Padmi

Senior Analyst ISMS Governance, Risk & Compliance (GRC)

MumbaiPosted 3 months ago
CybersecuritySeniorFull Time; Regular
Apply at Curapersonal Private Limited

Opens the source posting on shine.com

Source description

About the role

View original

Role Overview: As a Senior Analyst in ISMS Governance, Risk & Compliance (GRC) in Pune, you will be responsible for designing and managing Information Security Management System (ISMS) governance, risk, and compliance frameworks. Your role will involve ensuring ISO 27001:2022 compliance, supporting audits, managing risk assessments, and driving continuous improvement in security governance across the organization in alignment with regulatory and business requirements. Key Responsibilities: - Implement and manage ISMS governance aligned with ISO 27001:2022 standards - Conduct ISMS risk assessments and define key risk indicators (KRIs) - Support internal and external audits, ensuring compliance readiness - Develop and maintain ISMS policies, procedures, and documentation - Collaborate with cross-functional teams including security, legal, and business units Qualifications Required: - Strong understanding of ISMS governance, risk, and compliance frameworks - Experience with ISO 27001:2022 standards and audit processes - Knowledge of risk assessment methodologies and regulatory compliance - Strong documentation, reporting, and analytical skills - Experience in stakeholder management and cross-functional coordination Additional Details: Experience in regulated industries such as BFSI, healthcare, or IT services is preferred. Exposure to SOC1, SOC2, HITRUST, ISO 42001, or PCI DSS frameworks would be beneficial. ISO 27001 Lead Implementer / Lead Auditor certification is preferred. Experience in client audits, due diligence, and enterprise compliance programs would be an advantage. Role Overview: As a Senior Analyst in ISMS Governance, Risk & Compliance (GRC) in Pune, you will be responsible for designing and managing Information Security Management System (ISMS) governance, risk, and compliance frameworks. Your role will involve ensuring ISO 27001:2022 compliance, supporting audits, managing risk assessments, and driving continuous improvement in security governance across the organization in alignment with regulatory and business requirements. Key Responsibilities: - Implement and manage ISMS governance aligned with ISO 27001:2022 standards - Conduct ISMS risk assessments and define key risk indicators (KRIs) - Support internal and external audits, ensuring compliance readiness - Develop and maintain ISMS policies, procedures, and documentation - Collaborate with cross-functional teams including security, legal, and business units Qualifications Required: - Strong understanding of ISMS governance, risk, and compliance frameworks - Experience with ISO 27001:2022 standards and audit processes - Knowledge of risk assessment methodologies and regulatory compliance - Strong documentation, reporting, and analytical skills - Experience in stakeholder management and cross-functional coordination Additional Details: Experience in regulated industries such as BFSI, healthcare, or IT services is preferred. Exposure to SOC1, SOC2, HITRUST, ISO 42001, or PCI DSS frameworks would be beneficial. ISO 27001 Lead Implementer / Lead Auditor certification is preferred. Experience in client audits, due diligence, and enterprise compliance programs would be an advantage.

One address, no account. We’ll tell you when matching roles go live.

More at Curapersonal Private Limited

Related open roles

View all roles