GRC Specialist

F-Prime Capital

Bengaluru

On-site

INR 1,600,000 - 2,400,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

F-Prime Capital is seeking a GRC Specialist to execute day-to-day tasks that keep our compliance and risk programs running. You will respond to customer security questionnaires and support audits while collaborating with Engineering, IT, Sales and Customer Success to turn requirements into clear, evidenced answers.

The GRC Lead will guide strategy and priorities. You will conduct risk assessments, maintain the risk register, and validate controls across SOC 2, ISO 27001, GDPR, and PCI DSS

Qualifications

  • 4–5 years of experience in GRC, IT audit, information security, or compliance.
  • Working knowledge of SOC 2, ISO 27001, GDPR, PCI DSS, or similar.
  • Experience with GRC tooling such as Scrut/Vanta/Drata.
  • Strong written communication; translate controls into clear customer/auditor responses.
  • Capable of managing multiple concurrent requests under deal-cycle timelines.

Responsibilities

  • Own end-to-end responses to inbound customer RFPs, RFIs, and CAIQs.
  • Conduct risk assessments and validate controls per SOC 2, ISO 27001, and NIST.
  • Support SOC 2 and ISO 27001 audits with evidence collection and remediation tracking.
  • Perform vendor risk assessments and review third-party responses.
  • Maintain Trust Centre certifications, policies, and security docs.
  • Coordinate with Engineering, IT, Legal, and Privacy to close findings.
  • Track metrics on risk, incidents, vulnerabilities, and controls.

Skills

GRC / IT audit
Security & compliance
GRC tooling
Written communication
Time management

Tools

Scrut/Vanta/Drata

Job description

About the Role

GRC Specialist to execute the day-to-day work that keeps our compliance and risk programs running — from responding to customer security questionnaires to supporting audits and assessing vendor risk. You'll work closely with Engineering, IT, Sales and Customer Success to turn security and compliance requirements into clear, evidenced answers, while the GRC Lead sets overall program strategy and priorities.

Key Responsibilities
  • Customer RFP & Security Questionnaire Response — Own end-to-end responses to inbound customer RFPs, RFIs, and CAIQs, coordinating with internal teams to gather accurate, evidence-backed answers that support sales and customer success deal cycles.
  • Risk Assessment & Management — Conduct risk assessments and control validation testing against frameworks such as SOC 2, ISO 27001, and NIST; maintain the risk register, score identified risks, and track treatment items through to closure.
  • Audit & Compliance Support — Support the full lifecycle of SOC 2 and ISO 27001 audits, including evidence collection, control walkthroughs, and remediation tracking, in coordination with internal stakeholders and external auditors.
  • Third-Party & Vendor Risk Management — Conduct vendor security assessments and review vendor questionnaire responses to evaluate third-party risk posture.
  • Trust Centre Maintenance — Keep customer-facing certifications, policies, and security documentation current and accurate.
  • Cross-Functional Coordination — Partner with Engineering, IT, Legal, and Privacy teams to resolve findings and validate control implementations.
  • Metrics & Reporting — Track and report on risk, incident, vulnerability, and control metrics, clearly explaining changes and next steps to stakeholders.
Required Qualifications
  • 4–5 years of experience in a GRC, IT audit, information security, or compliance-related role.
  • Working knowledge of security and compliance frameworks (SOC 2, ISO 27001, GDPR, PCI DSS, or similar).
  • Experience with GRC tooling (e.g., Scrut/Vanta/Drata)
  • Strong written communication skills — able to translate technical controls into clear answers for customers and auditors.
  • Comfort managing multiple concurrent requests under deal-cycle timelines.
Preferred Qualifications
  • Certifications such as ISO 27001 Lead Implementer/Auditor.
  • Prior experience responding to customer security questionnaires in a SaaS environment.
  • Familiarity with IT/cloud infrastructure (AWS/Azure/GCP) and vendor risk assessment methodologies.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC Specialist
GRC Specialist

MoEngage Inc. • Bengaluru

On-site
INR 900,000 - 1,400,000
GRC Specialist
GRC Specialist

Keka Technologies Private Limited • Ernakulam

On-site
INR 1,200,000 - 1,800,000
GRC - Security Analyst
GRC - Security Analyst

Jobgether • India

On-site
INR 1,200,000 - 1,800,000
Fully remote in India
Full-time employment
Exposure to multiple security framesk—
+2
Senior GRC Analyst
Senior GRC Analyst

3M HEALTHCARE • Hyderabad

On-site
INR 1,500,000 - 2,200,000
GRC
GRC

Deloitte Shared Services India • Bengaluru

On-site
INR 2,000,000 - 2,500,000
GRC Consultant
GRC Consultant

Lonvec Technologies Private Limited • Hyderabad

On-site
INR 1,200,000 - 2,200,000
Product GRC Consultant
Product GRC Consultant

CyRAACS™ • Bengaluru

On-site
INR 600,000 - 1,200,000
GRC Analyst
GRC Analyst

Exxat • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Information Security Engineer - GRC
Information Security Engineer - GRC

EDGE Executive Search • Gurugram District

On-site
INR 900,000 - 1,500,000
GRC Analyst / GRC Specialist (Information Security)_True Balance- NBFC
GRC Analyst / GRC Specialist (Information Security)_True Balance- NBFC

True Credits Pvt. Ltd. • Gurugram District

On-site
INR 1,200,000 - 2,400,000