GRC Specialist

NopalCyber

Hyderabad

On-site

INR 800,000 - 1,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading IT consulting firm in Hyderabad is seeking a detail-oriented GRC professional with expertise in SOC 2 and NIST compliance. This full-time role involves implementing and enhancing information security compliance programs, conducting risk assessments, and managing documentation for audits. Ideal candidates will have a Bachelor’s degree in Engineering, along with 5-8 years of relevant experience and knowledge of security domains. Strong analytical skills and an understanding of information security principles are essential.

Qualifications

  • Bachelor’s degree in Engineering or closely related technology development field.
  • 5-8 years of total experience with 2-4 years in relevant roles.
  • Certifications such as Security+, CEH, ISO 27001 Lead Implementer/Lead Auditor, CISA, CISM are valuable.

Responsibilities

  • Lead and support the implementation and maintenance of compliance programs.
  • Develop and align security policies with compliance frameworks.
  • Conduct risk assessments against SOC 2, NIST, and ISO standards.
  • Prepare documentation for audits and ensure audit readiness.
  • Support risk identification and mitigation processes.

Skills

SOC 2 compliance
NIST Cybersecurity Framework (CSF)
ISO 27001 controls
Risk assessment
Documentation management

Education

Bachelor’s degree in Engineering

Tools

Security+
CEH
ISO 27001 Lead Implementer
CISA
CISM

Job description

We are looking for a detail‑oriented and proactive GRC professional with hands‑on experience in SOC 2 Type 1 and Type 2, NIST CSF, NIST SP 800‑53 and ISO 27001 controls.

Job Responsibilities
  • Lead and support the implementation, maintenance, and continuous improvement of information security compliance programs, specifically focusing on SOC 2 Type 1 and Type 2, NIST Cybersecurity Framework (CSF), NIST Special Publications (SP 800‑53), and ISO 27001.
  • Develop, review, and update security policies, procedures, and guidelines to align with relevant compliance frameworks and regulatory requirements.
  • Conduct risk assessments and gap analyses against SOC 2, NIST, and ISO 27001 controls to identify areas for improvement and ensure audit readiness.
  • Prepare and compile documentation, evidence, and responses for audit requests efficiently and accurately.
  • Support the identification, assessment, and mitigation of information security risks in accordance with established risk management frameworks (e.g., NIST RMF).
  • Contribute to risk assessments and business impact analysis.
  • Maintain comprehensive documentation of security controls, compliance activities, and remediation plans.
  • Prepare regular reports on compliance status, key metrics, and areas of concern for management and stakeholders.
  • Perform comprehensive third‑party risk assessments to evaluate vendor compliance with information security policies.
  • Develop and maintain TPRM processes to monitor and mitigate risks associated with external vendors.
  • Ensure effective communication and documentation of third‑party risk assessments.
  • Assist in drafting and updating organizational policies and procedures for governance and compliance.
Job Specifications
Qualification
  • Bachelor’s degree in Engineering or closely related coursework in technology development disciplines
  • Certifications – Security+, CEH, ISO 27001 Lead Implementer/Lead Auditor, CISA, CISM (good to have, but not mandatory)
Experience
  • Total Experience: 5‑8 years
  • Total Experience: 2‑4 years
Knowledge and Experience
  • Demonstrable experience with the implementation and/or auditing of SOC 2 Type 1 and Type 2.
  • Solid understanding and practical experience with NIST Cybersecurity Framework (CSF) and NIST Special Publications (e.g., SP 800‑53).
  • Knowledge of various security domains such as network security, application security, data privacy, and vulnerability management.
  • Strong understanding of information security principles and related compliance controls. Ability to articulate the relevance of the security controls.
  • Experience in delivery of Information Security risk and compliance advisory services.
  • Experience in management consulting and information security audits.
  • Experience around technology risk assessments.
  • Hands‑on experience in GRC projects.
  • Proficient in preparation of reports, dashboards and documentation.
  • Ability to research and develop new risk‑based security offerings.
  • Comfortable working in a project‑based / client serving model.
Seniority level

Mid‑Senior level

Employment type

Full‑time

Job function

Consulting

Industry

IT Services and IT Consulting

Referrals increase your chances of interviewing at NopalCyber by 2x

Get notified about new Specialist jobs in Hyderabad, Telangana, India.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product GRC Consultant
Product GRC Consultant

CyRAACS™ • Bengaluru

On-site
INR 600,000 - 1,200,000
Senior GRC Analyst
Senior GRC Analyst

3M HEALTHCARE • Hyderabad

On-site
INR 1,500,000 - 2,200,000
Technical Manager
Technical Manager

Incedo Inc. • Gurugram District

On-site
INR 2,500,000 - 5,000,000
Consultant -GRC
Consultant -GRC

Value Point Systems Pvt Ltd • Bengaluru

On-site
GRC Engineer
GRC Engineer

Indian Institute of Technology Delhi (IIT Delhi) • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Senior GRC Analyst
Senior GRC Analyst

Qualys • Maharashtra

Hybrid
INR 1,500,000 - 2,500,000
GRC Consultant
GRC Consultant

AutomationEdge • Pune City

On-site
INR 350,000 - 500,000
Cyber Security Specialist
Cyber Security Specialist

Getinz Techno Services • Bengaluru

On-site
INR 2,500,000 - 4,200,000
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

844 Altera Semiconductor Technology India Pvt. Ltd. • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Senior GRC Analyst
Senior GRC Analyst

Tetuan Valley • India

On-site
INR 900,000 - 1,200,000
Variable Compensation