GRC - Security Analyst

Jobgether

India

Remote

INR 1,200,000 - 1,800,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Fully remote in India
Full-time employment
Exposure to multiple security framesk—
Cross-functional collaboration
Travel up to 10%

Job summary

Jobgether is seeking a GRC - Security Analyst based in India to support governance, risk, and compliance across technology and processes.

You will help develop security policies, controls, and audit readiness, collaborating with Security, IT, Legal, Privacy, Internal Audit, and business stakeholders, including third-party risk management and evidence collection. This is a remote, full-time role with growth in GRC automation.

Qualifications

  • Bachelor’s degree in cybersecurity, information technology, information systems, risk management, or related field, or equivalent experience.
  • 3+ years in cybersecurity, governance, risk management, compliance, IT audit, or related discipline.
  • Certification such as Security+, CISA, CRISC, or CGRC preferred.
  • Familiarity with HITRUST, SOC 2, PCI DSS, or comparable frameworks.
  • Experience performing security risk assessments and evaluating control effectiveness.
  • Familiarity with regulatory/compliance requirements for tech-driven orgs.
  • Some incident response exposure; willingness to learn.
  • Strong analytical, organizational, planning, documentation, and problem-solving skills; ability to manage multiple assessments and deadlines.
  • Excellent communication; able to explain security and risk to technical and non-technical stakeholders.
  • Attention to detail and ability to meet deadlines; proficient with Microsoft Office.
  • Curiosity about cybersecurity trends and opportunities to improve security and IT infra.

Responsibilities

  • Perform cybersecurity and technology risk assessments across systems, applications, vendors, and business processes.
  • Maintain information security policies, standards, procedures, control frameworks, risk registers, and governance docs.
  • Support compliance activities with SOC 2, HIPAA, HITRUST, PCI DSS, and other requirements.
  • Assist with audits, regulatory examinations, security assessments, and customer compliance by gathering and maintaining control evidence.
  • Track audit findings, risk, control deficiencies, exceptions, and remediation plans with owners.
  • Conduct third-party and vendor security assessments including questionnaires and audit reports.
  • Support security awareness, policy acknowledgment, risk acceptance, and due diligence responses.
  • Monitor regulatory changes and translate into governance improvements.
  • Develop GRC metrics, dashboards, and management reports to communicate status.
  • Partner with tech security teams to translate vulnerabilities into business risks and drive automation.

Skills

Analytical skills
Organizational skills
Planning skills
Documentation skills
Problem-solving
Communication skills
Attention to detail

Education

Bachelor’s degree in Cybersecurity or related field

Tools

Microsoft Office

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a GRC - Security Analyst based in India.

This role supports the organization’s cybersecurity governance, risk, and compliance program, helping identify and manage security risks across technology, vendors, and business processes. You will contribute to the development and maintenance of security policies, controls, and governance practices while supporting audits and compliance assessments. The position provides broad exposure to frameworks such as SOC 2, HIPAA, HITRUST, and PCI DSS, depending on business requirements. You will collaborate closely with Information Security, IT, Legal, Privacy, Internal Audit, and business stakeholders to translate security issues into actionable business risks. The role also involves third-party risk management, evidence collection, remediation tracking, and security reporting. This is an opportunity for a detail-oriented cybersecurity professional to strengthen security maturity while continuously improving GRC processes and automation.

