GRC Specialist

Keka Technologies Private Limited

Ernakulam

On-site

INR 1,200,000 - 1,800,000

Full time

40 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Keka Technologies Private Limited in India is seeking a hands-on GRC Specialist to support a banking/financial services client’s information security program, owning control design and evidence, risk assessments, audit support, and policy hygiene.

The role collaborates with DevSecOps, IAM, and security operations to map controls to GRC obligations, maintain risk registers and evidence packs, and escalate material risk with recommended actions.

Qualifications

  • 6+ years in information security GRC, IT risk, audit, or compliance (hands-on delivery; not pure program leadership).
  • Experience supporting audits and control evidence in enterprise environments.
  • BFSI or other regulated-industry experience preferred (banking, payments, insurance, or capital markets).
  • Comfortable working with technical teams to translate controls into testable evidence.

Responsibilities

  • Support and maintain the information security governance framework, policies, standards, and control library.
  • Plan and execute security risk assessments; track findings, remediation owners, and closure evidence.
  • Support regulatory and audit engagement (e.g., SOC 1/2, ISO 27001, PCI DSS, BFSI/regulator-equivalent expectations).
  • Gather, organize, and quality-check audit and compliance evidence across security, IAM, cloud, and engineering teams.
  • Maintain risk registers, control testing schedules, exceptions/waivers, and compliance reporting packs.
  • Support third-party/vendor risk reviews and ongoing due-diligence evidence where required.
  • Coordinate with DevSecOps, IAM/CIAM, and security operations teams to map technical controls to GRC obligations.
  • Contribute to GRC runbooks, process documentation, and continuous improvement of compliance workflows.
  • Escalate material risk, audit, or compliance issues to senior leadership with clear impact and recommended actions.

Skills

GRC
Audit support
Regulatory compliance
Vendor risk

Tools

ServiceNow GRC
Archer

Job description

GRC Specialist Role Summary: Hands-on Governance, Risk, and Compliance (GRC) specialist supporting a banking/financial services client’s information security program- owning control design/evidence, risk assessments, audit/regulatory support, and policy/process hygiene day to day (individual contributor; not a deputy CISO role).

Key Responsibilities:
  • Support and maintain the information security governance framework, policies, standards, and control library
  • Plan and execute security risk assessments; track findings, remediation owners, and closure evidence
  • Support regulatory and audit engagement (e.g., SOC 1/2, ISO 27001, PCI DSS, and BFSI/regulator-equivalent expectations as applicable)
  • Gather, organize, and quality-check audit and compliance evidence across security, IAM, cloud, and engineering teams
  • Maintain risk registers, control testing schedules, exceptions/waivers, and compliance reporting packs
  • Support third-party/vendor risk reviews and ongoing due-diligence evidence where required
  • Coordinate with DevSecOps, IAM/CIAM, and security operations teams to map technical controls to GRC obligations
  • Contribute to GRC runbooks, process documentation, and continuous improvement of compliance workflows
  • Escalate material risk, audit, or compliance issues to senior leadership with clear impact and recommended actions
Required Experience:
  • 6+ years in information security GRC, IT risk, audit, or compliance (hands-on delivery; not pure program leadership)
  • Experience supporting audits and control evidence in enterprise environments
  • BFSI or other regulated-industry experience preferred (banking, payments, insurance, or capital markets)
  • Comfortable working with technical teams (security engineering, cloud, IAM) to translate controls into testable evidence
Core Technical Expertise:
  • Security governance, risk & compliance (GRC)
  • Control frameworks and audits: ISO 27001, SOC 1/2, PCI DSS (as applicable); NIST CSF familiarity a plus
  • Risk assessment, control testing, issue management, and remediation tracking
  • Policy, standard, and procedure development/maintenance
  • Audit evidence management and stakeholder coordination
  • Third-party/vendor risk fundamentals (preferred)
  • Familiarity with GRC tooling (e.g., ServiceNow GRC, Archer, or equivalent) preferred
Preferred Certifications:
  • CISA, CISM, ISO 27001 Lead Auditor/Implementer, CRISC, or equivalent (as applicable)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst
GRC Analyst

Exotel • Bengaluru

On-site
INR 800,000 - 1,200,000
Lead Security GRC Analyst
Lead Security GRC Analyst

Providence India • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Senior GRC Engineer
Senior GRC Engineer

Qualys • Maharashtra

On-site
INR 4,000,000 - 8,000,000
Senior Manager
Senior Manager

Pellera Technologies • India

On-site
INR 2,500,000 - 4,500,000
GRC Consultant
GRC Consultant

Lonvec Technologies Private Limited • Hyderabad

On-site
INR 1,200,000 - 2,200,000
GRC Analyst
GRC Analyst

AST Spacemobile • Bengaluru

On-site
INR 450,000 - 750,000
GRC Analyst
GRC Analyst

Exotel Techcom Pvt Ltd • Bengaluru

On-site
INR 600,000 - 900,000
Technical Manager
Technical Manager

Incedo Inc. • Gurugram District

On-site
INR 2,500,000 - 5,000,000
Senior Security GRC & ISO 27001 Manager
Senior Security GRC & ISO 27001 Manager

UST • Thiruvananthapuram

On-site
INR 1,500,000 - 2,100,000
GRC Analyst
GRC Analyst

Soffit Infrastructure Services (P) Ltd • Ernakulam

On-site
INR 800,000 - 1,200,000