
Search by job, company or skills

Fulcrum Digital is an agile and next-generation digital accelerating company providing digital transformation and technology services right from ideation to implementation. These services have applicability across a variety of industries, including banking & financial services, insurance, retail, higher education, food, healthcare, and manufacturing.
Job SummaryWe are seeking a detail-oriented and analytical GRC Analyst to support the organization's governance, risk management, and compliance initiatives. The ideal candidate will help identify risks, ensure regulatory compliance, support audit processes, and strengthen internal controls to protect the organization's assets and reputation.
Key ResponsibilitiesSupport development and maintenance of security policies, standards, and procedures
Ensure alignment with industry frameworks (e.g., ISO 27001, NIST, SOC 2)
Assist in policy awareness and training initiatives
Conduct risk assessments and maintain risk registers
Identify, analyze, and document security and operational risks
Track remediation plans and risk mitigation efforts
Support third-party/vendor risk assessments
Monitor compliance with regulatory and industry requirements (e.g., GDPR, HIPAA, PCI-DSS as applicable)
Assist with internal and external audits
Collect and maintain evidence for compliance reporting
Coordinate remediation of audit findings
Prepare risk and compliance reports for management
Maintain documentation of controls and audit artifacts
Track KPIs and KRIs
Bachelor's degree in Information Security, Cybersecurity, IT, Risk Management, or related field
2–5 years of experience in GRC, risk management, compliance, or IT audit
Knowledge of security frameworks (ISO 27001, NIST, SOC 2, etc.)
Understanding of regulatory requirements (GDPR, HIPAA, PCI-DSS, etc.)
Strong analytical and documentation skills
Mandatory - Certifications such as CISA, CRISC, CISM, ISO 27001 Lead Implementer/Auditor
Experience with GRC tools (e.g., Archer, ServiceNow GRC)
Experience working with cloud environments (Azure, AWS, GCP)
Knowledge of cybersecurity controls and risk methodologies
Risk assessment and analysis
Policy and control documentation
Audit coordination
Strong communication and stakeholder management
Attention to detail
Ability to work independently and manage multiple priorities
Full-time position
Hybrid/Remote (as applicable)
Cross-functional collaboration with IT, Security, Legal, and Business teams
Job ID: 149086305
Skills:
Pci Dss, Hipaa, Iso 27001, Csf, Cisa, DORA, NIST RMF, CRISC, SOC 2
Skills:
, Gdpr, Saas, Grc, Cloud Computing, AI Governance, Compliance Audits, ISO IEC 27001, Risk Management, CIS Controls, SOC 2, ISO 27701, CCPA, Security Policies, NIST CSF, It Audit, CSA CCM, Third-Party Risk Management, ISO IEC 42001, NIST AI RMF, NIST SP 800-53, CPRA
Skills:
Grc, Gdpr, Hipaa, Iso 27001, Policy and control documentation, Audit Coordination, PCI-DSS, nist, SOC 2, Risk assessment and analysis
Skills:
Gdpr, Saas, Information Security, Cloud Computing, Grc, It Audit, CPRA, CCSK, NIST CSF, CIS Controls, AI RMF, SOC 2, CCPA, Risk Management, NIST SP 800-53, NIST AI Risk Management Framework, EU AI Act, CSA CCM, ISO IEC 27001, ISO IEC 42001, CRISC, ISO 27701, ISO IEC 23894
Skills:
Iso 27001, It Operations, third-party risk assessments, Zscaler for Endpoint, DLP Policies, security control evaluations, KRI development, CIS Controls, gap analyses, SOC 2, cybersecurity awareness training, NIST CSF, cybersecurity best practices, cybersecurity policies, vendor security evaluations, cybersecurity reporting and metrics, risk assessments
We don’t charge any money for job offers