Clear Wave Information Technologies (CWIT) is looking for a skilled GRC & Compliance Specialist to join their Compliance & Operations team in a full-time, on-site capacity. The role operates from 1:00 PM to 10:00 PM and focuses on developing and maintaining governance, risk, compliance, certification, and audit documentation processes. The ideal candidate will have practical experience in GRC activities, ISO certification preparation, audit coordination, policy development, risk management, and compliance documentation. This position requires translating regulatory and certification requirements into actionable policies and controls while working closely with both technical and business teams. Experience with ISO 27001, ISO 9001, SOC 2, GDPR, PCI DSS, and familiarity with banking, financial services, cybersecurity, SaaS, or enterprise technology sectors is highly valued.

Key Responsibilities

Governance & Policy Management: Develop and maintain corporate governance documentation, including policies, procedures, standards, and control documents. Oversee document ownership, approval workflows, review cycles, version control, and retention. Ensure alignment of policies with business operations and compliance mandates.

Compliance Certification & Framework Management: Lead efforts to prepare the organization for compliance certifications such as ISO 27001, ISO 9001, SOC 2, GDPR, and PCI DSS. Conduct gap assessments, identify areas for improvement, develop certification roadmaps, and map controls against standards. Prepare control matrices, Statements of Applicability, corrective action plans, and compliance tracking documentation.

Risk Management: Create and maintain risk registers covering corporate, operational, information security, and vendor risks. Conduct risk assessments detailing likelihood, impact, controls, treatment plans, ownership, and deadlines. Monitor mitigation efforts and support ongoing enhancement of risk management practices.

Audit Management & Evidence Preparation: Plan and coordinate internal and external audits, including scheduling, checklists, and evidence requirements. Collect, review, and organize audit evidence with clear traceability. Document findings, non-conformities, remediation actions, and liaise with auditors and stakeholders.

Customer & Third-Party Compliance: Perform vendor and third-party security assessments. Complete customer security questionnaires and compliance assessments. Support compliance needs for enterprise customers, RFPs, tenders, and security reviews. Manage data processing agreements, NDAs, SLAs, and security obligations.

Compliance Awareness & Reporting: Develop compliance awareness materials and employee training content. Maintain policy acknowledgement records. Define and monitor compliance KPIs and KRIs, prepare dashboards and management reports, and provide regular updates and recommendations to leadership.

Required Qualifications

Bachelor’s degree in Computer Science, Software Engineering, Information Technology, Cybersecurity, Business Administration, or a related field. Four to seven years of professional experience in GRC, compliance, certification, audit documentation, or information security roles. Demonstrated ability to support compliance programs, audits, and certification activities. Proven skills in preparing policies, procedures, control documentation, and audit evidence. Strong understanding of GRC concepts, information security controls, and risk assessment methodologies. Hands-on experience with ISO 27001 requirements and control implementation. Excellent written and verbal communication skills in English. Strong documentation, reporting, organizational skills, and attention to detail. Ability to collaborate effectively with technical and business teams.

Preferred Qualifications and Benefits

Experience with compliance frameworks such as SOC 2, GDPR, PCI DSS, ISO 9001, NIST CSF, CIS Controls, and COBIT is advantageous. Familiarity with customer security questionnaires, tender compliance documentation, enterprise security assessments, cloud security controls, and data protection practices is preferred. Experience using GRC platforms and compliance evidence management tools is a plus. Relevant certifications like ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, CISA, CRISC, CISM, CGEIT, or COBIT are highly regarded. The role offers a competitive market-based salary ranging from Rs70,000 to Rs120,000 per month. Candidates will have the opportunity to establish and enhance enterprise compliance practices within a technology-driven environment. Exposure to international standards and enterprise technology, including AI, cloud solutions, and cybersecurity initiatives, is provided. The position supports professional growth in governance, risk, and compliance domains within a collaborative work environment involving technical, operational, and business teams. Continuous learning and certification advancement are encouraged and supported.

Work Location: On-site at Clear Wave Information Technologies.

Job Details

Total Positions:
1 Post
Job Shift:
First Shift (Day)
Job Type:
Job Location:
Gender:
No Preference
Age:
18 - 65 Years
Minimum Education:
Bachelors
Career Level:
Mid-Level
Experience:
3 Years - 5 Years
Apply Before:
Oct 01, 2026
Posting Date:
Sep 25, 2026

Clear Wave Information Technologies

· 11-50 employees - Lahore

What is your Competitive Advantage?

Get quick competitive analysis and professional insights about yourself
Talk to our expert team of counsellors to improve your CV!
Try Rozee Premium

Similar Job Titles

Assistant Manager - IT Audit & Advisory

Naseeb Enterprise Inc, Karachi, Pakistan
Posted Sep 24, 2026
I found a job on Rozee!