Preparation
  • Documentation
  • Maintenance
  • Business
  • English
  • Science
  • Management

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →