GRC Analyst

Cyderes

Bengaluru

Hybrid

INR 1,200,000 - 2,400,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical Insurance
Life Insurance
Retirement Match Program
Hybrid Work Model (2–3 days in office)
Parental Leave
Paid Time Off
Professional Development
LinkedIn Learning
Mobile Phone Reimbursement

Job summary

Cyderes is seeking a GRC Analyst to drive information security and compliance programs, maintain audit readiness, and support policy development. You will report to the Senior Manager GRC and Security.

You will coordinate risk assessments, respond to security inquiries from customers and partners, and help implement governance, risk, and compliance processes across the enterprise. The role requires hands-on GRC tooling, policy design, external audit work, and ongoing reporting to leadership,

Qualifications

  • Minimum 3 years in a GRC role with hands-on administration of a GRC automation tool (Vanta, Drata, or Sprinto).
  • Experience designing and implementing information security policies and controls.
  • Experience participating in external security audits; SOC2 Type II.
  • Experience conducting needs assessments and identifying/implementing appropriate solutions.
  • Knowledge of security technologies and architecture including encryption, cloud network security design, IDS, DLP and application security.
  • CISSP, CISM, CISA certifications.
  • Experience mapping SOC2/ISO criteria to technical controls.
  • Advanced Third-Party Risk (TPRM) analysis for SaaS vendors; SOC2/ISO reports.
  • Privacy & Data Protection liaison with GDPR/CCPA/HIPAA.

Responsibilities

  • Coordinate IT security governance, risk and compliance activities across the enterprise.
  • Oversee information security compliance activities, including risk assessments and audits.
  • Respond to information security compliance requests from customers and partners; review and negotiate agreements.
  • Support SOC2, ISO 27001 compliance efforts.
  • Conduct audit readiness assessments and coordinate with internal/external teams.
  • Manage GRC system implementation and administration.
  • Collaborate with other departments to address security compliance issues.
  • Revise and maintain security controls and procedures per regulations.
  • Ensure continuous compliance through ongoing testing of security and privacy controls.
  • Provide reports to management on compliance progress.

Skills

GRC
GRC tools (Vanta/Drata/Sprinto)
InfoSec policies
SOC2 Type II
Needs assessment
Security architecture
CISSP
CISM
CISA
Vanta
Drata
Sprinto
Third-Party Risk
Privacy & DPAs

Tools

Vanta
Drata
Sprinto

Job description

Who We Are

We help the world Be Everyday Ready. Today’s threatscape is relentless. So are we. At Cyderes, we specialize in building practical IAM, exposure management, and risk programs, and stopping active threats fast with MDR that works with your existing security tools— all augmented by AI and driven by seasoned operators. Our tireless global team is laser-focused on cybersecurity, arming organizations with the people, platforms, and perspectives they need to conquer whatever tomorrow throws their way.

Great Place to Work Certified | United States

  • Canada
  • United Kingdom
  • India
About the Job

Cyderes is looking for a GRC Analyst. The GRC Analyst will be responsible for daily activities in implementing the information security and compliance programme. You will help maintain audit and compliance projects to ensure policies, standards, procedures, and audit activities are according to business, IT, and regulatory requirements. You will also participate in and support multiple department activities. These activities may include quarterly user access reviews, the development of information security policies, procedures, and standards. Additionally, they may involve training and awareness activities. You will also review and respond to security requirements and inquiries regarding existing or proposed solutions. You will perform internal and external security compliance monitoring activities, manage client audits, IT control audits, and security risk assessments.

To be successful in this role, you must be comfortable with evaluating, documenting, and creating remediation plans. These plans must meet compliance requirements in a specific area. The effectiveness of the implementation and operation of the information security and compliance directives will measure success. You will be reporting to Senior Manager GRC and Security.

