T
GRC consultant
T
- Posted 2 hours ago
- Be among the first 10 applicants
Job Description
Role: GRC Analyst/Consultant
Location: Mumbai
We are looking for a motivated and detail-oriented professional for the role of GRC (Governance, Risk & Compliance) Analyst/Consultant with minimum 3+ years of experience in Information Security, Risk Management, Compliance, ISMS implementation, and IT Audits.
The ideal candidate should have hands-on experience in security frameworks, regulatory compliance, risk assessments, vendor audits, and policy implementation.
Key Responsibilities:
- Implement and maintain Information Security Governance frameworks and compliance programs.
- Conduct ISMS implementation and audits aligned with standards such as ISO 27001, ISO 27017, ISO 27018, RBI, SEBI, CERT-In, and other regulatory requirements.
- Perform risk assessments, gap assessments, internal audits, and compliance reviews.
- Develop, review, and update security policies, SOPs, standards, and procedures.
- Conduct Vendor Risk Assessments and Third-Party Risk Management (TPRM) activities.
- Track audit observations, remediation activities, and closure of compliance gaps.
- Coordinate with internal teams including IT, Network, Infrastructure, Application, SOC, and Business teams for audit and compliance activities.
- Support cybersecurity governance initiatives, application security reviews, and cloud security assessments.
- Conduct awareness sessions and support organization-wide security compliance initiatives.
- Prepare audit reports, dashboards, management presentations, and risk reports.
- Ensure proper documentation and maintenance of compliance evidence.
Required Skills:
- Strong understanding of:
- ISO 27001 / ISMS
- Risk Assessment & Risk Treatment
- ITGC Controls
- Internal & External Audits
- Vendor Risk Management
- Security Compliance & Governance
- Application / Infrastructure Security Concepts
- Experience with regulatory frameworks such as RBI, SEBI, CERT-In, GDPR, etc. will be an added advantage.
- Good knowledge of cloud security and cybersecurity controls.
- Excellent communication, stakeholder management, and report-writing skills.
- Ability to manage multiple projects and coordinate with cross-functional teams.
Preferred Certifications:
- ISO 27001 Lead Auditor / Lead Implementer
- CISA
- CEH
- Any GRC or Cybersecurity certification
Experience:
- Minimum 3+ years of relevant experience in GRC / Information Security / Compliance / ISMS.
Qualification:
- Bachelor's degree in Computer Science, IT, Cyber Security, Electronics, or related field.
Location:
Mumbai
Preferred Candidate Profile:
- Candidate with experience in BFSI, IT Services, Consulting, or Cybersecurity domain preferred.
- Strong analytical and problem-solving abilities.
- Ability to work independently and manage client-facing engagements.


