GRC & InfoSec Executive

Xpentra

Mumbai Suburban

On-site

INR 900,000 - 1,500,000

Full time

9 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Xpentra in Mumbai is seeking a detail-oriented GRC & Information Security Executive to support governance, risk, compliance and information security initiatives. The role bridges technical execution and regulatory requirements to keep processes secure and audit-ready.

You'll draft IT policies, support audits, conduct risk assessments and collaborate with IT teams and external auditors to close findings. A strong foundation in IT infrastructure and security controls is essential, with ISO 27001,

Qualifications

  • Bachelor's or Master's degree in IT, CS, Cyber Security or related field.
  • Knowledge of ISO 27001, SOC 2, NIST and DPDP.
  • Strong documentation and policy management skills.
  • Experience with IT infrastructure, audits and risk assessment.

Responsibilities

  • Draft and maintain IT policies, SOPs and control descriptions.
  • Support audits by collecting evidence and tracking remediation.
  • Identify vulnerabilities and propose corrective actions.
  • Assist in IT infrastructure risk assessment and tracking.
  • Collaborate with IT, developers, apps teams and external auditors.

Skills

IT Infrastructure basics
InfoSec principles
Compliance knowledge
Documentation skills
Communication skills

Education

Bachelor's or Master's degree in IT/CS/Cyber Security

Job description

Job Title:

GRC & InfoSec Executive

Location:

Mumbai

Job Type:

Full-time

Schedule:

Monday to Friday

Overview:

We are looking for a highly detailed-oriented and technically aware IT GRC and Information Security Executive to support Q2Pay Technologies governance, risk, compliance and information security initiatives.

This role is ideal for an ambitious professional with foundational experience in IT infrastructure, InfoSec controls and IT documentation who wants to play a key role in safeguarding our technology landscape. You will bridge the gap between technical execution and regulatory compliance, ensuring our processes remain secure, robust and audit-ready.

Key Responsibilities:
Documentation & Policy Management:

Draft, implement and maintain critical IT artifacts, including IT Operations policies, Information Security Policies, Standard Operating Procedures (SOPs), process documents and control descriptions.

Audit Readiness & Gap Analysis:

Support internal and external audits by proactively preparing evidence collections, tracking remediation progress and closing audit findings. Identify vulnerabilities or missing links in current IT controls and documentation suggesting concrete measures to fix them.

Risk Assessment:

Assist in IT Infrastructure risk identification, assessment and systematic tracking to mitigate potential vulnerabilities before they affect operations.

InfoSec Implementation Support:

Partner with core technical teams to implement and verify basic information security controls, including access management, backup verifications and endpoint security controls.

Cross-Functional Coordination:

Act as a central point of contact, working closely with IT Infrastructure, Developers, Application teams and external auditors to track open compliance tasks and ensure timely closure.

Required Skills:

Core Technical Knowledge: A strong foundational understanding of IT Infrastructure (Operating Systems, Databases, Networks, Applications and Hardware) alongside core Information Security principles.

Compliance Frameworks: Deep familiarity with industry-standard security frameworks such as ISO 27001, SOC 2, NIST and local regulations like DPDP.

Documentation Excellence: Exceptional technical and process documentation skills with a sharp eye for detail. You excel at spotting "what is missing" in a process or workflow.

Communication & Drive: Strong written and verbal communication skills, paired with a proactive mindset to take ownership of compliance trackers.

Preferred Qualifications
Educational Background:

Bachelor's or Master's Degree in IT, Computer Science, Cyber Security or a closely related field.

Cloud Familiarity:

Hands-on experience or familiarity with cloud computing platforms, particularly AWS, is a distinct advantage.

Certifications:

Industry certifications such as ISO 27001 Lead Implementer/Auditor, CompTIA Security+ or CISA are highly preferred but not mandatory.

Why Join Us?

Fast-Track to Engineering Management: This role is designed with a clear career growth trajectory, offering a structured path to transition into an IT GRC Manager or Information Security Manager.

High Visibility & Impact:

You will work directly with cross-functional engineering and infrastructure teams giving you a holistic view of the company's tech ecosystem and a direct hand in securing it.

Continuous Learning:

Dive deep into cutting-edge cloud security environments and complex regulatory compliance frameworks within a fast-growing technology space.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC - Security Analyst
GRC - Security Analyst

Jobgether • India

Remote
INR 1,200,000 - 1,800,000
Fully remote in India
Full-time employment
Exposure to multiple security framesk—
+2
Senior Role - GRC & Infosec
Senior Role - GRC & Infosec

NPCI Bharat BillPay Limited • Mumbai

On-site
INR 2,000,000 - 3,000,000
Cybersecurity Specialist – Governance, Risk & Compliance (GRC)
Cybersecurity Specialist – Governance, Risk & Compliance (GRC)

TalaKunchi Networks Pvt Ltd • Mumbai

On-site
INR 800,000 - 1,200,000
Opportunity to shape InfoSec practices
Work on cutting-edge cybersecurity initiatives
Be part of a forward-thinking team
Assistant Manager - Information Security/ IT GRC
Assistant Manager - Information Security/ IT GRC

KVAT & Co • Mumbai

On-site
INR 1,500,000 - 2,700,000
GRC Lead
GRC Lead

Baldor Technologies • Mumbai

On-site
INR 300,000 - 600,000
Assistant Manager - Information Security/ IT GRC
Assistant Manager - Information Security/ IT GRC

KVAT & Co • Navi Mumbai

On-site
INR 1,500,000 - 2,100,000
Flexible work arrangements
Assistant Manager - Information Security/ IT GRC
Assistant Manager - Information Security/ IT GRC

KVAT & Co • Thane

On-site
INR 1,200,000 - 1,800,000
Senior Manager – GRC
Senior Manager – GRC

ITHR Technologies Consulting LLC • Delhi

On-site
INR 4,000,000 - 7,000,000
GRC Analyst
GRC Analyst

Exotel Techcom Pvt Ltd • Bengaluru

On-site
INR 600,000 - 900,000
GRC Analyst
GRC Analyst

Exotel • Bengaluru

On-site
INR 800,000 - 1,200,000