GRC Analyst / GRC Specialist (Information Security)_True Balance- NBFC

True Credits Pvt. Ltd.

Gurugram District

Hybrid

INR 1,200,000 - 2,400,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

True Credits Pvt. Ltd. is seeking a Senior GRC Analyst / Specialist (Information Security) to lead governance, risk, and compliance operations in a hybrid setup.

You will own day-to-day GRC activities, collaborate with engineering, IT, security, legal, and vendors, and drive continuous security posture improvements. The role requires ~5 years of GRC experience, knowledge of ISO 27001/22301, SOC 2, NIST CSF, CIS, and hands-on SIEM usage.

Qualifications

  • Bachelor's degree in Information Security, Computer Science, Risk Management, or a related field.
  • Approximately 5 years of dedicated experience in GRC, Information Security, Risk Management, Security Operations, IAM, and RBI compliance.
  • Strong knowledge of ISO 27001, ISO 22301, SOC 2, NIST CSF, and CIS.
  • Hands-on experience with SIEM platforms and security monitoring tools.
  • Excellent stakeholder management, cross-functional collaboration, and strong documentation/reporting skills.

Responsibilities

  • Maintain the enterprise and operational risk registers, conducting risk assessments across business and technology functions.
  • Track risk treatment plans, monitor mitigation activities, and ensure timely closure of identified risks.
  • Prepare GRC and security metrics, dashboards, and management reports, tracking KPIs and KRIs.
  • Manage end-to-end Third-Party Risk Management (TPRM) activities including vendor onboarding assessments and due diligence.
  • Review vendor security questionnaires, audit reports (SOC 2, ISO), certifications, and remediation plans.
  • Maintain vendor risk registers, track outstanding findings, and monitor risk closure.
  • Perform control monitoring and effectiveness reviews to validate compliance with internal policies, ISO 27001, and regulatory obligations (e.g., RBI).
  • Support audits by coordinating evidence collection, responding to auditor requests, and tracking remediation actions.
  • Manage customer security assessments, due diligence requests, and security questionnaire responses.
  • Coordinate periodic user access, privileged access, and SSO reviews (IAM).
  • Validate user provisioning, deprovisioning, role changes, and SoD controls.
  • Conduct periodic asset inventory reviews for ownership, classification, and lifecycle compliance.
  • Monitor security alerts generated by SOC, SIEM, and logs; coordinate investigation/remediation.
  • Track security incidents, document findings, monitor corrective actions, and elevate critical risks.
  • Govern the vulnerability management process, tracking remediation timelines and overdue reporting.
  • Conduct periodic hardening reviews of cloud, servers, endpoints, and network devices.
  • Perform patch compliance reviews for endpoints periodically.

Skills

GRC expertise
Stakeholder management
Documentation
Analytical thinking
Automation mindset

Education

Bachelor's degree in Information Security/CS

Tools

SIEM platforms
Security monitoring tools
Vulnerability management tools

Job description

Role: Senior GRC Analyst / GRC Specialist (Information Security)
Department: Information Security
Work Mode: Hybrid

About the Role

We are seeking a seasoned Senior Governance, Risk, and Compliance (GRC) Analyst / Specialist with approximately 5 years of experience to lead and execute our core information security governance, risk management, and compliance operations.

In this role, you will own day-to-day GRC operations, acting as the primary operational point of contact for assurance activities. You will collaborate closely with internal engineering, IT, security operations, product, and legal teams, as well as external vendors. The ideal candidate is a self-starter who can drive continuous improvement, automate manual processes, and elevate the organization's overall security and compliance posture.


