Skip to content

Open nowPosted 31 days ago

M26333 - GRC Specialist (Governance, Risk and Compliance) (Locally recruited)

CIMMYT46 open roles

Where
Texcoco
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowM26333 - GRC Specialist (Governance, Risk and Compliance) (Locally recruited)CIMMYT · Texcoco
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on CIMMYT's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 31 days ago

The posting

CIMMYT is a cutting edge, non-profit, international organization dedicated to solving tomorrow's problems today. It is entrusted with fostering improved quantity, quality, and dependability of production systems and basic cereals such as maize, wheat, triticale, sorghum, millets, and associated crops through applied agricultural science, particularly in the Global South, through building strong partnerships. This combination enhances the livelihood trajectories and resilience of millions of resource-poor farmers, while working towards a more productive, inclusive, and resilient agrifood system within planetary boundaries.

For more information, visit cimmyt.org.

The GRC Specialist will serve as the internal subject-matter expert for governance, risk, and compliance across CIMMYT's enterprise application ecosystem (Dynamics 365 F&O, HR and Customer Engagement, Power Platform, ICERTIS Contract Intelligence, and Sapience HR), responsible for operating a single cross-platform GRC framework covering access control and segregation of duties, licensing and entitlement governance, data privacy, and audit readiness, under the supervision of the ERP Program Manager and in coordination with the CIMMYT ERP team, KMIT, and control and process owners across the institution.

  • Own and operate the full-lifecycle Access Management procedure (request, approval, provisioning, modification, recertification, revocation), and close gaps against each platform.
  • Maintain the privileged access elevation model (justification, approval, duration limits, session logging, post-use review) and the required log set, retention, and monitoring per platform.
  • Maintain the consolidated cross-platform segregation-of-duties (SoD) conflict matrix, run riskranked assessments, agree remediation or mitigating controls with process owners, and operate recurring SoD reporting.
  • Periodically review all accounts (active, dormant, duplicate, generic, shared, service, external), remediate orphaned accounts, and reconcile reclaimed accounts to license entitlement.
  • Maintain an entitlement register per platform, reconcile licenses against actual usage and quantify the gap, assess how security role design drives license tier, and operate request, approval, and reclamation controls so reclaimed accounts convert into recovered cost.
  • Maintain the data inventory and processing record, define and apply retention and disposal schedules, and enable data subject request handling within statutory timeframes.
  • Maintain and test the IT general controls (ITGC) matrix (access, change management, program development, computer operations) across all platforms; report deficiencies, require appropriate corrective actions from process and control owners, challenge inadequate or delayed remediation responses, and track remediation to closure.
  • Keep the evidence base continuously audit-ready, run readiness assessments before scheduled audits, act as coordination point during internal and external audit fieldwork, and track prior findings to closure.
  • Maintain the GRC policy and procedures set with owners and review cycles, the ERP/IT risk register on the institutional scale, and automated key risk and control indicators reporting breaches as they occur.
  • Assess interface controls (completeness, reconciliation, failure alerting, connector privileges) and the control environment of vendors with system or data access, including KMIT, reviewing assurance reports, contractual security, breach notification and audit rights, and relevant service levels.
  • Operate the exception register with expiry dates, contribute to change advisory and incident root-cause analysis, and train control owners on their obligations.
  • Deliver monthly progress reports and the quarterly GRC dashboard to the ERP Program Manager and governance bodies, escalating material findings directly.
  • Perform other related tasks within the job level as may be requested by the immediate supervisor.

Requirements

Requirements:

  • Bachelor's degree in Information Systems, Computer Science, or a related field.
  • Minimum of 5 years of experience in IT GRC or IT audit, of which at least 3 on enterprise application platforms; ITGC design, testing, and remediation experience in an audited environment.
  • Hands-on experience with the Dynamics 365 security model (F&O roles, duties, and privileges; CE role-based security) and practical ERP SoD design or assessment.
  • Experience with Power Platform governance (environments, DLP policies, Dataverse security) and license reconciliation.
  • Working knowledge of data protection law and of ISO 27001, NIST CSF, or COBIT.
  • Experience preferred; CISA, CRISC, CISM, or CIPP certification an advantage; experience with ICERTIS or a comparable CLM platform, HRIS governance, a GRC tool (Pathlock, Fastpath, SAP GRC, ServiceNow IRM), or in multi-jurisdiction environments an advantage.
  • Strong analytical skills and proficiency with reporting and dashboard tools; Power BI or equivalent an advantage.
  • Full professional proficiency in English.
  • Familiarity with ticketing tools and D365 administration highly desirable.
  • Strong stakeholder management and communication skills without direct line authority, with the ability to interact professionally with internal clients across IT, Finance, HR, Legal, and vendor teams.

Benefits

CIMMYT offers an attractive remuneration package and support for continuous professional development. In addition to the provisions of the Mexican Labor Law our package of benefits includes year-end bonus (40 days), vacation premium (56%), life and medical insurance, supermarket coupons, savings fund, social Mexican benefits (IMSS, SAR / Infonavit).

Please note only short-listed candidates will be contacted.

Foreign national candidates must have legal documents to work in Mexico.

This position will remain open until filled.

CIMMYT is an equal opportunity employer. It fosters a multicultural work environment that values gender equality, teamwork, and respect for diversity.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against CIMMYT's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on CIMMYT's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    CIMMYT's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.