GRC Specialist

Aviva India

Gurugram District

On-site

INR 2,500,000 - 4,200,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Aviva India in Gurugram is seeking an experienced IT Risk & Cybersecurity GRC professional to oversee governance, internal audit readiness, regulatory compliance posture and user access review framework within a regulated insurance environment.

The role will drive IRDAI/CERT-IN compliance, risk assessments, control testing, and executive risk reporting with a hands-on approach to audits as auditee and reviewer across IT and cybersecurity domains.

Qualifications

  • 6+ years of IT risk and cybersecurity governance, risk and compliance experience.
  • Experience with regulatory audits and internal audit readiness in regulated industries.
  • Hands-on in third-party risk management and control testing.
  • Familiar with IT risk lifecycle, risk assessment, and risk reporting.

Responsibilities

  • Strong understanding of IT Risk Management lifecycle (Integrated Risk Management, Risk and Control Self-Assessment, Information Risk Assessment, Business Impact Assessment).
  • Perform risk assessments and control testing across IT and cybersecurity domains.
  • Identify control gaps and design new controls aligned with evolving threat landscape.
  • Track and ensure timely closure of audit observations and risk issues.
  • Maintain risk registers and document risk acceptance where applicable.
  • Coordinate security incident reporting, root cause analysis and remediation tracking.

Skills

IT Risk Management
Cybersecurity
GRC
Regulatory compliance
Audit readiness
IRDAI/CERT-IN compliance

Tools

RBAC
PAM
UAR

Job description

Experience: ~6 Years

Industry: Insurance (Life/General/Health)/BFSI

Role Overview

We are seeking an experienced IT Risk & Cybersecurity GRC professional (6+ years) to oversee our governance, internal audit readiness, regulatory compliance posture and user access review framework within a regulated insurance environment.

The role will play a critical part in managing internal audits, IRDAI/CERT-IN compliance, user access governance, third-party risk, control testing and executive risk reporting.

The ideal candidate must have hands‑on experience as both:

  • An auditee for regulatory and internal audits
  • A control assessor / reviewer conducting independent internal reviews
Key Responsibilities
  • Strong understanding of IT Risk Management lifecycle (Integrated Risk Management, Risk and Control Self-Assessment, Information Risk Assessment, Business Impact Assessment)
  • Perform risk assessments and control testing across IT and cybersecurity domains
  • Identify control gaps and design new controls aligned with evolving threat landscape
  • Track and ensure timely closure of audit observations and risk issues
  • Maintain risk registers and document risk acceptance where applicable
  • Coordinate security incident reporting, root cause analysis and remediation tracking.
Internal & Regulatory Audit Management
  • Act as primary auditee for:
  • IRDAI Cyber Security Audits
  • CERT-IN compliance
  • Internal audits (including Big 4)
  • Coordinate evidence submission and stakeholder responses
  • Conduct internal mock audits to assess control effectiveness
  • Ensure 100% closure of audit issues within agreed timelines
  • Track remediation and report to senior leadership
User Access Governance
  • Deep understanding of:
  • Privileged Access Reviews
  • Normal User Access Reviews
  • Role-based access control (RBAC)
  • Segregation of Duties (SoD)
  • Joiner-Mover-Leaver (JML) process
  • Conduct periodic UAR across applications and infrastructure
  • Validate access appropriateness and least privilege principles
  • Coordinate with business owners and application teams for certifications
  • Review PAM controls and session monitoring
  • Publish interim and final access review reports
Third Party Risk Management
  • Conduct third-party risk assessments during onboarding in accordance to the organization’s risk tolerance
  • Perform annual continuous risk reassessment
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Technical Manager
Technical Manager

Incedo Inc. • Gurugram District

On-site
INR 2,500,000 - 5,000,000
GRC Manager - Cyber
GRC Manager - Cyber

Cubical Operations LLP • Chennai District

On-site
INR 800,000 - 1,200,000
IT GRC Lead
IT GRC Lead

DMart • Thane

On-site
INR 1,500,000 - 2,500,000
GRC Manager/ GRC Lead
GRC Manager/ GRC Lead

Riskpro India Ventures • Mumbai

On-site
INR 1,000,000 - 1,500,000
Assistant Manager - Cyber Security - IT-GRC
Assistant Manager - Cyber Security - IT-GRC

BDO India • Bengaluru Urban

On-site
INR 1,200,000 - 1,800,000
Required Skillset
Required Skillset

eProtect 360 • Mumbai

On-site
INR 2,000,000 - 3,500,000
GRC Analyst
GRC Analyst

Soffit Infrastructure Services (P) Ltd • Ernakulam

On-site
INR 800,000 - 1,200,000
GRC Analyst
GRC Analyst

Security Brigade • Delhi, Mumbai

Hybrid
INR 60,000 - 80,000
Competitive salary aligned to experience
Hybrid + remote-friendly
Sponsorship for relevant certifications
+2
IT Risk Analyst
IT Risk Analyst

Sayyam Investments Private Limited • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Lead GRC
Lead GRC

Ashley Global Capability Center • Chennai District

On-site
INR 1,200,000 - 1,800,000