Search by job, company or skills

GRC ANALYST

GRC ANALYST

Deltek
Fresher
Not Disclosed
Early Applicant
  • Posted 5 days ago
  • Be among the first 10 applicants

Job Description


Work Shift - 4 PM to 1 AM (IST)

100% Remote

Key Priorities :

· Deliver audit readiness and timely, high-quality evidence packages.

· Maintain control documentation and support continuous monitoring.

· Own risk and Plan of Action and Milestones (PoA&M) reporting, including end-to-end deliverables and coordination with Engineering, Product, and IT.

Audit, Assessment and Cloud Compliance.

· Lead cloud SaaS applications through audit frameworks and assessments, including SOC 1, SOC 2, NIST 800-53, NIST 800-171, CMMC, ISO, FedRAMP, PCI DSS, CIS, CSA CSM, and other applicable security regulations.

· Lead or support end-to-end internal and external audit engagements, including scoping, evidence requests, control testing, issue tracking, and final report support.

· Assess and communicate administrative, technical, and security controls across Oracle Cloud Infrastructure (OCI), Amazon Web Services (AWS), and Microsoft Azure.

· Translate regulatory obligations and control requirements into clear, testable expectations for technical teams.

Project Delivery, Automation and Stakeholder Coordination.

· Apply project management practices to plan, track, and deliver security assessments.

· Use Jira for epics and stories, backlog grooming, tracking, and stakeholder reporting.

· Use automation and AI responsibly to streamline evidence collection, control mapping, and recurring reporting, while maintaining appropriate human review.

· Coordinate inputs and follow-through across Engineering, Product, IT, auditors, and other stakeholders.

Reporting and Continuous Improvement :

· Define, build, and maintain recurring monthly and quarterly GRC metrics and dashboards.

· Present trends, risks, and remediation status to senior leadership.

· Draft, maintain, and socialize security policies, standards, and System Security Plans (SSPs), including control narratives, implementation details, and evidence references.

· Produce high-quality audit deliverables, including narratives, evidence packages, and status reports.

· Manage risk register items and PoA&Ms end-to-end by identifying control gaps, partnering on remediation plans, and tracking progress through continuous monitoring.

Program Ownership and Documentation

· Own, or serve as backup owner for, key GRC programs by maintaining procedures, service-level agreements (SLAs), and audit and customer-request artifacts.

· Support policy management and security due diligence questionnaires for Requests for Information (RFIs) and Requests for Proposals (RFPs).

· Participate in initiatives that improve team processes and procedures.

· Maintain and curate annual compliance training content and help improve the training process.

· Participate in incident-response reviews and root-cause analyses by documenting control failures, corrective actions, and follow-up evidence through closure.

More Info

Job Type:
Industry:
Employment Type:

Key Skills

SOC 2

NIST 800-171

Oracle Cloud Infrastructure (OCI)

Amazon Web Services (AWS)

NIST 800-53

CMMC

About Company

Similar Jobs

India
Skills:
Servicenow, Excel, audit-support practices, workflow-automation tools, UpGuard, generative AI, Diligent, One, NIST CSF, security governance, risk compliance controls, SOC 2, phishing simulations, third-party risk management, security awareness, Microsoft Purview, Sharepoint, Tenable, reporting dashboards, policy lifecycle management, vulnerability remediation, ISO IEC 27001
2-4 yrs
Mumbai, India
Skills:
Iso 27001, risk management, data annotation, AI evaluation workflows, GRC compliance, data quality review, nist, SOC 2, PCI-DSS
Cochin / Kochi / Ernakulam, India
Skills:
Iso 27001, Archer, Itil, ServiceNow GRC, Cobit, nist, MetricStream, regulatory and legal compliance requirements, risk assessment methodologies, GRC frameworks
2-4 yrs
Bengaluru, India
Skills:
Iso 27001, RBI Master Direction, nist, SOC 2
1-3 yrs
Bengaluru, India
Skills:
control testing , Gdpr, Iso 27001, AWS, evidence collection, ongoing monitoring, NIST CSF, security questionnaires, DPDP Act, Cloud fundamentals, risk scoring, Third-party risk management, Vendor Risk Management, NIST SP 800-53, IT audit management, SaaS models, modern infrastructure, TPRM