Department: Information Security / Governance, Risk & Compliance
Employment Type: Full-time
About the Role
We are looking for a motivated GRC Analyst with 1–2 years of experience to support our Information Security, Governance, Risk, and Compliance activities.
The candidate will work closely with the Information Security, IT, HR, Engineering, and other business teams to support compliance initiatives, maintain documentation, coordinate audits, track risks and remediation activities, and ensure that security controls are consistently implemented.
The role will primarily focus on ISO 27001:2022, SOC 2 Type II, and emerging AI governance requirements, including ISO/IEC 42001.
Key Responsibilities
ISO 27001:2022
- Support the implementation and maintenance of the ISO 27001:2022 ISMS.
- Assist with maintaining ISMS policies, procedures, standards, registers, and supporting documentation.
- Support periodic risk assessments and maintain the Risk Register.
- Assist in tracking Statement of Applicability (SoA) controls and control implementation status.
- Coordinate evidence collection for internal and external audits.
- Support internal audits, surveillance audits, and corrective action tracking.
- Monitor compliance with applicable ISO 27001 controls and identify gaps.
SOC 2 Type II- Support ongoing SOC 2 Type II compliance and audit activities.
- Coordinate with internal teams to collect and organize audit evidence.
- Maintain control matrices and evidence trackers.
- Assist in monitoring the implementation and operating effectiveness of controls.
- Track audit findings, exceptions, and remediation activities.
- Coordinate with external auditors and internal stakeholders as required.
- Help ensure evidence is complete, accurate, and available within defined timelines.
ISO/IEC 42001 – AI Management System- Support the organization's preparation and implementation of ISO/IEC 42001.
- Assist in documenting AI governance policies, procedures, and controls.
- Support AI-related risk assessments and maintain relevant risk registers.
- Assist with maintaining AI system inventories, assessments, and supporting documentation.
- Coordinate evidence collection for AI governance and compliance activities.
- Stay updated on developments related to AI governance, responsible AI, and AI security.
Risk Management & Third-Party Risk- Assist with maintaining the organization's risk register and tracking risk treatment plans.
- Support Third-Party Risk Management (TPRM) activities.
- Assist with vendor security assessments and review of security/compliance documentation.
- Review documents such as SOC 2 reports, ISO certificates, VAPT reports, and security questionnaires.
- Track vendor risks, remediation actions, and review timelines.
Security & Compliance Operations- Support periodic access reviews and control assessments.
- Assist with vulnerability management and VAPT remediation tracking.
- Maintain compliance dashboards, trackers, and audit evidence repositories.
- Support security awareness and compliance training activities.
- Assist in preparing management reports and compliance updates.
- Maintain proper version control and organization of GRC documentation.
- Follow up with stakeholders to ensure timely completion of compliance activities.
Required Skills & Qualifications
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field.
- 1–2 years of experience in GRC, Information Security, IT Audit, Risk Management, or Compliance.
- Basic to intermediate understanding of ISO 27001:2022.
- Understanding of SOC 2 Type II and the Trust Services Criteria.
- Basic understanding of ISO/IEC 42001 or willingness to learn and work on AI governance.
- Understanding of information security concepts, risks, and controls.
- Experience with documentation, evidence collection, and audit coordination.
- Good analytical and organizational skills.
- Strong attention to detail.
- Good written and verbal communication skills.
- Ability to coordinate with multiple teams and follow up on action items.
Good to Have
- ISO 27001 Foundation / Internal Auditor / Lead Auditor certification.
- SOC 2 audit or compliance experience.
- Exposure to ISO/IEC 42001 / AI governance.
- Knowledge of NIST CSF, CIS Controls, GDPR, or other security frameworks.
- Experience with GRC, ticketing, or compliance management tools.
- Basic understanding of cloud security, particularly Microsoft Azure or AWS.
- Exposure to vulnerability assessments, penetration testing, and security questionnaires.
- Governance & Compliance
- Audit & Evidence Management
- Policy & Documentation
- Control Monitoring
- Third-Party Risk Management
- Stakeholder Coordination
- Attention to Detail
- Analytical & Problem-Solving Skills
What the Candidate Will Learn
The role provides hands-on exposure to:
This position would be particularly suitable for someone who wants to build a career in Information Security GRC and AI Governance rather than a purely documentation-focused compliance role.