Über diese M26333 - GRC Specialist (Governance, Risk and Compliance) (Locally recruited) Stelle bei CIMMYT
CIMMYT is a cutting edge, non-profit, international organization dedicated to solving tomorrow's problems today. It is entrusted with fostering improved quantity, quality, and dependability of production systems and basic cereals such as maize, wheat, triticale, sorghum, millets, and associated crops through applied agricultural science, particularly in the Global South, through building strong partnerships. This combination enhances the livelihood trajectories and resilience of millions of resource-poor farmers, while working towards a more productive, inclusive, and resilient agrifood system within planetary boundaries.
For more information, visit cimmyt.org.
The GRC Specialist will serve as the internal subject-matter expert for governance, risk, and compliance across CIMMYT's enterprise application ecosystem (Dynamics 365 F&O, HR and Customer Engagement, Power Platform, ICERTIS Contract Intelligence, and Sapience HR), responsible for operating a single cross-platform GRC framework covering access control and segregation of duties, licensing and entitlement governance, data privacy, and audit readiness, under the supervision of the ERP Program Manager and in coordination with the CIMMYT ERP team, KMIT, and control and process owners across the institution.
- Own and operate the full-lifecycle Access Management procedure (request, approval, provisioning, modification, recertification, revocation), and close gaps against each platform.
- Maintain the privileged access elevation model (justification, approval, duration limits, session logging, post-use review) and the required log set, retention, and monitoring per platform.
- Maintain the consolidated cross-platform segregation-of-duties (SoD) conflict matrix, run riskranked assessments, agree remediation or mitigating controls with process owners, and operate recurring SoD reporting.
- Periodically review all accounts (active, dormant, duplicate, generic, shared, service, external), remediate orphaned accounts, and reconcile reclaimed accounts to license entitlement.
- Maintain an entitlement register per platform, reconcile licenses against actual usage and quantify the gap, assess how security role design drives license tier, and operate request, approval, and reclamation controls so reclaimed accounts convert into recovered cost.
- Maintain the data inventory and processing record, define and apply retention and disposal schedules, and enable data subject request handling within statutory timeframes.
- Maintain and test the IT general controls (ITGC) matrix (access, change management, program development, computer operations) across all platforms; report deficiencies, require appropriate corrective actions from process and control owners, challenge inadequate or delayed remediation responses, and track remediation to closure.
- Keep the evidence base continuously audit-ready, run readiness assessments before scheduled audits, act as coordination point during internal and external audit fieldwork, and track prior findings to closure.
- Maintain the GRC policy and procedures set with owners and review cycles, the ERP/IT risk register on the institutional scale, and automated key risk and control indicators reporting breaches as they occur.
- Assess interface controls (completeness, reconciliation, failure alerting, connector privileges) and the control environment of vendors with system or data access, including KMIT, reviewing assurance reports, contractual security, breach notification and audit rights, and relevant service levels.
- Operate the exception register with expiry dates, contribute to change advisory and incident root-cause analysis, and train control owners on their obligations.
- Deliver monthly progress reports and the quarterly GRC dashboard to the ERP Program Manager and governance bodies, escalating material findings directly.
- Perform other related tasks within the job level as may be requested by the immediate supervisor.
Requirements
Requirements:
- Bachelor's degree in Information Systems, Computer Science, or a related field.
- Minimum of 5 years of experience in IT GRC or IT audit, of which at least 3 on enterprise application platforms; ITGC design, testing, and remediation experience in an audited environment.
- Hands-on experience with the Dynamics 365 security model (F&O roles, duties, and privileges; CE role-based security) and practical ERP SoD design or assessment.
- Experience with Power Platform governance (environments, DLP policies, Dataverse security) and license reconciliation.
- Working knowledge of data protection law and of ISO 27001, NIST CSF, or COBIT.
- Experience preferred; CISA, CRISC, CISM, or CIPP certification an advantage; experience with ICERTIS or a comparable CLM platform, HRIS governance, a GRC tool (Pathlock, Fastpath, SAP GRC, ServiceNow IRM), or in multi-jurisdiction environments an advantage.
- Strong analytical skills and proficiency with reporting and dashboard tools; Power BI or equivalent an advantage.
- Full professional proficiency in English.
- Familiarity with ticketing tools and D365 administration highly desirable.
- Strong stakeholder management and communication skills without direct line authority, with the ability to interact professionally with internal clients across IT, Finance, HR, Legal, and vendor teams.
Benefits
CIMMYT offers an attractive remuneration package and support for continuous professional development. In addition to the provisions of the Mexican Labor Law our package of benefits includes year-end bonus (40 days), vacation premium (56%), life and medical insurance, supermarket coupons, savings fund, social Mexican benefits (IMSS, SAR / Infonavit).
Please note only short-listed candidates will be contacted.
Foreign national candidates must have legal documents to work in Mexico.
This position will remain open until filled.
CIMMYT is an equal opportunity employer. It fosters a multicultural work environment that values gender equality, teamwork, and respect for diversity.