Source description
About the role
As an experienced IT Governance, Risk & Compliance (GRC) Specialist, your role will involve driving information security, compliance, audit readiness, and risk management initiatives throughout the organization. You will work closely with IT, Security, Product, and Business teams to enhance governance practices, manage audits, mitigate risks, and support continuous compliance improvements. Key Responsibilities: - Manage IT compliance and security governance programs aligned with NIST CSF 2.0, ISO 27001:2022, GDPR, DPDP Act, and related frameworks. - Coordinate internal and external audits, including evidence collection, auditor engagement, remediation tracking, and closure of findings. - Conduct IT risk assessments and contribute to enterprise risk management initiatives. - Oversee Third-Party Risk Management (TPRM) tasks, such as vendor assessments, security questionnaires, risk scoring, and ongoing monitoring. - Assist in developing, implementing, and enhancing security controls, policies, and governance processes. - Collaborate with various stakeholders to ensure compliance requirements are integrated into operational processes effectively. - Monitor compliance metrics, risks, audit observations, and remediation activities. - Support continuous improvement efforts related to information security, risk management, and regulatory compliance. Qualifications Required: - 5+ years of experience in IT Audit, IT Risk, Information Security, Governance Risk & Compliance (GRC), or related fields. - Strong understanding of IT General Controls (ITGC), security controls, compliance programs, and data protection requirements. - Experience in managing internal and external audits, control testing, audit evidence collection, and remediation tracking. - Hands-on experience with Third-Party Risk Management (TPRM), vendor assessments, security reviews, and risk evaluation processes. - Knowledge of NIST CSF 2.0, NIST SP 800-53, ISO 27001:2022, GDPR, and DPDP Act. - Familiarity with cloud environments (preferably AWS), SaaS platforms, and modern technology architectures. - Excellent stakeholder management, communication, and documentation skills. - Strong analytical, risk assessment, and problem-solving capabilities. - B.E. / B.Tech in Computer Science, Information Technology, or related discipline. The company offers an opportunity to work on enterprise-wide Information Security, Compliance, and Risk Management initiatives. You will gain hands-on exposure to NIST CSF 2.0, ISO 27001:2022, GDPR, DPDP Act, and Third-Party Risk Management programs. Additionally, you will collaborate with Security, Product, Engineering, and Compliance leadership teams in a high-impact role with visibility across audit, governance, and risk functions. The work environment is flexible and fast-paced, with the potential for contract extension based on performance and business requirements. As an experienced IT Governance, Risk & Compliance (GRC) Specialist, your role will involve driving information security, compliance, audit readiness, and risk management initiatives throughout the organization. You will work closely with IT, Security, Product, and Business teams to enhance governance practices, manage audits, mitigate risks, and support continuous compliance improvements. Key Responsibilities: - Manage IT compliance and security governance programs aligned with NIST CSF 2.0, ISO 27001:2022, GDPR, DPDP Act, and related frameworks. - Coordinate internal and external audits, including evidence collection, auditor engagement, remediation tracking, and closure of findings. - Conduct IT risk assessments and contribute to enterprise risk management initiatives. - Oversee Third-Party Risk Management (TPRM) tasks, such as vendor assessments, security questionnaires, risk scoring, and ongoing monitoring. - Assist in developing, implementing, and enhancing security controls, policies, and governance processes. - Collaborate with various stakeholders to ensure compliance requirements are integrated into operational processes effectively. - Monitor compliance metrics, risks, audit observations, and remediation activities. - Support continuous improvement efforts related to information security, risk management, and regulatory compliance. Qualifications Required: - 5+ years of experience in IT Audit, IT Risk, Information Security, Governance Risk & Compliance (GRC), or related fields. - Strong understanding of IT General Controls (ITGC), security controls, compliance programs, and data protection requirements. - Experience in managing internal and external audits, control testing, audit evidence collection, and remediation tracking. - Hands-on experience with Third-Party Risk Management (TPRM), vendor assessments, security reviews, and risk evaluation processes. - Knowledge of NIST CSF 2.0, NIST SP 800-53, ISO 27001:2022, GDPR, and DPDP Act. - Familiarity with cloud environments (preferably AWS), SaaS platforms, and modern technology archi
More at Neorealm
Related open roles
NET Developer (Fresher) - Bengaluru Only, 100% work from office
Bangalore
.NET Developer - 1 + Yrs of experience - Bengaluru Only
Bangalore
Full Stack Developer 4-7 Years Experience (Bengaluru)
Bangalore
3 To 8 Yrs Exp - Java + Aws Developer (Mumbai)
Mumbai
8+ Yrs Exp - Banking Enterprise Architect Credit Card Platforms
Mumbai