
Search by job, company or skills
We are looking for a highly skilled IT Governance, Risk and Compliance (GRC) to manage information security and compliance initiatives by supporting our NIST CSF, ISO 27001, GDPR, DPDP Act, TPRM and other related programs, while driving risk management, audit readiness and continuous process improvement.
Manage IT Compliance programs and support IT/ Security initiatives, including NIST CSF 2.0, ISO 27001:2022, GDPR, DPDP Act and other similar standards and frameworks
Manage internal and external audits, including coordination with auditors, evidence collection, and remediation of findings.
Drive IT risk assessments, vendor risk management, and corrective action plans.
Collaborate with IT, security, and product teams to ensure operational practices meet compliance requirements.
5+ years of experience in IT Audit, IT Risk, GRC, or Information Security.
Strong understanding of IT general controls, security operations, and data protection requirements.
Experience with IT audit management, evidence collection, and control testing.
Experience with end to end Third-party risk management including tiered vendor reviews, security questionnaires, risk scoring, and ongoing monitoring.
Hands-on knowledge of NIST CSF, NIST SP 800-53 and ISO 27001.
Knowledge of Cloud fundamentals (AWS), SaaS models, and modern infrastructure
Excellent communication, documentation, and stakeholder management skills.
Strong analytical and problem-solving abilities.
B.E / B.Tech - IT /CS
Prior security engineering or application security background before moving into GRC
Experience in a regulated sector (Banking, Fintech, Insurance) or Big 4 Audit (IT Risk advisory) is highly preferred.
Exotel was started by Shivakumar Ganesan in 2011. Shivakumar's previous venture, Roopit, needed a simple automated call center solution for which he built an in-house product, and eventually it became a standalone company in the form of Exotel.Exotel picked up a Rs. 25 million (approximately US$500,000 funding from Mumbai Angels and Blume Ventures in March 2012
Job ID: 148159485
Skills:
control testing , Gdpr, Data Protection, Iso 27001, IT General Controls, Grc, AWS, It Audit, evidence collection, Security Operations, IT Risk, security questionnaires, NIST CSF, DPDP Act, Cloud fundamentals, risk scoring, Third-party risk management, NIST SP 800-53, IT audit management, SaaS models, vendor reviews
Skills:
Pci Dss, Gdpr, Iso 27001, Enterprise IT security risk policies and controls, SOC 2, Risk mitigation strategies, CCPA, Business Continuity and Disaster Recovery Plans, Risk Assessment, NIST 800-171, Internal and external audits, Audit board
Skills:
Google Cloud, Iso 27001, Pci, Azure, AWS, Iso, MLPS, Cisa, FedRAMP, NIST 800-171, PCI ISA, Cissp, IRAP, NIST 800-53
Skills:
Gdpr, Data Protection, Incident Response, CPRA, Security Architecture, AI Governance, ISO IEC 27001, ISO IEC 42001, CCPA, CMMC
Skills:
Power Bi, Hipaa, Jira, Iso 27001, Grc, Data Analytics, Cism, Cisa, SOC2, Risk Management, Cissp, cgeit, CRISC
We don’t charge any money for job offers