GRC Associate

Hireologist

Bengaluru

On-site

INR 600,000 - 1,200,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Hireologist is seeking a GRC Associate/Information Security Analyst in Bengaluru with 2–3 years of relevant experience in Governance, Risk & Compliance, Information Security, IT Risk, Internal Controls, or related areas.

The role supports GRC assessments, audits, risk and control reviews, documentation, audit readiness, and client coordination. You will map regulatory requirements to controls, identify gaps, and help clients achieve compliance objectives.

Qualifications

  • 2–3 years of experience in GRC, Risk, Compliance, or Information Security.
  • Strong understanding of GRC concepts and control frameworks.
  • Experience in risk and control assessments.
  • Excellent documentation and report-writing skills.

Responsibilities

  • Support GRC assessments, audits, and compliance engagements.
  • Perform risk, control, and gap assessments against applicable frameworks.
  • Review policies, procedures, processes, and control documentation.
  • Identify control gaps and compliance issues and recommend corrective actions.
  • Prepare Risk Registers, Control Matrices, SoA, policies, procedures, and assessment reports.
  • Coordinate with client stakeholders for evidence collection and control validation.
  • Review evidence for completeness, accuracy, and compliance.
  • Track findings, observations, corrective actions, and closure status.
  • Support audit preparation and client readiness activities.
  • Participate in client meetings and assessment walkthroughs.
  • Prepare clear and structured reports, findings, and recommendations.
  • Stay updated with relevant GRC frameworks, regulations, and industry practices.
  • Work with senior consultants to deliver projects within timelines.

Skills

ISO/IEC 27001
SOC 1/ SOC 2
PCI DSS
Privacy & Data Protection
IT General Controls
Information Security Controls
Internal Controls
Business Continuity

Job description

GRC Associate/ Information Security Analyst

Experience: 2–3 Years

About the Role

We are looking for a GRC Associate with 2–3 years of relevant experience in Governance, Risk & Compliance, Information Security, IT Risk, Internal Controls, or related areas.

The candidate will support GRC assessments, audits, compliance reviews, risk assessments, gap assessments, documentation, audit readiness, and client coordination. The role involves mapping regulatory and security requirements to organizational controls, identifying gaps, and supporting clients in achieving compliance objectives.

Key Responsibilities
  • Support GRC assessments, audits, and compliance engagements.
  • Perform risk, control, and gap assessments against applicable frameworks.
  • Review policies, procedures, processes, and control documentation.
  • Identify control gaps and compliance issues and recommend corrective actions.
  • Prepare Risk Registers, Control Matrices, Statement of Applicability (SoA), policies, procedures, and assessment reports.
  • Support implementation and assessment of information security and compliance controls.
  • Coordinate with client stakeholders for evidence collection and control validation.
  • Review evidence for completeness, accuracy, and compliance.
  • Track findings, observations, corrective actions, and closure status.
  • Support audit preparation and client readiness activities.
  • Participate in client meetings, discussions, and assessment walkthroughs.
  • Prepare clear and structured reports, findings, and recommendations.
  • Stay updated with relevant GRC frameworks, regulations, and industry practices.
  • Work with senior consultants/assessors to deliver projects within timelines.
Candidate Profile
  • 2–3 years of relevant experience in GRC, Risk, Compliance, or Information Security.
  • Strong understanding of GRC concepts and control frameworks.
  • Experience in risk and control assessments.
  • Ability to review and interpret policies, procedures, and evidence.Strong documentation and report-writing skills.
  • Good analytical and problem-solving abilities.
  • Strong verbal and written communication skills.
  • Comfortable interacting with client stakeholders.
  • Ability to manage multiple tasks and meet deadlines.
  • Strong attention to detail.
Required Skills & Knowledge
  • ISO/IEC 27001
  • SOC 1 / SOC 2
  • PCI DSS
  • Privacy & Data Protection Frameworks
  • IT General Controls (ITGC)
  • Information Security Controls
  • Internal Controls
  • Business Continuity / Operational Resilience
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC Analyst
GRC Analyst

Linnk Group • Ernakulam

On-site
INR 600,000 - 800,000
GRC Analyst
GRC Analyst

NewSpace Research and Technologies • Bengaluru

On-site
INR 350,000 - 550,000
GRC Specialist
GRC Specialist

Keka Technologies Private Limited • Ernakulam

On-site
INR 1,200,000 - 1,800,000
GRC Analyst
GRC Analyst

Exotel • Bengaluru

On-site
INR 800,000 - 1,200,000
IT Audit Specialist
IT Audit Specialist

Hireologist • Bengaluru

On-site
INR 400,000 - 600,000
GRC Consultant
GRC Consultant

Lonvec Technologies Private Limited • Hyderabad

On-site
INR 1,200,000 - 2,200,000
Compliance Analyst
Compliance Analyst

INTECH Creative Services Pvt. Ltd. • Mumbai, Navi Mumbai

On-site
INR 900,000 - 1,500,000
GRC Analyst
GRC Analyst

Exotel Techcom Pvt Ltd • Bengaluru

On-site
INR 600,000 - 900,000
GRC Analyst
GRC Analyst

Soffit Infrastructure Services (P) Ltd • Ernakulam

On-site
INR 800,000 - 1,200,000
Information Security GRC Analyst
Information Security GRC Analyst

Perydot • Mumbai

On-site
INR 600,000 - 1,000,000