A&A: Consultant (GRC Configuration)

🗓️ Posted 2026-08-03 Bangkok City, Thailand Full-time Hybrid ICT

Company shared salary

NA

Market rate

THB 45,000–THB 75,000/mo (THB 540,000–THB 900,000/yr)

Based on similar roles (title + domain + location).

About the Company

Work You Will Do As a GRC Technology Consultant , you will be part of our Governance, Risk, and Compliance (GRC) team, supporting the delivery of technology-enabled risk transformation projects . In this role, you will perform a functional consultant capacity by gathering business requirements, contributing to the design, implementation, and enhancement of the Information Technology Risk Management (ITRM) module within our GRC platform.

Responsibilities

  • nd the system implementation team, ensuring effective design, testing, and deployment of ITRM functionalities. Your work will align with established risk management frameworks, regulatory requirements, and industry best practices to enable a robust and sustainable risk management environment.
  • Gather business and regulatory requirements from stakeholders.
  • Provide advisory on Information Technology Risk Management to support good design of system functionality to ensure design aligning with relevant regulatory requirement and good practice.
  • Information Technology Risk Management Framework and Matrix
  • Information Technology Risk Management Workflow from end to end including identification, assessment, monitoring, escalation and reporting.
  • Information Technology Risk Indicators
  • Information Technology Risk Inventory and Controls
  • Information Technology Asset (application, devices, IT asset etc.) and Mapping with Control
  • Information Technology Risk Dashboard
  • IT Incident Management Activities from end-to-end process
  • Translate requirements into system specifications and user stories.
  • Prepare documentation including Requirement Traceability Matrix (RTM), Functional Specification Document (FSD), and process flows.
  • Support design, configuration, and integration of the ITRM module within the GRC platform.
  • Develop and execute test cases and UAT scripts for ITRM module.
  • Support accuracy and completeness of data migration and system outputs.
  • Document test results, track defects, and support resolution.
  • Create training materials such as manuals, quick guides, and e-learning modules.
  • Deliver user training sessions and provide adoption support.

Requirements

  • Bachelor's or Master's degree in Business Administration, Risk Management, Finance, Information Systems, or related field.
  • -3 years of experience in GRC, Information Technology Risk Management, or Risk Advisory, preferably in the financial services sector.
  • Strong knowledge of IT Risk Management frameworks and regulatory standards (e.g. ISO, NIST, COBIT, Basel, or BOT).
  • Archer Certified Administrator (Specialist/Expert), ServiceNow CIS (Risk & Compliance), or equivalent certification is a plus.
  • Proficiency in business analysis, documentation, and stakeholder facilitation.
  • Strong problem-solving, analytical, and communication skills.
  • Professional certifications such as GRC, CISA, CRISC, CISM, CISSP are highly desirable.
  • Technical Skills
  • Exposure to GRC/IRM platforms such as Archer, ServiceNow, or MetricStream.
  • Understanding of workflows, reporting, and dashboard.
  • Proficiency in Microsoft Excel and PowerPoint for analysis and reporting.
  • Analytical and detail-oriented mindset with the ability to work on multiple projects simultaneously.
  • Strong written and verbal communication, able to engage both technical and business stakeholders.
  • Team-oriented with a willingness to learn and adapt to dynamic client environments.
  • Ability to work in structured consulting environments with deadlines and deliverables.
  • Industry Focus: FSI
  • Exposure to banking, asset management, digital asset, insurance, and financial services risk and compliance processes. Understanding of significant risk and compliance domain for specific industry.