Search Jobs

Search by job, company or skills

GRC Associate

GRC Associate

hireologist
Early Applicant
  • Posted 19 hours ago
  • Be among the first 10 applicants

Job Description

GRC Associate/ Information Security Analyst

Location: Bangalore

Experience:2–3 Years

About the Role

We are looking for a GRC Associate with 2–3 years of relevant experience in Governance, Risk & Compliance, Information Security, IT Risk, Internal Controls, or related areas.

The candidate will support GRC assessments, audits, compliance reviews, risk assessments, gap assessments, documentation, audit readiness, and client coordination. The role involves mapping regulatory and security requirements to organizational controls, identifying gaps, and supporting clients in achieving compliance objectives.

Key Responsibilities

  • Support GRC assessments, audits, and compliance engagements.
  • Perform risk, control, and gap assessments against applicable frameworks.
  • Review policies, procedures, processes, and control documentation.
  • Identify control gaps and compliance issues and recommend corrective actions.
  • Prepare Risk Registers, Control Matrices, Statement of Applicability (SoA), policies, procedures, and assessment reports.
  • Support implementation and assessment of information security and compliance controls.
  • Coordinate with client stakeholders for evidence collection and control validation.
  • Review evidence for completeness, accuracy, and compliance.
  • Track findings, observations, corrective actions, and closure status.
  • Support audit preparation and client readiness activities.
  • Participate in client meetings, discussions, and assessment walkthroughs.
  • Prepare clear and structured reports, findings, and recommendations.
  • Stay updated with relevant GRC frameworks, regulations, and industry practices.
  • Work with senior consultants/assessors to deliver projects within timelines.

Candidate Profile

  • 2–3 years of relevant experience in GRC, Risk, Compliance, or Information Security.
  • Strong understanding of GRC concepts and control frameworks.
  • Experience in risk and control assessments.
  • Ability to review and interpret policies, procedures, and evidence.
  • Strong documentation and report-writing skills.
  • Good analytical and problem-solving abilities.
  • Strong verbal and written communication skills.
  • Comfortable interacting with client stakeholders.
  • Ability to manage multiple tasks and meet deadlines.
  • Strong attention to detail.

Required Skills & Knowledge

  • ISO/IEC 27001
  • SOC 1 / SOC 2
  • PCI DSS
  • ISO 31000 / Risk Management
  • Privacy & Data Protection Frameworks
  • IT General Controls (ITGC)
  • Information Security Controls
  • Risk Assessment & Risk Treatment
  • Internal Controls
  • Business Continuity / Operational Resilience
  • Third-Party / Vendor Risk Management

Key Skills

Third-Party Vendor Risk Management

Privacy Data Protection Frameworks

SOC 2

IT General Controls (ITGC)

Information Security Controls

Risk Treatment

ISO 31000 Risk Management

Operational Resilience

ISO IEC 27001

About Company

Similar Jobs

2-4 yrs
Bengaluru, India
Skills:
Pci DssISO 31000 Risk ManagementRisk Assessment Risk TreatmentThird-Party Vendor Risk ManagementPrivacy Data Protection FrameworksSOC 1 SOC 2Internal ControlsISO IEC 27001Business Continuity Operational ResilienceInformation Security ControlsIT General Controls ITGC
4-6 yrs
Bengaluru, India
Skills:
smartsheet ADOIso 27001GrcIt ComplianceAzureAWSSharepointrisk managementSOC 2enterprise GRC toolsMS ProjectISO 27000 seriesnist