İş RadarıTüm ilanlar
Aktif Remote Ümraniye Yayınlandı · 03.09.2026 LinkedIn Jobs Türkiye

Senior IT Governance, Risk & Compliance Specialist

Hepiyi Sigorta

We are looking for a Senior IT Governance, Risk & Compliance (IT GRC) Specialist to join our Information Technology organization, responsible for managing IT governance, risk, compliance, and process management activities; developing ITIL processes; coordinating internal and external audit processes; and ensuring that organizational policies and procedures remain up to date. Responsibilities • Establish, develop, and ensure the sustainability of IT Governance, Risk & Compliance processes, • Prepare, update, and periodically review IT policies, procedures, standards, instructions, and process documentation, • Establish, document, and enhance the maturity of IT processes within the ITIL framework, including Incident Management, Problem Management, Change Management, Request Management, Configuration Management, and Service Level Management, • Define roles and responsibilities related to IT processes and create RACI matrices when required, • Monitor IT processes to ensure they are carried out in accordance with defined policies, procedures, standards, and control requirements, • Coordinate between IT teams and auditors during internal audits, independent audits, and regulatory audits, • Coordinate with relevant teams to prepare and provide IT documentation and audit evidence requested during audits conducted by independent audit firms, • Record audit findings, identify relevant action owners, and track actions through to closure, • Assess the IT control environment and identify improvement actions related to control deficiencies, • Identify, assess, document, and track IT risks through the IT Risk Register, • Plan and monitor risk mitigation actions in collaboration with relevant technical and business units, • Support the assessment of IT processes in line with ISO 27001, COBIT, ITIL, NIST, and other relevant standards/frameworks, • Periodically monitor IT controls related to information security, access management, access reviews, patch management, vulnerability management, backup, log management, change management, and similar areas, • Provide IT governance support for Business Continuity Management (BCM), Business Impact Analysis (BIA), Disaster Recovery (DR), and annual DR testing processes, • Establish KPI, KRI, and SLA metrics related to IT processes and prepare periodic management reports, • Track identified improvement areas in IT processes together with relevant teams, • Support the assessment of the impact of applicable legislation and regulations on IT and the execution of necessary compliance activities. Qualifications • Bachelor’s degree in Computer Engineering, Computer Science, Management Information Systems, Industrial Engineering, or a related field, • 4–5 years of relevant experience in IT Governance, IT Risk, IT Compliance, IT Audit, Information Security Governance, or similar areas, • Knowledge of ITIL processes and IT service management, preferably with hands-on implementation experience, • Knowledge and experience in several of the following frameworks: COBIT, ISO 27001, ITIL, and NIST, • Knowledge of IT risk assessment and control design, • Experience in internal and external audit processes and in preparing audit evidence, • Experience in preparing policies, procedures, standards, and process documentation, • Experience in tracking audit findings and related actions, • Knowledge of business continuity and disaster recovery processes, • Basic knowledge of IT infrastructure sufficient to coordinate between technical IT teams and audit, risk, and compliance teams, • Strong analytical thinking, documentation, reporting, and follow-up skills, • Ability to communicate effectively with different IT teams and stakeholders, • Preferably experienced in the finance, banking, or insurance industry. Preferred Qualifications • ITIL Foundation / ITIL 4, • COBIT Foundation, • ISO 27001 Lead Implementer / Lead Auditor, • CISA, CRISC, CGEIT, or similar certifications, • Experience with GRC platforms or ITSM tools, • Experience in IT audit or IT compliance processes within regulated financial institutions, • Active involvement in IT Audit / ITGC engagements conducted with independent audit firms. Primary Purpose of the Role The primary purpose of this position is to contribute to the operation of IT processes in a documented, measurable, auditable, and sustainable manner by ensuring coordination among technical IT teams, Information Security, Risk/Compliance, Internal Audit, and independent audit teams. Rather than directly operating technical systems, the position will focus on IT Governance, IT Risk, Compliance, ITIL Process Management, and Audit Management .
Bu ilan LinkedIn Jobs Türkiye kaynağından doğrulandı. Başvuru özgün kaynakta tamamlanır.
Özgün ilanda başvur ↗
Bu ilanda sorun mu var?