IT Domain GRC Specialist - Back-Office

🗓️ Posted 2026-09-03 2 Locations Hybrid ICT

Company shared salary

NA

Market rate

4,500 GBP–6,500 GBP/mo (54,000 GBP–78,000 GBP/yr)

Based on similar roles (title + domain + location).

About the Company

AVEVA is creating software trusted by over 90% of leading industrial companies. Job Title: IT Domain GRC Specialist - Back-Office Location: Hyderabad / Bengaluru Employment Type: Full-time, Hybrid The job The IT Domain GRC Specialist - Back Office is responsible for defining, implementing, and ensuring the effective operation of IT controls within the Back Office domain, with a strong emphasis on the Oracle ERP SaaS environment. This role ensures compliance with SOx requirements , leads the adoption of AVEVA's Crown Jewel Security Playbook , and protects critical assets through governance, identification, protection, detection, response, and recovery practices.

About the Role

tiple GRC stakeholders to document control designs, manage evidence collection, coordinate key dependencies, and strengthen Role-Based Access Control (RBAC) across Back Office operations. This position plays a vital role in shaping digital risk management and maintaining a secure and compliant Back Office ecosystem.

Responsibilities

  • ● Document control designs for Back Office processes, ensuring alignment with Crown Jewel Playbook controls such as stakeholder inventories, supply-chain risk management, risk assessments, data inventories, and user access reviews.
  • ● Coordinate and support Control Operators in maintaining structured, accurate evidence for control effectiveness, including backups, vulnerability scans, logging, and penetration testing results.
  • ● Project manage dependencies across teams-ensuring timely SOC report reviews (Finance), JML feeds (HR), and user access reviews (Business Owners).
  • ● Strengthen RBAC structures by reviewing roles, permissions, and access levels to support least privilege principles and periodic access certifications.
  • ● Define cybersecurity and data protection requirements for Back Office systems, especially Oracle ERP SaaS, ensuring consistent compliance across services.
  • ● Support readiness and response efforts for cybersecurity incidents within Back Office scope, contributing to domain specific security best practices.
  • ● Identify, mitigate, and monitor cybersecurity risks related to Back Office activities, ensuring protection of Crown Jewel assets.
  • ● Guide teams on Secure Development Lifecycle (SDL) practices, ensuring security and privacy requirements are embedded into design and delivery.
  • ● Measure compliance with IT policies, set KPIs, identify gaps, and lead corrective initiatives. Prepare documentation for internal and external audits, as well as Executive Risk Committee submissions.
  • ● Ensure SOx compliance through timely evidence collection, audit preparation, and proactive management of remediation activities.
  • ● Serve as the Digital Risk representative for the domain and collaborate with broader GRC teams as required.

Requirements

  • ● ISACA (or equivalent) qualification such as CISA , CISM , or CGEIT .
  • ● Minimum 2 years' experience in IT control design, assurance, or auditing.
  • ● Hands on experience with Oracle ERP SaaS , including implementing controls for financial and operational processes.
  • ● Strong proficiency in documenting risk and control mappings for audit review.
  • ● Ability to map business processes, system workflows, and RBAC structures.
  • ● Strong MS Office skills, especially Excel, PowerPoint, Outlook, and SharePoint.
  • ● Desired skills
  • ● Knowledge of Crown Jewel Playbook controls (e.g., patching, MFA, data encryption, incident response).
  • ● Familiarity with Oracle ERP specific controls such as database hardening, data flow mapping, and supplier security requirements.
  • ● Strong analytical skills and the ability to coach non direct reports.
  • ● Collaborative mindset, with the ability to work across teams while establishing clear accountability.
  • ● High attention to detail when drafting submissions or communications for auditors and stakeholders.
  • ● Proactive approach to identifying improvements and driving evidence based enhancements.
  • ● Our global team of 300+ IT professionals is responsible for the systems and platforms that keep AVEVA running. By empowering our colleagues and ensuring the smooth operation of the company, we help keep the business healthy and productivity high. We also provide key support for the transformation and modernisation efforts globally.
  • ● We pride ourselves on a collaborative, inclusive and authentic culture that provides a framework allowing for autonomy, whilst always being available for support and guidance. We respect the differences that each team member brings and seek to include those perspectives in our solutions for our business functions. The energy and sense of purpose is evident when talking to team members, you will feel part of something special from the first day you join.
  • ● Find out more: https://www.aveva.com/en/about/careers/
  • ● India Benefits include:
  • ● Gratuity, Medical and accidental insurance, very attractive leave entitlement, emergency leave days, childcare support, maternity, paternity and adoption leaves, education assistance program, home office set up support (for hybrid roles), well-being support
  • ● It's possible we're hiring for this position in multiple countries, in which case the above benefits apply to the primary location. Specific benefits vary by country, but our packages are similarly comprehensive.
  • ● Find out more: aveva.com/en/about/careers/benefits/