Governance, Risk & Compliance Analyst

Hero Fincorp

India

On-site

INR 1,800,000 - 2,600,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Hero Fincorp is seeking a seasoned Information Security Governance, Risk and Compliance (GRC) professional to lead policy and procedure management, audits, and regulatory alignment across the organization.

You will maintain a centralized repository of governance documents, drive remediation plans, conduct risk assessments, and oversee third-party security reviews, while delivering governance dashboards to leadership.

Qualifications

  • 5 years of relevant experience in Information Security Governance, Risk, and Compliance (GRC).
  • Strong knowledge of regulatory frameworks (ISO 27001, GDPR, RBI).
  • Hands-on experience in facilitating audits/assessments and managing security documentation.
  • Experience in risk management and vendor security assessments.
  • Strong presentation, communication and stakeholder management skills.

Responsibilities

  • Create, review, and periodically update IT and Information Security policies, procedures, and standards.
  • Coordinate with stakeholders to ensure timely approval and alignment of policies with regulatory and industry best practices.
  • Maintain a centralized repository of all policies, procedures, and governance documents. Audits, Assessments and Compliances
  • Facilitate internal, external, and regulatory audits/assessments, including audit kick-off, data collection, evidence validation, and closure discussions.
  • Respond to auditor/assessor queries, ensuring timely and accurate evidence submission.
  • Maintain a secure repository of all documents and related artifact.
  • Drive closure of open observations/issues within defined timelines.
  • Assist in conducting Information Security Risk Assessments in line with organizational, regulatory, and industry requirements.
  • Maintain and update the risk register, ensuring timely closure of action items arising from identified risks.
  • Conduct third-party/vendor risk assessments, prepare assessment reports, and drive remediation plans with vendors.
  • Conduct induction sessions on Information Security for new joiners.
  • Organize periodic awareness training including targeted training as and when required.
  • Develop and deliver ongoing security awareness initiatives across the organization.
  • Prepare and present monthly Information Security review decks and tracking status of action items.
  • Track closure of identified gaps from periodic access reviews.
  • Review and assess Master Service Agreements (MSAs) and vendor contracts for compliance with Information Security requirements.

Skills

Detail-oriented
Analytical skills
Stakeholder management
Communication
Independent working

Education

Bachelor's degree in information technology or computer science

Job description

Key Responsibilities Policy & Procedure Management


  • Create, review, and periodically update IT and Information Security policies, procedures, and standards.
  • Coordinate with stakeholders to ensure timely approval and alignment of policies with regulatory and industry best practices.
  • Maintain a centralized repository of all policies, procedures, and governance documents. Audits, Assessments and Compliances
  • Facilitate internal, external, and regulatory audits/assessments, including audit kick-off, data collection, evidence validation, and closure discussions.
  • Respond to auditor/assessor queries, ensuring timely and accurate evidence submission.
  • Maintain a secure repository of all documents and related artifact.
  • Drive closure of open observations/issues within defined timelines. Risk Management
  • Assist in conducting Information Security Risk Assessments in line with organizational, regulatory, and industry requirements.
  • Maintain and update the risk register, ensuring timely closure of action items arising from identified risks.
  • Conduct third-party/vendor risk assessments, prepare assessment reports, and drive remediation plans with vendors. Training & Awareness
  • Conduct induction sessions on Information Security for new joiners.
  • Organize periodic awareness training including targeted training as and when required.
  • Develop and deliver ongoing security awareness initiatives across the organization. Governance & Monitoring
  • Prepare and present monthly Information Security review decks and tracking status of action items.
  • Track closure of identified gaps from periodic access reviews.
  • Review and assess Master Service Agreements (MSAs) and vendor contracts for compliance with Information Security requirements.

Conduct periodic meetings to monitor end-user security posture and follow-ups on remediation plans.


Eligibility Criteria for the Job

Education

  • Bachelors degree in information technology, Computer Science, or related field.
  • Relevant certifications preferred (e.g. CISA, CISM, ISO 27001 LA/LI, CRISC).

Experience

  • 5 years of relevant experience in Information Security Governance, Risk, and Compliance (GRC).
  • Strong knowledge of regulatory frameworks (e.g. ISO 27001, GDPR, RBI, etc)
  • Hands-on experience in facilitating audits/assessments and managing security documentation.
  • Experience in risk management and vendor security assessments.
  • Strong presentation, communication and stakeholder management skills.

Skills & Competencies

  • Detail-oriented with strong analytical skills.
  • Ability to work independently and collaboratively in a cross-functional environment.
  • Proactive in driving closure of issues and ensuring compliance readiness.
  • Strong commitment to fostering a culture of security awareness within the organization.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Analyst
Senior GRC Analyst

Exotel Techcom Pvt Ltd • Bengaluru

On-site
INR 800,000 - 1,400,000
Governance, Risk and Compliance (GRC) Specialist
Governance, Risk and Compliance (GRC) Specialist

Career Guideline • Pune District

On-site
INR 1,500,000 - 2,500,000
Senior Information Security Analyst-(Risk and Regulatory Tech Complainance)
Senior Information Security Analyst-(Risk and Regulatory Tech Complainance)

KreditBee • Bengaluru

On-site
INR 800,000 - 1,500,000
Info/Security - Analyst
Info/Security - Analyst

Ascendion Engineering • Hyderabad

Hybrid
INR 2,500,000 - 3,800,000
Manager IT Governance & Compliance
Manager IT Governance & Compliance

Sabpaisa • Delhi

On-site
INR 1,500,000 - 2,500,000
Cybersecurity Specialist – Governance, Risk & Compliance (GRC)
Cybersecurity Specialist – Governance, Risk & Compliance (GRC)

TalaKunchi Networks Pvt Ltd • Mumbai

On-site
INR 800,000 - 1,200,000
Opportunity to shape InfoSec practices
Work on cutting-edge cybersecurity initiatives
Be part of a forward-thinking team
GRC Analyst
GRC Analyst

Soffit Infrastructure Services (P) Ltd • Ernakulam

On-site
INR 800,000 - 1,200,000
Information Security GRC Analyst
Information Security GRC Analyst

Perydot • Mumbai

On-site
INR 600,000 - 1,000,000
IT Risk Control Manager
IT Risk Control Manager

Futops • Mumbai

On-site
INR 1,200,000 - 1,800,000
Senior Manager - Information Security And Governance
Senior Manager - Information Security And Governance

HDB Financial Services Ltd. • Hyderabad

On-site
INR 1,000,000 - 1,500,000