Padmi

Governance Risk Compliance Analyst

ChennaiPosted 2 months ago
CybersecuritySeniorFull Time; Regular
Apply at TI Steps

Opens the source posting on shine.com

Source description

About the role

View original

Job Summary We are seeking a detail-oriented Governance, Risk & Compliance (GRC) Analyst to support the organizations information security governance, risk management, and compliance programs. The role involves performing risk assessments, supporting security audits, maintaining compliance with industry standards, and ensuring that security policies and controls are effectively implemented and monitored. The ideal candidate should have strong knowledge of security frameworks, risk assessment methodologies, compliance requirements, and audit processes. Key Responsibilities Governance & Policy Management Develop, review, and maintain information security policies, standards, and procedures. Ensure alignment of security policies with organizational goals and regulatory requirements. Support implementation of governance frameworks across IT and business functions. Assist in security awareness and policy communication programs. Risk Management Conduct information security risk assessments across infrastructure, applications, and cloud environments. Identify, evaluate, and document security risks, threats, and vulnerabilities. Maintain and update risk registers and track mitigation plans. Work with technical teams to ensure timely risk remediation and closure. Compliance & Audit Support Support internal and external audits (ISO 27001, SOC 2, PCI-DSS, etc.). Gather and maintain audit evidence and compliance documentation. Track compliance gaps and coordinate remediation efforts. Assist in certification and surveillance audits. Control Assessment & Monitoring Evaluate security controls and ensure their effectiveness. Perform control testing and gap analysis against security frameworks. Support continuous monitoring of compliance posture. Assist in thirdparty/vendor risk assessments. Reporting & Documentation Prepare risk and compliance reports for management and stakeholders. Maintain dashboards for risk posture, compliance status, and audit findings.Document security processes, findings, and remediation activities. Support KPI/KRI tracking for governance and compliance metrics. Required Qualifications Bachelors degree in Information Security, Cybersecurity, Computer Science, Information Technology, or related field. 25 years of experience in GRC, Information Security, Risk Management, or Compliance roles. Strong understanding of information security principles and governance frameworks. Experience conducting risk assessments and supporting audits. Technical Skills & Knowledge Security & Compliance Frameworks ISO 27001 / ISO 27002 NIST Cybersecurity Framework CIS Controls SOC 2 PCIDSS GDPR (preferred) IT Act / local regulatory compliance (as applicable) Risk Management Risk identification, analysis, and mitigation Risk registers and treatment plans Qualitative and quantitative risk assessment methodologies Audit & Compliance Tools GRC tools (ServiceNow GRC, Archer, or equivalent preferred) Microsoft Excel / dashboards for reporting ITSM tools (ServiceNow, Jira) Security Domains (basic understanding) Network Security Cloud Security (AWS/Azure/GCP basics) IAM concepts Vulnerability Management Incident Management lifecycle Preferred Skills Experience with ISO 27001 implementation or certification support. Familiarity with vendor risk management and thirdparty assessments. Basic understanding of cloud security controls. Knowledge of security metrics (KPIs/KRIs) and reporting dashboards. Exposure to automation in GRC reporting (Power BI or similar tools). Basic scripting knowledge (optional). Preferred Certifications ISO 27001 Lead Implementer / Lead Auditor CompTIA Security+ Certified Information Systems Security Professional (CISSP Associate level acceptable) Certified in Risk and Information Systems Control (CRISC) Certified Information Security Manager (CISM) Certified Internal Auditor (CIA) (optional) SOC 2 / compliancerelated training certifications Key Competencies Risk Assessment & Management Governance & Policy Development Compliance & Audit ManagementAnalytical Thinking Documentation & Reporting Stakeholder Communication Attention to Detail Problem Solving Regulatory Awareness Key Performance Indicators (KPIs) Accuracy and completeness of risk assessments. Timely closure of audit findings and compliance gaps. Reduction in unresolved security risks. Compliance adherence across frameworks (ISO/SOC2/PCI-DSS). Quality of governance documentation and reporting. Effectiveness of risk mitigation tracking Job Summary We are seeking a detail-oriented Governance, Risk & Compliance (GRC) Analyst to support the organizations information security governance, risk management, and compliance programs. The role involves performing risk assessments, supporting security audits, maintaining compliance with industry standards, and ensuring that security policies and controls are effectively implemented and monitored. The ideal candidate should have strong knowledge of security frameworks

One address, no account. We’ll tell you when matching roles go live.

More at TI Steps

Related open roles

View all roles