Position: GRC & Compliance Specialist
Department: Compliance & Operations
Working Hours: 01:00 PM – 10:00 PM
Employment Type: Full-Time
Location: On-site

Clear Wave Information Technologies (CWIT) is a technology-driven digital transformation company specializing in enterprise software development, AI solutions, cloud technologies, cybersecurity, automation, and IT-enabled services. We provide secure, scalable technology solutions across industries, helping businesses enhance operations through advanced platforms and digital transformation services. As we expand our compliance capabilities, we seek an experienced GRC & Compliance Specialist to establish governance practices, manage compliance frameworks, support certifications, and maintain audit-ready documentation.

The GRC & Compliance Specialist will develop and maintain governance, risk, compliance, certification, and audit documentation processes. The ideal candidate will have hands-on experience in GRC activities, ISO certification preparation, audit coordination, policy development, risk management, and compliance documentation. This role demands translating regulatory and certification requirements into practical policies and controls while collaborating with technical and business teams. Experience with ISO 27001, ISO 9001, SOC 2, GDPR, PCI DSS, banking, financial services, cybersecurity, SaaS, or enterprise technology environments is highly preferred.

Key Responsibilities
- Develop, maintain, and improve corporate governance documentation including policies, procedures, standards, and control documents.
- Establish document management processes covering ownership, approval workflows, review cycles, version control, and retention.
- Prepare and maintain information security, data protection, risk management, operational, and compliance policies aligned with business operations and regulatory requirements.
- Lead and support organizational readiness for compliance certifications such as ISO 27001, ISO 9001, SOC 2, GDPR, PCI DSS, including conducting gap assessments and developing implementation roadmaps.
- Map organizational processes and controls against compliance requirements and maintain control matrices, Statements of Applicability, corrective action plans, and compliance tracking.
- Establish and maintain risk registers for corporate, operational, information security, and vendor risks; perform risk assessments and monitor mitigation activities.
- Plan and coordinate internal and external audits, prepare audit schedules, collect and organize audit evidence, document findings, and coordinate with stakeholders.
- Conduct vendor and third-party security assessments, complete customer security questionnaires, and support compliance for RFPs, tenders, and security reviews.
- Develop compliance awareness materials and training content, maintain policy acknowledgments, track compliance KPIs and KRIs, and provide regular compliance updates and recommendations to management.

Required Qualifications
- Bachelor’s degree in Computer Science, Software Engineering, IT, Cybersecurity, Business Administration, or related field.
- 4–7 years of professional experience in GRC, compliance, certification, audit documentation, or information security roles.
- Practical experience supporting compliance programs, audits, and certification activities, especially ISO 27001.
- Proven ability to prepare policies, procedures, control documentation, and audit evidence.
- Experience in software, SaaS, banking, cybersecurity, telecommunications, or managed services environments is advantageous.
- Strong understanding of GRC concepts, information security controls, risk assessments, control testing, audit evidence management, and remediation tracking.
- Excellent written and verbal communication skills in English, with strong documentation, reporting, and organizational abilities.
- Ability to coordinate effectively with both technical and business teams.

Preferred Qualifications and Benefits
- Experience with additional frameworks such as SOC 2, GDPR, PCI DSS, ISO 9001, NIST CSF, CIS Controls, and COBIT.
- Familiarity with customer security questionnaires, enterprise security assessments, cloud security controls, and data protection practices.
- Experience using GRC platforms and compliance evidence management tools.
- Preferred certifications include ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, CISA, CRISC, CISM, CGEIT, and COBIT.

What We Offer
- Competitive market-based salary ranging from Rs70,000 to Rs120,000 per month.
- Opportunity to establish and enhance enterprise compliance practices.
- Exposure to international standards and enterprise technology environments.
- Experience working with AI, cloud solutions, cybersecurity, and software platforms.
- Professional growth opportunities in governance, risk, and compliance domains.
- Collaborative work environment with technical, operational, and business teams.
- Support for continuous learning and professional certifications.

Work Location: On-site (In person)

Job Details

Total Positions:
1 Post
Job Shift:
First Shift (Day)
Job Type:
Job Location:
Gender:
No Preference
Age:
18 - 65 Years
Minimum Education:
Bachelors
Career Level:
Mid-Level
Experience:
3 Years - 5 Years
Apply Before:
Oct 02, 2026
Posting Date:
Sep 26, 2026

Clear Wave Information Technologies

· 11-50 employees - Lahore

What is your Competitive Advantage?

Get quick competitive analysis and professional insights about yourself
Talk to our expert team of counsellors to improve your CV!
Try Rozee Premium

Similar Job Titles

Package Specialist-SAP GRC

Naseeb Enterprise Inc, Islamabad, Pakistan
Posted Sep 30, 2026

Package Specialist-SAP GRC

Naseeb Enterprise Inc, Islamabad, Pakistan
Posted Sep 29, 2026

Package Specialist-SAP GRC

Naseeb Enterprise Inc, Karachi, Pakistan
Posted Sep 29, 2026

Package Specialist-SAP GRC

Naseeb Enterprise Inc, Islamabad, Pakistan
Posted Sep 28, 2026
View All
I found a job on Rozee!