Назад
Company hidden
2 дня назад

Junior GRC Analyst

Формат работы
onsite
Тип работы
fulltime
Грейд
junior
Английский
b2
Страна
Taiwan
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Junior GRC Analyst (Governance, Risk, and Compliance): Developing and maintaining GRC policies, risk assessments, regulatory filings, and cybersecurity incident reporting drills for the Taiwan environment with an accent on FSC, SITCA, PDPA, and APAC financial-sector requirements. Focus on coordinating regulatory readiness, maintaining segregation of duties, supporting SecOps activities, and advising business and IT stakeholders.

Location: Taipei, Taiwan; applicants must already have the right to work in Taiwan without current or future sponsorship

Company

hirify.global's Global Technology organization supports information security, governance, risk, and compliance across Taiwan and the APAC region.

What you will do

  • Develop, implement, maintain, and improve GRC and information security policies and procedures.
  • Conduct risk assessments, monitor internal and external compliance, and support the risk management framework.
  • Coordinate FSC, SITCA, and other regulatory filings, surveys, annual training requirements, and examination-readiness activities.
  • Lead cybersecurity incident reporting drills, including scenario development, system walkthroughs, execution, and post-drill reporting.
  • Advise business and IT teams on information security and regulatory compliance while maintaining segregation of duties from Internal Audit and operational IT.
  • Maintain regulatory, audit, governance, drill, and evidence documentation and co-sign the Annual Statement on Internal Control.

Requirements

  • 3+ years of related IT experience, preferably in financial services, with relevant GRC, information security, or SecOps experience.
  • Working knowledge of GRC principles, risk assessment, policy development, control monitoring, and industry frameworks.
  • Familiarity with Taiwan FSC and SITCA information security obligations and Taiwan's Personal Data Protection Act.
  • Bachelor's degree in Information Technology, Business Administration, Risk Management, or a related field.
  • Strong analytical, problem-solving, project management, business analysis, documentation, and organizational skills.
  • Excellent English business and technical writing and communication skills, plus functional written and verbal Chinese communication skills in Cantonese and/or Mandarin.

Nice to have

  • Experience or an internship in a GRC or related role.
  • Familiarity with GRC tools and software.
  • Experience in the broader APAC financial sector or security standards.

Culture & Benefits

  • Close partnership with business, technology, information security, and operations teams.
  • Exposure to nearly every area of the firm and regular interaction with senior and executive leadership across APAC.
  • Opportunities for continuous learning and professional development.
  • Required professional development includes 15 hours of information security training annually.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →