Governance, Risk and Compliance (GRC) Specialist

Career Guideline

Pune District

On-site

INR 1,500,000 - 2,500,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Career Guideline in Pune is seeking a Governance, Risk and Compliance Specialist to lead audit programs and regulatory alignment across information security. You will oversee ISO 27001, SOC 2, and AI governance activities, defining controls and evidence collection with cross-functional teams.

The role requires 5+ years in information security, strong knowledge of NIST frameworks and GLBA, and hands-on experience with GRC platforms. Pune-based office with growth potential.

Qualifications

  • 5+ years in Information Security, GRC, IT Audit, Risk, or Compliance.
  • Minimum 2 years managing ISO 27001 or SOC 2 audits/certifications.
  • Experience with vendor/third-party risk assessments.
  • Experience creating information security policies and procedures.

Responsibilities

  • Manage ISO 27001, ISO 42001, and SOC 2 audit activities.
  • Prepare audit evidence and coordinate testing with external auditors.
  • Create and maintain information security policies, procedures, standards, and controls.
  • Maintain the organization's risk register and track risk mitigation activities.
  • Conduct vendor and third-party security risk assessments.
  • Review vendor security documents such as SOC 2 reports and penetration testing reports.
  • Complete client security questionnaires and due diligence assessments.
  • Manage and track compliance activities using GRC/compliance platforms.
  • Monitor applicable security and regulatory requirements such as NIST CSF, NIST RMF, and GLBA.
  • Support security audits, evidence collection, gap assessments, and closure of audit findings.
  • Manage security awareness training, phishing simulations, and policy attestations.
  • Support cybersecurity and AI governance advisory projects, including gap analysis and documentation.
  • Coordinate compliance activities across different offices and business entities.
  • Work with clients, auditors, vendors, and internal teams to resolve security and compliance requirements.

Skills

ISO 27001
SOC 2
NIST CSF
NIST RMF
GLBA
GRC tools
Vendor risk assessment
Audit coordination
Policy development

Education

Bachelor's degree in Information Security / IT
Master's degree preferred

Tools

GRC platforms
SOC auditing tools

Job description

Were Hiring for Governance, Risk and Compliance (GRC) Specialist
Requirements
  • Location: Pune
  • Department: Information Technology Information Security
  • CTC: Up to 25 LPA
  • Experience: 5+ Years
  • Reporting To: Chief Information Security Officer (CISO)
  • Travel: Up to 10%
Key Responsibilities
  • Manage ISO 27001, ISO 42001, and SOC 2 audit and certification activities.
  • Prepare audit evidence, coordinate control testing, and work with external auditors.
  • Create and maintain information security policies, procedures, standards, and controls.
  • Maintain the organization's risk register and track risk mitigation activities.
  • Conduct vendor and third-party security risk assessments.
  • Review vendor security documents such as SOC 2 reports and penetration testing reports.
  • Complete client security questionnaires and due diligence assessments.
  • Manage and track compliance activities using GRC/compliance platforms.
  • Monitor applicable security and regulatory requirements such as NIST CSF, NIST RMF, and GLBA.
  • Support security audits, evidence collection, gap assessments, and closure of audit findings.
  • Manage security awareness training, phishing simulations, and policy attestations.
  • Support cybersecurity and AI governance advisory projects, including gap analysis and documentation.
  • Coordinate compliance activities across different offices and business entities.
  • Work with clients, auditors, vendors, and internal teams to resolve security and compliance requirements.
Required Experience
  • 5+ years of experience in Information Security, GRC, IT Audit, Risk, or Compliance.
  • Minimum 2 years of experience managing ISO 27001 or SOC 2 audits/certifications.
  • Minimum 2 years of experience in vendor/third-party risk assessments.
  • Minimum 2 years of experience creating information security policies and procedures.
  • Good understanding of ISO 27001, SOC 2, NIST CSF, NIST RMF, and GLBA.
  • Experience working with GRC or compliance management tools.
  • Experience communicating with clients, auditors, and vendors.
  • Experience in financial services, banking, mortgage, or other regulated industries is preferred.
Preferred Experience
  • Experience with ISO 42001 / AI Governance.
  • Experience with AI risk and compliance frameworks.
  • Experience administering GRC/compliance automation platforms.
Education
  • Bachelor's degree in Information Security, Computer Science, IT, or a related field.
  • Master's degree is preferred.
Certifications
  • Any of the following certifications would be preferred:
  • CISSP
  • CISA
  • CRISC
  • ISO 27001 Lead Auditor
  • ISO 27001 Lead Implementer
  • ISO 42001 Lead Auditor / Lead Implementer
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

844 Altera Semiconductor Technology India Pvt. Ltd. • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Senior GRC Analyst
Senior GRC Analyst

Exotel Techcom Pvt Ltd • Bengaluru

On-site
INR 800,000 - 1,400,000
GRC Analyst
GRC Analyst

Exotel Techcom Pvt Ltd • Bengaluru

On-site
INR 600,000 - 900,000
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

Altera • Bengaluru

On-site
INR 3,000,000 - 4,500,000
GRC Analyst
GRC Analyst

Exotel • Bengaluru

On-site
INR 800,000 - 1,200,000
Governance, Risk & Compliance Analyst
Governance, Risk & Compliance Analyst

Hero Fincorp • India

On-site
INR 1,800,000 - 2,600,000
GRC Manager - Cyber
GRC Manager - Cyber

Cubical Operations LLP • Chennai District

On-site
INR 800,000 - 1,200,000
GRC Analyst
GRC Analyst

Soffit Infrastructure Services (P) Ltd • Ernakulam

On-site
INR 800,000 - 1,200,000
Senior GRC Analyst
Senior GRC Analyst

Exotel • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Compliance Analyst
Compliance Analyst

INTECH Creative Services Pvt. Ltd. • Mumbai, Navi Mumbai

On-site
INR 900,000 - 1,500,000