Skip to content

GRC Specialist

  • On-site
    • Tehran, Tehrān, Iran, Islamic Republic of
  • Tech

Job description

As an Information Security GRC Specialist, you will be responsible for designing, implementing, and continuously improving the organization's information security governance, risk management, compliance across Snapp Cab and other ventures. You will work closely with Security, Engineering, Product, Legal, HR, and Business teams to ensure that information assets, business services, and AI-powered solutions are secure, compliant, and aligned with regulatory requirements and international standards.

  • Design, implement, and continuously improve information security governance frameworks aligned with ISO 27001, NIST CSF, and organizational requirements.

  • Conduct information security risk assessments and manage risk treatment plans.

  • Plan, execute, and coordinate internal, external, and compliance audits.

  • Develop and maintain security policies, standards, procedures, and governance documentation.

  • Govern Identity & Access Management (IAM), including periodic access reviews and Joiner/Mover/Leaver processes.

  • Perform third-party security and compliance assessments.

  • Support the implementation of AI Governance frameworks and conduct AI risk assessments for AI-enabled solutions.

  • Monitor compliance with regulatory, contractual, and industry security requirements.

  • Prepare executive dashboards and reports covering security posture, risk, compliance, and governance metrics.

  • Collaborate with Security, Engineering, Legal, HR, and Business teams to strengthen information security and AI governance across the organization.

Job requirements

  • Bachelor's degree or higher in Cybersecurity, Computer Science, Information Technology, or a related field.

  • Minimum 5 years of experience in Governance, Risk, and Compliance (GRC), risk management, or security compliance roles.

  • Strong expertise in regulatory requirements and frameworks such as NIST CSF, ISO 27001, ISO 42001, Cyber-police requirements, and industry audit standards.

  • In-depth understanding and hands-on experience with leading security frameworks, including NIST Cybersecurity Framework, NIST AI Risk Management Framework, ISO 27001, and CIS Controls.

  • Relevant certifications (CISA, CISM, ISO 27001 Lead Implementer) are highly preferred.

  • Strong problem-solving skills, attention to detail, and ability to manage multiple initiatives simultaneously.

  • Excellent verbal and written communication skills, capable of influencing both technical and non-technical stakeholders.

  • Experience creating dashboards and visual reports using Power BI or similar business intelligence tools.

  • Ability to write SQL queries for auditing, reporting, and investigation purposes.

  • Have experience working with SIEM platforms (e.g., Splunk, ELK, or similar) for event monitoring, log analysis, and compliance reporting. 

or