Working Title: Governance Risk and Compliance (GRC) Risk Register Analyst
Title/Level: Information Security Manager 3
Location RemoteI.KEY RESPONSIBILITIESRisk Governance & Framework Development
- Design and implement end-to-end risk governance workflows, including:
- Risk identification and intake
- Risk review and validation
- Risk acceptance, mitigation, or transfer
- Continuous monitoring and reassessment
- Define roles and responsibilities for risk owners, reviewers, and governance bodies
- Establish escalation procedures and reporting mechanisms for high-risk scenarios
Risk Register & Scoring Model
- Develop and standardize the enterprise risk register structure and taxonomy
- Create and document risk scoring methodologies, including likelihood and impact scales
- Define prioritization logic for effective risk management decision-making
Stakeholder Engagement & Enablement
- Collaborate with cross-functional stakeholders across business, IT, security, and governance teams
- Facilitate workshops and working sessions to validate workflows and requirements
- Drive adoption and onboarding of risks into the enterprise risk register
Documentation & Knowledge Transfer
- Produce comprehensive, audit-ready documentation including:
- Risk register framework and data definitions
- Risk scoring and prioritization models
- Governance workflows and decision authorities
- Provide knowledge transfer and training to internal security staff
III. DELIVERABLESThe contractor will be responsible for delivering:
- Enterprise Risk Register Framework
- Standardized templates and taxonomy
- Risk Scoring & Prioritization Model
- Defined scoring criteria and prioritization methodology
- Risk Governance Model
- Documented workflows and roles/responsibilities
- Initial Risk Register Population
- Baseline risks reflecting current cybersecurity posture
- Final Documentation Package
- Complete operational guidance and procedures
IV. REQUIRED SKILLS & QUALIFICATIONSMinimum Requirements (Mandatory)
- 8+ years of experience in:
- Risk Register Design and Framework development
- Risk Scoring and Prioritization methodologies
- Governance processes and workflow implementation
- Stakeholder engagement and enablement
- Documentation, reporting, and knowledge transfer
- Strong understanding of GRC frameworks and cybersecurity risk management practices
- Proven ability to create audit-ready documentation
- Excellent communication and facilitation skills
VIII. IDEAL CANDIDATE PROFILE
- Strong background in enterprise risk management (ERM) and GRC tools/processes
- Experience working with government or public sector organizations preferred
- Ability to translate complex risk concepts into actionable frameworks
- Skilled in leading cross-functional collaboration and governance initiatives
Thanks & RegardsMohammad Faisal
—