Specialist, GRC (Governance, Risk & Compliance)
On-siteSanturce, Santa Fe Province, Argentine Republic
Job Summary
Execute IT/OT security risk assessments and compliance reviews aligned with the LUMA Cybersecurity Controls Program and frameworks such as NIST CSF, CIS Controls, and NERC CIP. Maintain the risk register and self-identified issue tracker to ensure accurate status reporting and timely escalation of risks. Support audit activities by assessing compliance with information security policies, coordinating third-party assessments, and tracking remediation progress for identified control gaps. Monitor technology projects to validate secure-by-design principles and support incident response through review of data protection controls and log reports. Prepare monthly and quarterly compliance reports with data-driven insights and deliver cybersecurity awareness training across IT/OT teams. Participate in storm restoration tasks and assigned drills to contribute to service recovery.
Required Qualifications
- Bachelor's degree Information Technology, Computer Science, Engineering, or related field
- 5 years of related experience in information security governance, risk management, compliance, or audit functions
- Demonstrated experience executing audit plans, maintaining risk registers, and supporting compliance programs
- Experience working with cybersecurity frameworks such as NIST CSF, CIS Controls, NERC CIP, or equivalent standards
- Experience with evidence repositories, compliance dashboards, and GRC tools
- Experience collaborating with cross-functional technical teams and external auditors in a regulated or highly controlled environment
- Knowledge of governance, risk, compliance, and audit frameworks (NIST CSF, CIS v8, NERC CIP, PR Cybersecurity Act)
- Strong analytical and critical thinking skills with ability to interpret complex data
- Understanding of relevant laws, regulations, and industry standards applicable to IT/OT environments
- Excellent communication skills, with the ability to translate complex technical concepts for non-technical audiences
- Ability to collaborate effectively with cross-functional teams and external auditors
- Strong planning and organizational skills, with the ability to manage multiple audit and compliance workstreams simultaneously
- 20% travel
Desired Qualifications
- Associate's degree in information technology, Computer Science
- Certified Information Systems Auditor (CISA)
- Certified in Risk and Information Systems Control (CRISC)
- Certified Information Security Manager (CISM)
- Certified Information Systems Security Professional (CISSP)
- Additional NIST, NERC CIP, or cybersecurity framework certifications
- Experience collaborating with cross-functional technical teams and external auditors in a regulated or highly controlled environment preferred
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.