Sr. IT GRC Analyst

🗓️ Posted 2026-08-20 Abu Dhabi, Abu Dhabi Emirate, United Arab Emirates Full-time Hybrid ICT

Company shared salary

NA

Market rate

AED 20,000–AED 30,000/mo (AED 240,000–AED 360,000/yr)

Based on similar roles (title + domain + location).

About the Company

Avrioc and its associated entities operate across fintech, digital platforms, gaming, fitness, communication and related technology-enabled businesses. The group is committed to maintaining strong governance, risk management, regulatory compliance, information security and operational resilience across its products and services. The Sr. IT GRC Analyst will support the implementation and ongoing management of the technology governance, risk and compliance framework across Avrioc and its associated entities, including regulated and non-regulated business units.

About the Role

coordination, certification maintenance, third-party risk management, IT control reviews, evidence management and GRC reporting. The role requires close coordination with Technology, Cybersecurity, DevOps, Product, Compliance, Legal, Privacy, Finance, Operations and business teams to ensure that technology and business processes remain aligned with internal policies, applicable regulatory requirements and industry standards.

Responsibilities

  • Maintain and update technology risk registers across Avrioc and its associated entities, including risk identification, assessment, ownership, treatment actions, residual risk and closure tracking.
  • Support Risk and Control Self-Assessment activities and ensure timely reporting of control gaps, risk exposures and remediation status.
  • Monitor technology risk indicators and provide periodic updates to GRC management and relevant stakeholders.
  • Support ongoing compliance with applicable standards and frameworks, including PCI DSS, ISO 27001, ISO 20000, UAE IA, NIST, COBIT, ITIL and other relevant requirements.
  • Support compliance with CBUAE and other applicable regulatory requirements for regulated entities and products, including technology risk, outsourcing, cybersecurity, operational resilience, business continuity and incident-reporting requirements.
  • Coordinate internal audits, external audits, certification audits, customer audits, regulatory reviews and evidence-collection activities.
  • Track audit findings, regulatory observations, risk-treatment actions, control gaps, policy exceptions and management action plans through closure.
  • Maintain accurate GRC documentation, including policies, procedures, risk assessments, audit evidence, control trackers, compliance reports and management updates.
  • Track regulatory and framework updates, assess applicability across relevant entities and support impact assessments.
  • Work with IT, DevOps and Cybersecurity teams to review IT general controls, access controls, privileged access, change management, backup, logging, monitoring, vulnerability management and incident-management controls.
  • Support third-party risk management, including vendor due diligence, risk assessment, contract-control review, ongoing monitoring, evidence tracking and renewal reviews.
  • Support cloud, application, infrastructure, data, AI and integration risk assessments across group products and platforms.
  • Support implementation and usage of GRC tools such as Vanta, Jira and other evidence-management or compliance automation platforms.
  • Assist in preparing dashboards, reports and updates for management, auditors, regulators and internal stakeholders.
  • Support employee awareness activities related to GRC, information security, risk management and compliance.
  • Promote a culture of accountability, timely remediation, evidence-based control ownership and continuous improvement. Skills and Attributes
  • Good understanding of technology risk management, IT governance, information security, compliance and audit practices.
  • Knowledge of PCI DSS, ISO 27001, ISO 20000, NIST, COBIT, ITIL, UAE IA and CBUAE technology risk expectations.
  • Understanding of IT general controls, access management, change management, incident management, vulnerability management, cloud governance and third-party risk management.
  • Ability to support GRC activities across multiple entities, products and technology environments.