Search Jobs

Search by job, company or skills

GRC Analyst

GRC Analyst

Exotel
Early Applicant
  • Posted a day ago
  • Be among the first 10 applicants

Job Description

Job Overview

We are looking for a highly skilled IT Governance, Risk and Compliance (GRC) Analyst to manage information security and compliance initiatives by supporting our NIST CSF, ISO 27001, GDPR, DPDP Act, TPRM and other related programs, while driving risk management, audit readiness and continuous process improvement.

Key Responsibilities

  • Manage IT Compliance programs and support IT/ Security initiatives, including NIST CSF 2.0, ISO 27001:2022, GDPR, DPDP Act and other similar standards and frameworks

  • Manage internal and external audits, including coordination with auditors, evidence collection, and remediation of findings.

  • Drive IT risk assessments, vendor risk management, and corrective action plans.

  • Collaborate with IT, security, and product teams to ensure operational practices meet compliance requirements.

Skills & Qualifications Required

  • 1+ years of experience in IT Audit, IT Risk, GRC, or Information Security.

  • Strong understanding of IT general controls, security operations, and data protection requirements.

  • Experience with IT audit management, evidence collection, and control testing.

  • Experience with end to end Third-party risk management including tiered vendor reviews, security questionnaires, risk scoring, and ongoing monitoring.

  • Hands-on knowledge of NIST CSF, NIST SP 800-53 and ISO 27001.

  • Knowledge of Cloud fundamentals (AWS), SaaS models, and modern infrastructure

  • Excellent communication, documentation, and stakeholder management skills.

  • Strong analytical and problem-solving abilities.

  • B.E / B.Tech - IT /CS



More Info

Key Skills

ongoing monitoring

NIST CSF

security questionnaires

DPDP Act

Cloud fundamentals

risk scoring

Third-party risk management

NIST SP 800-53

IT audit management

SaaS models

modern infrastructure

About Company

Similar Jobs

3-5 yrs
Bengaluru, India
Skills:
Pci DssIso 27001Internal AuditRisk MitigationVendor AssessmentThird-Party Risk Management
2-4 yrs
Bengaluru, India
Skills:
control testing GdprIso 27001AWSevidence collectionongoing monitoringNIST CSFsecurity questionnairesDPDP ActCloud fundamentalsrisk scoringThird-party risk managementVendor Risk ManagementNIST SP 800-53IT audit managementSaaS modelsmodern infrastructureTPRM
2-4 yrs
Bengaluru, India
Skills:
GdprHipaaJiraMicrosoft 365Iso 27001ConfluenceSalesforceNIST CSFAI-assisted response toolingCisaSOC 2GCP security conceptsISO 27001 Foundation or Lead ImplementerCompTIA Security+DORA
2-4 yrs
Bengaluru, India
Skills:
IsmsIso 27001RBI Master DirectionInternal AuditsnistSOC 2risk assessments
3-5 yrs
Bengaluru, India
Skills:
risk registers Iso 27001automationGrcAI toolsthird-party risk managementnistSOC 2risk assessments