Padmi

Grc Analyst

Hyderabad · HybridPosted 1 month ago
CybersecurityMid-level
Apply at Brace Infotech

Opens the source posting on naukri.com

Source description

About the role

View original

Role & responsibilities JOB DESCRIPTION 1. We are looking for a detail-oriented and proactive GRC professional with hands-on experience in SOC 2 Type 2, NIST CSF,/NIST SP 800-53/CIS/GDPR/HIPAA, ISO 27001 controls and Data Protection. JOB REQUIREMENTS 2. Lead and support the implementation, maintenance, and continuous improvement of information security compliance programs, specifically focusing on SOC 2 Type 1 and Type 2, NIST Cybersecurity Framework (CSF), NIST Special Publications (SP 800-53), and ISO 27001. 3. Develop, review, and update security policies, procedures, and guidelines to align with relevant compliance frameworks and regulatory requirements. 4. Conduct risk assessment, coordinating with all stakeholders against SOC 2, NIST, and ISO 27001 controls to identify areas for improvement and ensure audit readiness. 5. Prepare and compile documentation, evidence, and responses for audit requests efficiently and accurately 6. Contribute to risk assessments and business impact analysis. 7. Maintain comprehensive documentation of security controls, compliance activities, and remediation plans. 8. Prepare regular reports on compliance status, key metrics, and areas of concern for management and stakeholders. 9. Perform comprehensive third-party risk assessments to evaluate vendor compliance with information security policies. 10. Develop and maintain TPRM processes to monitor and mitigate risks associated with external vendors. 11. Ensure effective communication and documentation of third-party risk assessments. 12. Assist in drafting and updating organisational policies and procedures for governance and compliance.

One address, no account. We’ll tell you when matching roles go live.

Grc Analyst at Brace Infotech · Padmi