Key Responsibilities
1. Risk Management & Governance
  • Maintain the enterprise and operational risk registers, conducting risk assessments across business and technology functions.
  • Track risk treatment plans, monitor mitigation activities, and ensure timely closure of identified risks.
  • Prepare GRC and security metrics, dashboards, and management reports, tracking KPIs and KRIs.
2. Third-Party Risk Management (TPRM)
  • Manage end-to-end TPRM activities, including vendor onboarding assessments, due diligence reviews, and periodic reassessments.
  • Review vendor security questionnaires, audit reports (SOC 2, ISO), certifications, and remediation plans.
  • Maintain vendor risk registers, track outstanding findings, and monitor risk closure.
3. Compliance, Audit & Control Monitoring
  • Perform control monitoring and effectiveness reviews to validate compliance with internal policies, ISO 27001, and regulatory obligations (e.g., RBI compliance).
  • Support internal and external audits by coordinating evidence collection, responding to auditor requests, and tracking remediation actions.
  • Manage customer security assessments, due diligence requests, and security questionnaire responses.
4. Identity & Access Governance (IAM) & Asset Management
  • Coordinate periodic user access, privileged access, and SSO reviews.
  • Validate user provisioning, deprovisioning, role changes, and segregation of duties (SoD) controls.
  • Conduct periodic asset inventory reviews to ensure asset ownership, classification, and lifecycle compliance.
5. Incident Management / SOC
  • Monitor security alerts generated by SOC, SIEM, and application logs, coordinating with relevant technical teams for investigation and remediation.
  • Track security incidents, document findings, monitor corrective actions, and elevate critical risks.
  • Govern the vulnerability management process, tracking remediation timelines and reporting overdue vulnerabilities.
6. Security Operations
  • Conduct periodic hardening reviews of cloud, servers, endpoints, and network devices.
  • Perform patch compliance reviews for endpoints on a periodic basis.
Required Qualifications
  • Education: Bachelor's degree in Information Security, Computer Science, Risk Management, or a related technical field.
  • Experience: Approximately 5 years of dedicated experience in GRC, Information Security, Risk Management, Security Operations, IAM, and RBI compliance.
  • Frameworks: Strong knowledge of ISO 27001, ISO 22301, SOC 2, NIST CSF, and CIS.
  • Technical Skills: Hands‑on experience with SIEM platforms, security monitoring tools, and vulnerability management governance.
  • Soft Skills: Excellent stakeholder management, cross‑functional collaboration, and strong documentation/reporting skills (advanced MS Excel/Word).
Preferred Qualifications
  • Certifications: ISO 27001 Lead Implementer / Lead Auditor, CISA, CRISC, or equivalent security certifications.
  • Industry Experience: Prior experience in NBFC, PPI, SaaS, FinTech, or fast-paced product-based organizations in a regulated industry.
  • Cloud Governance: Direct exposure to cloud security governance, preferably within AWS environments.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC - Security Analyst
GRC - Security Analyst

Jobgether • India

On-site
INR 1,200,000 - 1,800,000
Fully remote in India
Full-time employment
Exposure to multiple security framesk—
+2
GRC Specialist
GRC Specialist

Keka Technologies Private Limited • Ernakulam

On-site
INR 1,200,000 - 1,800,000
Senior GRC Analyst
Senior GRC Analyst

3M HEALTHCARE • Hyderabad

On-site
INR 1,500,000 - 2,200,000
Senior Role - GRC & Infosec
Senior Role - GRC & Infosec

NPCI Bharat BillPay Limited • Mumbai

On-site
INR 2,000,000 - 3,000,000
Senior Security GRC Analyst
Senior Security GRC Analyst

Kite • Gurugram District

On-site
INR 1,500,000 - 2,300,000
Information Security Engineer - GRC
Information Security Engineer - GRC

EDGE Executive Search • Gurugram District

On-site
INR 900,000 - 1,500,000
GRC Analyst
GRC Analyst

Soffit Infrastructure Services (P) Ltd • Ernakulam

On-site
INR 800,000 - 1,200,000
GRC Consultant @ Mumbai
GRC Consultant @ Mumbai

Quess IT Solutions • Mumbai

On-site
INR 1,800,000 - 2,400,000
Compliance Analyst
Compliance Analyst

TRDFIN Support Services Pvt Ltd • Gurugram District

On-site
INR 800,000 - 1,000,000
Competitive compensation and benefits
Exposure to technology and financial compliance landscapes
Career growth in GRC and risk management
GRC Specialist
GRC Specialist

F-Prime Capital • Bengaluru

On-site
INR 1,600,000 - 2,400,000