Search Jobs

Search by job, company or skills

GRC Analyst

GRC Analyst

Decathlon
Early Applicant
  • Posted 3 days ago
  • Be among the first 10 applicants

Job Description

Location: Whitefield, Bangalore - Decathlon(4 days in office and 1 day work from home)

Position: Third Party Payroll

About the Role:

We are looking for a GRC Analyst with 3–5 years of experience to lead our Third-Party Risk Management (TPRM) program. You will be responsible for ensuring that our vendors meet our security standards and data privacy requirements. This role sits at the intersection of security, legal, and procurement.

Key Responsibilities (Must Have)

  • Understanding the Engagement by liaising with the partner.
  • Vendor Assessment: Conduct end-to-end security reviews of third-party vendors using industry-standard questionnaires.
  • Clear understanding of data flow diagrams and architecture reviews.
  • DPA Review: Partner with the Legal team to review Data Processing Agreements (DPAs), ensuring appropriate technical and organizational measures are in place.
  • Risk Mitigation: Identify gaps in vendor security postures and negotiate remediation plans before contract signatures.

Key Responsibilities (Good to have)

  • Internal Audit: Support internal audit cycles (ISO 27001/PCI DSS) by gathering evidence and performing gap analyses on internal controls.
  • Risk Register Management: Maintain the corporate risk register, ensuring vendor risks are quantified and reported to stakeholders.

More Info

Job Type:
Industry:
Employment Type:

Key Skills

Vendor Assessment

Third-Party Risk Management

About Company

Similar Jobs

1-3 yrs
Bengaluru, India
Skills:
control testing GdprIso 27001AWSevidence collectionongoing monitoringNIST CSFsecurity questionnairesDPDP ActCloud fundamentalsrisk scoringThird-party risk managementVendor Risk ManagementNIST SP 800-53IT audit managementSaaS modelsmodern infrastructureTPRM
2-4 yrs
Bengaluru, India
Skills:
GdprHipaaJiraMicrosoft 365Iso 27001ConfluenceSalesforceNIST CSFAI-assisted response toolingCisaSOC 2GCP security conceptsISO 27001 Foundation or Lead ImplementerCompTIA Security+DORA
7-12 yrs
Bengaluru, India
Skills:
GdprData ProtectionIncident ResponseISO IEC 42001AI GovernanceCCPAISO IEC 27001CMMCSecurity ArchitectureCPRA
2-4 yrs
Bengaluru, India
Skills:
IsmsIso 27001RBI Master DirectionInternal AuditsnistSOC 2risk assessments
3-5 yrs
Bengaluru, India
Skills:
risk registers Iso 27001automationGrcAI toolsthird-party risk managementnistSOC 2risk assessments