GRC Specialist (Governance, Risk and Compliance)

GRC Specialist (Governance, Risk and Compliance)

International Maize and Wheat Improvement Center (CIMMYT)

September 8, 2026October 23, 2026TexcocodemoraMexico
Job Description
Job Posting Organization:
CIMMYT, the International Maize and Wheat Improvement Center, is a non-profit, international organization that was established to address the challenges of security" style="border-bottom: 1px dotted #007bff !important;">security" style="border-bottom: 1px dotted #007bff !important;">food security and agricultural sustainability. The organization is dedicated to improving the quantity, quality, and reliability of production systems for staple crops such as maize, wheat, and other cereals. CIMMYT operates primarily in the Global South, focusing on building strong partnerships to enhance the livelihoods of resource-poor farmers. The organization employs a diverse workforce and operates in multiple countries, working towards a more productive and resilient agrifood system while adhering to planetary boundaries. For more information, visit cimmyt.org.

Job Overview:
The GRC Specialist will act as the internal subject-matter expert for governance, risk, and compliance within CIMMYT's enterprise application ecosystem. This includes overseeing a comprehensive cross-platform GRC framework that encompasses various aspects such as access control, licensing governance, data privacy, and audit readiness. The role requires collaboration with the ERP Program Manager and the CIMMYT ERP team, as well as coordination with control and process owners across the institution. The GRC Specialist will be responsible for managing the full lifecycle of Access Management procedures, maintaining the privileged access elevation model, and ensuring compliance with data protection laws. The position also involves conducting risk assessments, maintaining an entitlement register, and ensuring that the organization remains audit-ready at all times. The GRC Specialist will deliver regular reports to governance bodies and escalate material findings as necessary.

Duties and Responsibilities:
The duties and responsibilities of the GRC Specialist include:
  • Operating a comprehensive GRC framework across CIMMYT's enterprise applications, ensuring compliance with access control and segregation of duties.
  • Managing the full lifecycle of Access Management procedures, including request, approval, provisioning, modification, recertification, and revocation of access.
  • Maintaining the privileged access elevation model and ensuring compliance with logging and monitoring requirements.
  • Conducting periodic reviews of all accounts and remediating orphaned accounts.
  • Maintaining an entitlement register and reconciling licenses against actual usage.
  • Managing the data inventory and processing records, including retention and disposal schedules.
  • Testing and maintaining IT general controls across all platforms and reporting deficiencies.
  • Preparing for internal and external audits, acting as a coordination point during audit fieldwork, and tracking prior findings to closure.
  • Maintaining GRC policies and procedures, as well as the ERP/IT risk register. 1
  • Assessing interface controls and vendor control environments. 1
  • Delivering monthly progress reports and quarterly GRC dashboards to the ERP Program Manager.

Required Qualifications:
The required qualifications for the GRC Specialist position include:
  • A Bachelor's degree in Information Systems, Computer Science, or a related field.
  • A minimum of 5 years of experience in IT governance, risk, and compliance (GRC) or IT audit, with at least 3 years focused on enterprise application platforms.
  • Experience in ITGC design, testing, and remediation in an audited environment.
  • Hands-on experience with the Dynamics 365 security model and practical experience in ERP segregation of duties design or assessment.
  • Familiarity with Power Platform governance and license reconciliation.
  • Knowledge of data protection laws and standards such as ISO 27001, NIST CSF, or COBIT.
  • Professional certifications such as CISA, CRISC, CISM, or CIPP are preferred.
  • Strong analytical skills and proficiency with reporting and dashboard tools, with Power BI or equivalent being an advantage.
  • Excellent stakeholder management and communication skills.

Educational Background:
Candidates must possess a Bachelor's degree in Information Systems, Computer Science, or a related field. This educational background is essential for understanding the technical aspects of governance, risk, and compliance within enterprise applications.

Experience:
The position requires a minimum of 5 years of relevant experience in IT governance, risk, and compliance or IT audit. Candidates should have at least 3 years of experience specifically working with enterprise application platforms, demonstrating a strong understanding of ITGC design, testing, and remediation in an audited environment.

Languages:
Full professional proficiency in English is mandatory for this position. Familiarity with additional languages may be considered an advantage, but English proficiency is essential for effective communication within the organization and with stakeholders.

Additional Notes:
CIMMYT offers an attractive remuneration package that includes benefits beyond the provisions of Mexican Labor Law, such as a year-end bonus equivalent to 40 days of salary, a vacation premium of 56%, life and medical insurance, supermarket coupons, and a savings fund. The organization also provides social benefits in accordance with Mexican regulations. Candidates must have the legal right to work in Mexico, and only shortlisted candidates will be contacted. This position is open until filled, and CIMMYT is committed to fostering a multicultural work environment that values diversity and gender equality.
Apply now
Similar Jobs