Governance, Risk & Compliance (GRC) Specialist

Guideline Inc

Pune District

On-site

INR 2,250,000 - 2,750,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Travel up to 10%
US shift

Job summary

Guideline Inc is seeking an experienced Governance, Risk & Compliance (GRC) Specialist in Pune to enhance information security, risk, and compliance across the organization. The role focuses on managing ISO 27001, ISO 42001, and SOC 2 programs, audits, risk assessments, and policy governance, working with auditors, clients, vendors, and internal teams.

The ideal candidate has 5+ years in information security/GRC, with ISO 27001 or SOC 2 audit experience, and strong policy-writing skills.

Qualifications

  • 5+ years in Information Security, GRC, IT Audit, Risk, or Compliance.
  • 2+ years in ISO 27001 or SOC 2 audits/certifications.
  • 2+ years in vendor/third-party risk assessments.
  • 2+ years in developing information security policies and procedures.

Responsibilities

  • Manage ISO 27001, ISO 42001, and SOC 2 compliance and audit activities.
  • Prepare audit documentation and coordinate with external auditors.
  • Develop and maintain information security policies, procedures, standards, and controls.
  • Maintain the organization's risk register and track risk mitigation activities.
  • Conduct vendor and third-party security risk assessments.
  • Review vendor security documents, including SOC 2 reports and penetration testing reports.
  • Complete client security questionnaires and security due diligence assessments.
  • Coordinate compliance activities across different offices and business units.

Skills

Information Security
GRC
IT Audit
Risk Assessment
Policy Writing
Stakeholder Management
Audit Coordination

Education

Bachelor's degree in information security
Master's degree preferred

Tools

GRC Platforms
Audit Tools

Job description

We are Hiring for Governance, Risk & Compliance (GRC) Specialist

Location: Pune

Department: Information Technology – Information Security

Experience: 5+ Years

CTC: Up to ₹25 LPA

Reporting To: Chief Information Security Officer (CISO)

Travel: Up to 10%

Shift: US Shift

About the Role

We are looking for an experienced GRC Specialist to manage and strengthen the organization's information security, risk, and compliance activities. The person will be responsible for managing ISO 27001, ISO 42001, and SOC 2 compliance, supporting audits, conducting risk assessments, managing vendor security assessments, maintaining security policies, and responding to client security questionnaires. The role will also support cybersecurity and AI governance initiatives and involve regular interaction with auditors, clients, vendors, and internal teams.

Key Responsibilities
  • Manage ISO 27001, ISO 42001, and SOC 2 compliance and audit activities.
  • Prepare audit documentation and evidence and coordinate with external auditors.
  • Develop and maintain information security policies, procedures, standards, and controls.
  • Maintain the organization's risk register and track risk mitigation activities.
  • Conduct vendor and third-party security risk assessments.
  • Review vendor security documents, including SOC 2 reports and penetration testing reports.
  • Complete client security questionnaires and security due diligence assessments.
  • Manage compliance activities using GRC and compliance management tools.
  • Monitor security frameworks and regulatory requirements such as NIST CSF, NIST RMF, and GLBA.
  • Support security audits, gap assessments, evidence collection, and closure of audit findings.
  • Manage security awareness training, phishing simulations, and policy attestations.
  • Support cybersecurity and AI governance projects, including gap assessments and documentation.
  • Coordinate compliance activities across different offices and business units.
  • Work with clients, auditors, vendors, CISO, and internal teams to address security and compliance requirements.
Required Experience
  • 5+ years of experience in Information Security, GRC, IT Audit, Risk, or Compliance.
  • At least 2 years of experience managing ISO 27001 or SOC 2 audits/certifications.
  • At least 2 years of experience in vendor/third-party risk assessments.
  • At least 2 years of experience developing information security policies and procedures.
  • Good knowledge of ISO 27001, SOC 2, NIST CSF, NIST RMF, and GLBA.
  • Experience using GRC or compliance management platforms.
  • Experience working with clients, auditors, vendors, and internal stakeholders.
  • Experience in financial services, banking, mortgage, or other regulated industries is preferred.
Preferred Experience
  • Hands‑on experience with ISO 42001 and AI Governance.
  • Understanding of AI risk management and compliance frameworks.
  • Experience administering GRC/compliance automation platforms.
  • Experience supporting cybersecurity or AI governance advisory projects.
Education
  • Bachelor's degree in information security, Computer Science, IT, or a related field.
  • Master's degree is preferred.
Preferred Certifications

Candidates with any of the following certifications will be preferred: CISSP CISA CRISC ISO 27001 Lead Auditor ISO 27001 Lead Implementer 001 Lead Auditor / Lead Implementer

Key Skills
  • Strong knowledge of Information Security and GRC.
  • Good understanding of security frameworks and compliance requirements.
  • Ability to convert security requirements into practical controls and documentation.
  • Strong policy writing and documentation skills.
  • Good risk assessment and analytical skills.
  • Strong communication and presentation skills.
  • Good stakeholder management skills.
  • Ability to manage multiple audits, assessments, and deadlines.
  • Ability to work independently and take ownership of tasks.
  • Strong understanding of a risk-based approach to information security and compliance.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

844 Altera Semiconductor Technology India Pvt. Ltd. • Bengaluru

On-site
INR 2,000,000 - 3,000,000
GRC Consultant @ Mumbai
GRC Consultant @ Mumbai

Quess IT Solutions • Mumbai

On-site
INR 1,800,000 - 2,400,000
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

Altera • Bengaluru

On-site
INR 3,000,000 - 4,500,000
GRC Analyst
GRC Analyst

AiVantage Inc (Global) • Ahmedabad District

On-site
INR 800,000 - 1,200,000
Cyber Security GRC Consultant @ Mumbai
Cyber Security GRC Consultant @ Mumbai

Quess IT Solutions • Mumbai

On-site
INR 1,600,000 - 2,800,000
Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

Power Bridge • Arishinakunte

On-site
INR 1,200,000 - 2,400,000
Health insurance
Long-term savings plan with employer’匹
Professional development opportunities
GRC Manager - Cyber
GRC Manager - Cyber

Cubical Operations LLP • Chennai District

On-site
INR 800,000 - 1,200,000
GRC Analyst
GRC Analyst

Soffit Infrastructure Services (P) Ltd • Ernakulam

On-site
INR 800,000 - 1,200,000
Senior GRC Analyst
Senior GRC Analyst

Litmos • India

On-site
INR 2,400,000 - 3,200,000
Product GRC Consultant
Product GRC Consultant

CyRAACS™ • Bengaluru

On-site
INR 600,000 - 1,200,000