Analyst / Senior Analyst — Governance, Risk & Compliance (GRC)

NMT Security

Dadri

On-site

INR 700,000 - 1,400,000

Full time

15 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

NMT Security, a product-based startup building an AI-native automation platform for audit readiness, is hiring a GRC professional. You will own controls, evidence, and audit cycles end to end, translating regulatory demands into practical platform capabilities.

You will implement ISO 27001, run RBI ITGRC and SOC 2 readiness, handle data privacy (DPDPA), and collaborate with product and engineering to automate control logic, with a fast-moving startup mindset.

Qualifications

  • 1–3 years hands-on GRC, information security compliance, or IT audits.
  • Familiarity with RBI ITGRC and regulatory guidelines for banks/fintech.
  • Experience with ISO 27001 implementation, internal audits, or audit support.

Responsibilities

  • Own controls, evidence, and audit cycles end to end.
  • Map regulatory requirements to internal controls and policies.
  • Collaborate with product/engineering to automate control data in the platform.
  • Prepare audit artifacts and respond to customer security questionnaires.

Skills

GRC
InfoSec
IT Audit

Job description

We are a product-based startup building an AI-native automation platform for audit and assessment readiness. We are hiring a GRC professional who can operate across two fronts: keeping our own compliance posture audit-ready, and bringing real-world GRC judgement into how the product is built.

This is a hands-on role. You will own controls, evidence, and audit cycles end to end rather than sitting in a review layer above them. If you want to move beyond checklist compliance and understand how controls are designed, mapped, and automated, this role is built for that.

What you'll do
Framework implementation and audit readiness
  • Implement and maintain the ISO 27001 ISMS — risk assessment, SoA, internal audits, management review, and surveillance/recertification support.
  • Run SOC 2 Type II readiness and the observation period: control design, evidence cadence, sampling, exception tracking, and auditor coordination.
  • Prepare and maintain audit artefacts so that every control has a defensible, repeatable evidence trail.
RBI and regulated-sector compliance
  • Support ITGRC obligations under the RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices, and related circulars (Cyber Security Framework, Outsourcing of IT Services, IT Examination / CSITE expectations, System Audit Reports).
  • Map regulatory clauses to internal controls and help customers and internal teams interpret what a requirement actually demands in practice.
  • Track regulatory changes and translate them into control and policy updates.
Data privacy
  • Support DPDPA implementation: consent and notice flows, data principal rights handling, data inventory and mapping, retention, breach notification readiness.
  • Assist with privacy impact assessments and third-party/processor due diligence.
Risk and control operations
  • Maintain the risk register: identification, scoring, treatment plans, and follow-through on remediation owners and timelines.
  • Run vendor risk assessments and periodic reviews.
  • Draft and maintain policies, standards, and procedures; keep them versioned, approved, and actually usable.
  • Handle customer security questionnaires, RFP security sections, and due-diligence requests.
  • Work with product and engineering to turn control logic, framework mappings, and evidence requirements into platform capability.
  • Give practical feedback on where automation helps and where auditor judgement is still required.
What we're looking for
  • 1–3 years of hands-on GRC, information security compliance, or IT audit experience.
  • Working knowledge ofRBI ITGRC and regulatory guidelinesapplicable to banks, NBFCs, or fintechs.
  • Practical experience withISO 27001(implementation, internal audit, or audit support).
  • Exposure to a fullSOC 2 Type IIcycle — readiness, evidence collection, or auditor interaction.
  • Familiarity withDPDPAand its operational implications.
  • Ability to read a control requirement and independently decide what evidence would satisfy an auditor.
  • Clear written communication — policies, assessment reports, and customer responses are a large part of the job.
  • Comfort working in a fast-moving startup where scope shifts and process is something you help build.
Good to have
  • Exposure toNIST CSF,GDPR,HIPAA, orPCI-DSS.
  • Certifications such asISO 27001 Lead Auditor / Lead Implementer, or a privacy certification (CIPP/E, CIPM, DCPP, CDPSE). ISACA certifications (CISA, CRISC) are also valued.
  • Experience with GRC or compliance automation tooling.
  • Experience supporting audits in a cloud environment (AWS/Azure/GCP) and understanding of cloud security controls.
  • Prior work in a banking, fintech, or SaaS environment serving regulated customers.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Specialist
GRC Specialist

Keka Technologies Private Limited • Ernakulam

On-site
INR 1,200,000 - 1,800,000
Senior GRC Engineer
Senior GRC Engineer

Razorpay • Bengaluru

On-site
INR 1,500,000 - 2,100,000
GRC Analyst
GRC Analyst

AiVantage Inc (Global) • Ahmedabad District

On-site
INR 800,000 - 1,200,000
GRC Analyst
GRC Analyst

Exotel • Bengaluru

On-site
INR 800,000 - 1,200,000
GRC Analyst
GRC Analyst

Exotel Techcom Pvt Ltd • Bengaluru

On-site
INR 600,000 - 900,000
Senior GRC Engineer
Senior GRC Engineer

Qualys • Maharashtra

On-site
INR 4,000,000 - 8,000,000
GRC Lead / Security Compliance Lead
GRC Lead / Security Compliance Lead

Gnani Innovations Private Limited. • India

On-site
INR 350,000 - 600,000
Security Compliance & GRC Lead
Security Compliance & GRC Lead

Cybrilla • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Compliance Analyst
Compliance Analyst

INTECH Creative Services Pvt. Ltd. • Mumbai, Navi Mumbai

On-site
INR 900,000 - 1,500,000
Senior GRC Analyst
Senior GRC Analyst

Exotel • Bengaluru

On-site
INR 1,200,000 - 1,800,000