Responsibilities
  • Coordinate IT security governance, risk and compliance activities across the enterprise
  • Oversee information security compliance activities, including daily, weekly, quarterly and annual security risk assessments—both performing internal assessments and responding to external assessments
  • Respond to request for information on Cyderes' security compliance from customers and partners, review and negotiate relevant agreements
  • Support efforts for compliance with SOC2, ISO 27001, and other security standards and regulatory frameworks
  • Conduct audit readiness assessments and coordinate with internal and external functions and audit resources
  • Support the implementation and administration of the Governance, Risk, and Compliance system (GRC)
  • Collaborate with other departments to direct security compliance issues to appropriate channels for investigation and resolutions
  • Revise and maintain security and controls procedures following applicable regulations
  • Ensure Continuous Compliance through continuous testing of security and privacy controls
  • Provide recommendations for technology, licensing, and process updates to improve Cyderes overall security posture
  • Develop and provide reports to keep management informed of the operation and progress of compliance efforts
Requirements
  • Minimum 3 years in a GRC role with at least 1 full year of hands‑on administration of a GRC automation tool (Vanta, Drata, or Sprinto). We prefer Vanta
  • Experience in design and implementation of information security policies and controls
  • Experience participating in external security audits; SOC2 Type II
  • Experience conducting needs assessments and identifying/implementing appropriate solutions
  • Knowledge of security technologies and architecture, including encryption, cloud network security design, security group configuration, intrusion detection, data loss prevention and application security
  • CISSP, CISM, CISA certifications
  • Analyst A (The Internal Builder): Focuses on Vanta, SOC2/ISO mapping, and internal engineering/DevOps agreement
  • Evidence Collection: Experience translating abstract SOC2 criteria into technical screenshots, logs, or API outputs
  • Experience translating abstract SOC2 Common Criteria or ISO 27001 clauses into applicable technical controls
  • Analyst B (The External/Risk Specialist): Focuses on Third-Party Risk, Customer Questionnaires/Trust Centre, and Privacy (GDPR/CCPA)
  • High proficiency in interpreting SOC2/ISO reports and Data Processing Agreements (DPAs)
  • Advanced Third-Party Risk (TPRM) Analysis requires minimum 3 years of hands‑on experience evaluating SaaS vendors, with the ability to dissect SOC2 Type II, ISO 27001, and Reach Test reports
  • Vanta Trust Centre & Questionnaire Automation: Proficiency in managing Vanta's Trust Centre and Vendor Risk modules
  • Privacy & Data Protection Liaison: Practical experience navigating Data Processing Agreements (DPAs) and mapping vendor risks to privacy frameworks like GDPR, CCPA, or HIPAA
Why Cyderes?
  • Medical Insurance – Employee and dependents covered
  • Life Insurance – Protection for what matters most
  • Retirement Match Program – We invest in your future
  • Hybrid Work Model – 2–3 days in office
  • Maternity & Paternity Leave – Time for the moments that matter
  • Paid Time Off – PTO plus sick & casual leave
  • Bereavement & Volunteer Time – Give back to your community
  • Professional Development – Reimbursement program
  • LinkedIn L&D Platform – Thousands of courses at your fingertips
  • Mobile Phone Reimbursement – Stay connected, on us

Cyderes is an Equal Opportunity Employer (EOE). Qualified applicants are considered for employment without regard to race, religion, color, sex, age, disability, sexual orientation, genetic information, national origin, or veteran status.

Note: This job posting is intended for direct applicants only. We request that outside recruiters do not contact us regarding this position.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst II, Splunk
Security Analyst II, Splunk

Cyderes • India

On-site
INR 900,000 - 1,500,000
Medical Insurance
Hybrid Work Model
Paid Time Off
+1
Lead Security Engineer IGA
Lead Security Engineer IGA

Cyderes • Bengaluru

On-site
INR 1,500,000 - 2,000,000
Medical Insurance
Life Insurance
Retirement Match Program
+3
Platform Operations Analyst
Platform Operations Analyst

Cyderes • Bengaluru

On-site
INR 800,000 - 1,200,000
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Cacheflow • Bengaluru

Hybrid
INR 1,500,000 - 2,200,000
Medical Insurance
Life Insurance
Hybrid Work Model
+2
Security Engineer ll - Microsoft Sentinel SIEM
Security Engineer ll - Microsoft Sentinel SIEM

Cacheflow • Bengaluru

Hybrid
INR 1,200,000 - 3,000,000
Medical Insurance - Employee + depend.
Life Insurance
Hybrid Work Model
Senior Security Engineer - Microsoft Sentinel SIEM
Senior Security Engineer - Microsoft Sentinel SIEM

Cacheflow • Bengaluru

Hybrid
INR 3,000,000 - 5,500,000
Medical Insurance
Retirement Match Program
Hybrid Work Model
+3
Senior GRC Analyst - 26157
Senior GRC Analyst - 26157

Pearl Street Technologies • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Senior GRC Analyst
Senior GRC Analyst

Tetuan Valley • India

On-site
INR 900,000 - 1,200,000
Variable Compensation
Security Engineer ll – Microsoft Sentinel SIEM
Security Engineer ll – Microsoft Sentinel SIEM

Cyderes • Bengaluru

Hybrid
INR 900,000 - 1,500,000
Medical Insurance
Hybrid Work Model
Paid Time Off
+1
Security Engineer ll – Microsoft Sentinel SIEM
Security Engineer ll – Microsoft Sentinel SIEM

Linuxconfig • India

Hybrid
INR 1,500,000 - 2,800,000
Medical Insurance
Hybrid Work Model
PTO and leave benefits
+2