Accountabilities:
  • Perform cybersecurity and technology risk assessments across systems, applications, vendors, and business processes, documenting risks and evaluating their potential business impact.
  • Maintain information security policies, standards, procedures, control frameworks, risk registers, and governance documentation.
  • Support compliance activities aligned with frameworks and regulations such as SOC 2, HIPAA, HITRUST, PCI DSS, and other applicable requirements.
  • Assist with internal and external audits, regulatory examinations, security assessments, and customer compliance reviews by gathering, validating, and maintaining control evidence.
  • Track audit findings, security risks, control deficiencies, exceptions, and remediation plans through resolution, working with control owners to assess effectiveness and implement improvements.
  • Conduct third-party and vendor security assessments, including reviewing security questionnaires, certifications, audit reports, and supporting documentation.
  • Support security awareness, policy acknowledgment, risk acceptance, and security exception processes while responding to customer and partner due diligence requests.
  • Monitor changes in regulatory requirements, security standards, and cybersecurity practices and help translate relevant developments into governance improvements.
  • Develop GRC metrics, dashboards, reports, and management documentation to communicate security and compliance status effectively.
  • Partner with technical security teams to translate vulnerabilities and technical security issues into clear business risks and identify opportunities to automate and improve GRC processes.
Requirements:
  • Bachelor’s degree in Cybersecurity, Information Technology, Information Systems, Risk Management, or a related field, or equivalent professional experience.
  • 3+ years of experience in cybersecurity, governance, risk management, compliance, IT audit, or a related discipline.
  • Relevant certification such as Security+, CISA, CRISC, or CGRC is preferred.
  • Working knowledge of cybersecurity frameworks and standards such as HITRUST, SOC 2, PCI DSS, or comparable frameworks.
  • Experience performing security risk assessments and evaluating the effectiveness of security controls.
  • Familiarity with regulatory and compliance requirements relevant to technology-driven organizations.
  • Some experience or exposure to incident response, with a strong interest in cybersecurity and a willingness to continuously learn.
  • Strong analytical, organizational, planning, documentation, and problem-solving skills, with the ability to manage multiple assessments, findings, and deadlines.
  • Excellent communication skills, with the ability to explain security, compliance, and risk concepts clearly to both technical and non-technical stakeholders.
  • Strong attention to detail, ability to meet deadlines, and proficiency with Microsoft Office or comparable productivity and reporting tools.
  • Curiosity about emerging technology and cybersecurity trends, with the ability to identify practical opportunities for improving security and IT infrastructure.
Benefits:
  • Fully remote work arrangement in India.
  • Full-time opportunity within an Information Technology and cybersecurity environment.
  • Exposure to enterprise-wide cybersecurity governance, risk, compliance, and audit activities.
  • Hands-on experience with recognized security frameworks including SOC 2, HIPAA, HITRUST, and PCI DSS.
  • Opportunity to work cross-functionally with Information Security, IT, Legal, Privacy, Internal Audit, and business teams.
  • Broad experience in third-party risk management, security assessments, audit readiness, and regulatory compliance.
  • Opportunity to contribute to GRC automation, process improvement, reporting, and security maturity initiatives.
  • Approximately 10% travel as needed.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Analyst
Senior GRC Analyst

3M HEALTHCARE • Hyderabad

On-site
INR 1,500,000 - 2,200,000
Cybersecurity - Risk & Compliance Analyst
Cybersecurity - Risk & Compliance Analyst

Scybers • Chennai District

On-site
INR 900,000 - 1,500,000
GRC Analyst
GRC Analyst

Exotel • Bengaluru

On-site
INR 800,000 - 1,200,000
Senior GRC Analyst
Senior GRC Analyst

Litmos • Pune District

On-site
INR 2,880,000 - 3,520,000
Annual bonus
Information Security GRC Consultant
Information Security GRC Consultant

Aarcalev Technology Solutions • India

Remote
INR 900,000 - 1,500,000
Fully remote role
Exposure to global compliance frameworks
Professional growth opportunities
Cybersecurity Lead - GRC
Cybersecurity Lead - GRC

Medusind • Mumbai

On-site
INR 2,500,000 - 4,500,000
Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

Powerbridge • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Health insurance
Long-term benefit savings plan
Professional development opportunities
Cybersecurity Specialist – Governance, Risk & Compliance (GRC)
Cybersecurity Specialist – Governance, Risk & Compliance (GRC)

TalaKunchi Networks Pvt Ltd • Mumbai

On-site
INR 800,000 - 1,200,000
Opportunity to shape InfoSec practices
Work on cutting-edge cybersecurity initiatives
Be part of a forward-thinking team
Senior Analyst GRC (Cyber Security)
Senior Analyst GRC (Cyber Security)

Quarks Technosoft • Hyderabad

On-site
INR 1,200,000 - 2,200,000
Senior GRC Analyst
Senior GRC Analyst

Tetuan Valley • India

On-site
INR 900,000 - 1,200,000
Variable Compensation