GRC Analyst

AiVantage Inc (Global)

Ahmedabad District

On-site

INR 800,000 - 1,200,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

AiVantage Inc (Global) is looking for a GRC Analyst in India with 1–2 years of experience to support information security, governance, risk, and compliance activities. The role focuses on ISO 27001:2022, SOC 2 Type II, and ISO/IEC 42001 AI governance.

You will coordinate audits, manage risk registers, and ensure security controls are effectively implemented across multiple teams.

Qualifications

  • 1–2 years of experience in GRC, information security, IT audit, risk management, or compliance.
  • Bachelor's degree in IT/CS/cybersecurity or related field.
  • Understanding of ISO 27001:2022 and SOC 2 Type II.

Responsibilities

  • Support ISO 27001:2022 ISMS implementation and maintenance.
  • Coordinate SOC 2 Type II compliance and audit activities.
  • Assist with ISO/IEC 42001 AI governance preparation and controls.
  • Maintain risk registers and track remediation actions.
  • Coordinate evidence collection for audits and maintain documentation.
  • Support third-party risk management and vendor security reviews.

Skills

GRC
Information Security
Audit coordination
Documentation

Education

Bachelor's degree in IT/CS/Cybersecurity

Job description

Department: Information Security / Governance, Risk & Compliance

Employment Type: Full-time

About the Role

We are looking for a motivated GRC Analyst with 1–2 years of experience to support our Information Security, Governance, Risk, and Compliance activities.

The candidate will work closely with the Information Security, IT, HR, Engineering, and other business teams to support compliance initiatives, maintain documentation, coordinate audits, track risks and remediation activities, and ensure that security controls are consistently implemented.

The role will primarily focus on ISO 27001:2022, SOC 2 Type II, and emerging AI governance requirements, including ISO/IEC 42001.

Key Responsibilities

ISO 27001:2022

  • Support the implementation and maintenance of the ISO 27001:2022 ISMS.
  • Assist with maintaining ISMS policies, procedures, standards, registers, and supporting documentation.
  • Support periodic risk assessments and maintain the Risk Register.
  • Assist in tracking Statement of Applicability (SoA) controls and control implementation status.
  • Coordinate evidence collection for internal and external audits.
  • Support internal audits, surveillance audits, and corrective action tracking.
  • Monitor compliance with applicable ISO 27001 controls and identify gaps.
SOC 2 Type II
  • Support ongoing SOC 2 Type II compliance and audit activities.
  • Coordinate with internal teams to collect and organize audit evidence.
  • Maintain control matrices and evidence trackers.
  • Assist in monitoring the implementation and operating effectiveness of controls.
  • Track audit findings, exceptions, and remediation activities.
  • Coordinate with external auditors and internal stakeholders as required.
  • Help ensure evidence is complete, accurate, and available within defined timelines.
ISO/IEC 42001 – AI Management System
  • Support the organization's preparation and implementation of ISO/IEC 42001.
  • Assist in documenting AI governance policies, procedures, and controls.
  • Support AI-related risk assessments and maintain relevant risk registers.
  • Assist with maintaining AI system inventories, assessments, and supporting documentation.
  • Coordinate evidence collection for AI governance and compliance activities.
  • Stay updated on developments related to AI governance, responsible AI, and AI security.
Risk Management & Third-Party Risk
  • Assist with maintaining the organization's risk register and tracking risk treatment plans.
  • Support Third-Party Risk Management (TPRM) activities.
  • Assist with vendor security assessments and review of security/compliance documentation.
  • Review documents such as SOC 2 reports, ISO certificates, VAPT reports, and security questionnaires.
  • Track vendor risks, remediation actions, and review timelines.
Security & Compliance Operations
  • Support periodic access reviews and control assessments.
  • Assist with vulnerability management and VAPT remediation tracking.
  • Maintain compliance dashboards, trackers, and audit evidence repositories.
  • Support security awareness and compliance training activities.
  • Assist in preparing management reports and compliance updates.
  • Maintain proper version control and organization of GRC documentation.
  • Follow up with stakeholders to ensure timely completion of compliance activities.
Required Skills & Qualifications
  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field.
  • 1–2 years of experience in GRC, Information Security, IT Audit, Risk Management, or Compliance.
  • Basic to intermediate understanding of ISO 27001:2022.
  • Understanding of SOC 2 Type II and the Trust Services Criteria.
  • Basic understanding of ISO/IEC 42001 or willingness to learn and work on AI governance.
  • Understanding of information security concepts, risks, and controls.
  • Experience with documentation, evidence collection, and audit coordination.
  • Good analytical and organizational skills.
  • Strong attention to detail.
  • Good written and verbal communication skills.
  • Ability to coordinate with multiple teams and follow up on action items.
Good to Have
  • ISO 27001 Foundation / Internal Auditor / Lead Auditor certification.
  • SOC 2 audit or compliance experience.
  • Exposure to ISO/IEC 42001 / AI governance.
  • Knowledge of NIST CSF, CIS Controls, GDPR, or other security frameworks.
  • Experience with GRC, ticketing, or compliance management tools.
  • Basic understanding of cloud security, particularly Microsoft Azure or AWS.
  • Exposure to vulnerability assessments, penetration testing, and security questionnaires.
  • Governance & Compliance
  • Audit & Evidence Management
  • Policy & Documentation
  • Control Monitoring
  • Third-Party Risk Management
  • Stakeholder Coordination
  • Attention to Detail
  • Analytical & Problem-Solving Skills
What the Candidate Will Learn

The role provides hands-on exposure to:

This position would be particularly suitable for someone who wants to build a career in Information Security GRC and AI Governance rather than a purely documentation-focused compliance role.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance, Risk and Compliance (GRC) Specialist
Governance, Risk and Compliance (GRC) Specialist

Career Guideline • Pune District

On-site
INR 1,500,000 - 2,500,000
Staff Risk & Compliance Analyst
Staff Risk & Compliance Analyst

GE-Vernova- • Bengaluru

Hybrid
INR 800,000 - 1,500,000
Relocation assistance
GRC /SOC Analyst
GRC /SOC Analyst

fulcrumdigital • Pune District

Hybrid
INR 600,000 - 900,000
GRC Analyst
GRC Analyst

Exotel Techcom Pvt Ltd • Bengaluru

On-site
INR 600,000 - 900,000
Senior IT Audit & Compliance Specialist
Senior IT Audit & Compliance Specialist

NXP • Bengaluru

On-site
INR 2,000,000 - 3,500,000
Information Security GRC Analyst
Information Security GRC Analyst

Perydot • Mumbai

On-site
INR 600,000 - 1,000,000
Product GRC Consultant
Product GRC Consultant

CyRAACS™ • Bengaluru

On-site
INR 600,000 - 1,200,000
Senior GRC Analyst
Senior GRC Analyst

Exotel • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

844 Altera Semiconductor Technology India Pvt. Ltd. • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Information Security Manager
Information Security Manager

Focaloid Technologies • Ernakulam

On-site
INR 1,200,000 - 1,900,000