Description

CIMMYT is a cutting edge, non-profit, international organization dedicated to solving tomorrow's problems today. It is entrusted with fostering improved quantity, quality, and dependability of production systems and basic cereals such as maize, wheat, triticale, sorghum, millets, and associated crops through applied agricultural science, particularly in the Global South, through building strong partnerships. This combination enhances the livelihood trajectories and resilience of millions of resource-poor farmers, while working towards a more productive, inclusive, and resilient agrifood system within planetary boundaries.

For more information, visit cimmyt.org.

The GRC Specialist will serve as the internal subject-matter expert for governance, risk, and compliance across CIMMYT's enterprise application ecosystem (Dynamics 365 F&O, HR and Customer Engagement, Power Platform, ICERTIS Contract Intelligence, and Sapience HR), responsible for operating a single cross-platform GRC framework covering access control and segregation of duties, licensing and entitlement governance, data privacy, and audit readiness, under the supervision of the ERP Program Manager and in coordination with the CIMMYT ERP team, KMIT, and control and process owners across the institution.

  • Own and operate the full-lifecycle Access Management procedure (request, approval, provisioning, modification, recertification, revocation), and close gaps against each platform.

  • Maintain the privileged access elevation model (justification, approval, duration limits, session logging, post-use review) and the required log set, retention, and monitoring per platform.

  • Maintain the consolidated cross-platform segregation-of-duties (SoD) conflict matrix, run riskranked assessments, agree remediation or mitigating controls with process owners, and operate recurring SoD reporting.

  • Periodically review all accounts (active, dormant, duplicate, generic, shared, service, external), remediate orphaned accounts, and reconcile reclaimed accounts to license entitlement.

  • Maintain an entitlement register per platform, reconcile licenses against actual usage and quantify the gap, assess how security role design drives license tier, and operate request, approval, and reclamation controls so reclaimed accounts convert into recovered cost.

  • Maintain the data inventory and processing record, define and apply retention and disposal schedules, and enable data subject request handling within statutory timeframes.

  • Maintain and test the IT general controls (ITGC) matrix (access, change management, program development, computer operations) across all platforms; report deficiencies, require appropriate corrective actions from process and control owners, challenge inadequate or delayed remediation responses, and track remediation to closure.

  • Keep the evidence base continuously audit-ready, run readiness assessments before scheduled audits, act as coordination point during internal and external audit fieldwork, and track prior findings to closure.

  • Maintain the GRC policy and procedures set with owners and review cycles, the ERP/IT risk register on the institutional scale, and automated key risk and control indicators reporting breaches as they occur.

  • Assess interface controls (completeness, reconciliation, failure alerting, connector privileges) and the control environment of vendors with system or data access, including KMIT, reviewing assurance reports, contractual security, breach notification and audit rights, and relevant service levels.

  • Operate the exception register with expiry dates, contribute to change advisory and incident root-cause analysis, and train control owners on their obligations.

  • Deliver monthly progress reports and the quarterly GRC dashboard to the ERP Program Manager and governance bodies, escalating material findings directly.

  • Perform other related tasks within the job level as may be requested by the immediate supervisor.


At Impactpool we do our best to provide you the most accurate info, but closing dates may be wrong on our site. Please check on the recruiting organization's page for the exact info. Candidates are responsible for complying with deadlines and are encouraged to submit applications well ahead.
Before applying, please make sure that you have read the requirements for the position and that you qualify. Applications from non-qualifying applicants will most likely be discarded by the recruiting manager.