Verified today
Senior Cybersecurity GRC Analyst
About the role
Cybersecurity Governance, Risk & Compliance team at McCormick drives enterprise‑wide SOX and security control initiatives. The Senior Cybersecurity GRC Analyst coordinates global IT SOX processes, conducts testing, and partners with SMEs to design controls while supporting audit and transformation projects. Based in Gurgaon, hybrid work model (50% remote, 50% onsite).
What you’ll do
- Coordinate global IT SOX processes and annual scoping
- Manage quarterly SOX testing, certifications, and remediation activities
- Develop and deliver SOX training materials for IT teams
- Collaborate with SMEs to design and mature security controls
- Support IT transformation projects and ad‑hoc internal control requests
- Perform audit testing, data analytics, and report findings to leadership
What you’ll bring
- 8-11 years experience in internal/external audit, IT, or internal controls
- Experience with Sarbanes-Oxley compliance and IT general controls
- Knowledge of SAP, HANA, Windows, SQL databases
- Familiarity with NIST, COBIT frameworks
- Strong project management and problem‑solving skills
- Excellent verbal and written communication across management levels
Skills
Education
Bachelor's degree in Information Technology, Information Systems, Risk Management, Accounting or similar