GRC Consultant – Information Security

Infosec Train

Thiruvananthapuram

Hybrid

INR 406,000 - 487,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Infosec Train is seeking a GRC Consultant with 2–3 years of experience in Information Security, Governance, Risk and Compliance. The role supports client engagements, security assessments, documentation, and the implementation of information security processes and controls.

Based in Kerala with hybrid work in Trivandrum or Kochi, the position requires occasional travel to client sites, including international locations.

Qualifications

  • 2–3 years of experience in Information Security, GRC, Risk, Compliance, IT Governance, or related areas.
  • Strong understanding of ISO 27001 and ISO 27002.
  • Experience in security risk assessments and compliance assessments.
  • Knowledge of ISO 22301, ISO 31000, NIST, CIS, or similar frameworks.
  • Understanding of information security controls, policies, processes, and risk mitigation.
  • Familiarity with application security, network security, endpoint security, server security, and SIEM/security monitoring.
  • Good technical documentation and report-writing skills.
  • Strong written and verbal communication skills.

Responsibilities

  • Support consulting engagements related to Information Security, Business Continuity, Data Privacy, IT Governance, and Risk Management.
  • Conduct AS-IS assessments, gap assessments, risk assessments, and compliance assessments.
  • Assist in developing and implementing information security policies, processes, procedures, guidelines, and templates.
  • Conduct compliance assessments against frameworks and standards such as ISO 27001, ISO 27002, ISO 22301, ISO 31000, NIST, and CIS.
  • Identify and document security gaps, risks, and non-conformities and support corrective action closure.
  • Prepare technical reports, presentations, assessment reports, and client documentation.
  • Develop and track KPIs, metrics, and compliance reports.
  • Work with clients and internal stakeholders to understand business requirements and translate them into appropriate security and GRC deliverables.
  • Provide guidance on applicable security standards, controls, processes, and best practices.
  • Support implementation and institutionalization of security and compliance processes within client environments.
  • Travel occasionally to client locations, including international locations, based on project requirements.

Skills

GRC
Information Security
Risk Management
Compliance
IT Governance
Documentation
Stakeholder mgmt
Security controls
Security policies
ISO 27001

Education

Bachelor's degree in CS/IT

Job description

GRC Consultant - Information Security

Location: Preferably Trivandrum / Kochi (Hybrid) OR Willing to Relocate

Experience: 2–3 Years

Salary: Up to ₹40,000 per month

Employment Type: Full-Time

Job Description

We are looking for a GRC Consultant with 2–3 years of experience in Information Security, Governance, Risk, and Compliance. The candidate will be responsible for supporting client consulting engagements, security assessments, compliance activities, documentation, and implementation of information security processes.

Key Responsibilities
  • Support consulting engagements related to Information Security, Business Continuity, Data Privacy, IT Governance, and Risk Management.
  • Conduct AS-IS assessments, gap assessments, risk assessments, and compliance assessments.
  • Assist in developing and implementing information security policies, processes, procedures, guidelines, and templates.
  • Conduct compliance assessments against frameworks and standards such as ISO 27001, ISO 27002, ISO 22301, ISO 31000, NIST, and CIS.
  • Identify and document security gaps, risks, and non-conformities and support corrective action closure.
  • Prepare technical reports, presentations, assessment reports, and client documentation.
  • Develop and track KPIs, metrics, and compliance reports.
  • Work with clients and internal stakeholders to understand business requirements and translate them into appropriate security and GRC deliverables.
  • Provide guidance on applicable security standards, controls, processes, and best practices.
  • Support implementation and institutionalization of security and compliance processes within client environments.
  • Travel occasionally to client locations, including international locations, based on project requirements.
Required Skills & Qualifications
  • 2–3 years of relevant experience in Information Security, GRC, Risk, Compliance, IT Governance, or related areas.
  • Strong understanding of ISO 27001 and ISO 27002.
  • Experience in security risk assessments and compliance assessments.
  • Knowledge of ISO 22301, ISO 31000, NIST, CIS, or similar frameworks.
  • Understanding of information security controls, policies, processes, and risk mitigation.
  • Familiarity with application security, network security, endpoint security, server security, and SIEM/security monitoring concepts.
  • Good technical documentation and report-writing skills.
  • Strong written and verbal communication skills.
  • Ability to interact effectively with technical and non-technical stakeholders.
  • Bachelor's degree in Computer Science, Engineering, Information Technology, or a related field.
Additional Requirements
  • Willingness to travel occasionally to client locations as required by projects.
  • Valid passport and eligibility to undertake international travel when required.
  • Candidate should have a personal laptop for work-related activities.
Preferred Certifications

Certifications such as ISO 27001 LA/LI, ISO 22301 LA/LI, CISA, CISSP, CRISC, CCSK, CompTIA CASP, or PMP will be an added advantage.

Key Competencies
  • Client-facing skills
  • Risk assessment and analysis
  • Information Security & GRC
  • Compliance and audit
  • Documentation and reporting
  • Stakeholder management
  • Project coordination
  • Business and technical understanding
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Consultant -GRC
Consultant -GRC

Value Point Systems Pvt Ltd • Bengaluru

On-site
Cyber Security GRC Consultant @ Mumbai
Cyber Security GRC Consultant @ Mumbai

Quess IT Solutions • Mumbai

On-site
INR 1,600,000 - 2,800,000
GRC - Security Analyst
GRC - Security Analyst

Jobgether • India

Remote
INR 1,200,000 - 1,800,000
Fully remote in India
Full-time employment
Exposure to multiple security framesk—
+2
Business Continuity Manager @ Mumbai
Business Continuity Manager @ Mumbai

Quess IT Solutions • Mumbai

On-site
INR 1,400,000 - 2,000,000
GRC Associate
GRC Associate

Hireologist • Bengaluru

On-site
INR 600,000 - 1,200,000
GRC Specialist
GRC Specialist

NopalCyber • Hyderabad

On-site
INR 800,000 - 1,200,000
GRC Consultant
GRC Consultant

Lonvec Technologies Private Limited • Hyderabad

On-site
INR 1,200,000 - 2,200,000
Product GRC Consultant
Product GRC Consultant

CyRAACS™ • Bengaluru

On-site
INR 600,000 - 1,200,000
GRC Analyst
GRC Analyst

Exotel • Bengaluru

On-site
INR 800,000 - 1,200,000
GRC Solution Consultant
GRC Solution Consultant

LTM • Sector 10

Hybrid
INR 4,000,000 - 6,500,000