GRC Specialist

NopalCyber

Hyderabad

On-site

INR 800,000 - 1,200,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

A leading IT consulting firm in Hyderabad is seeking a detail-oriented GRC professional with expertise in SOC 2 and NIST compliance. This full-time role involves implementing and enhancing information security compliance programs, conducting risk assessments, and managing documentation for audits. Ideal candidates will have a Bachelor’s degree in Engineering, along with 5-8 years of relevant experience and knowledge of security domains. Strong analytical skills and an understanding of information security principles are essential.

Qualifications

  • Bachelor’s degree in Engineering or closely related technology development field.
  • 5-8 years of total experience with 2-4 years in relevant roles.
  • Certifications such as Security+, CEH, ISO 27001 Lead Implementer/Lead Auditor, CISA, CISM are valuable.

Responsibilities

  • Lead and support the implementation and maintenance of compliance programs.
  • Develop and align security policies with compliance frameworks.
  • Conduct risk assessments against SOC 2, NIST, and ISO standards.
  • Prepare documentation for audits and ensure audit readiness.
  • Support risk identification and mitigation processes.

Skills

SOC 2 compliance
NIST Cybersecurity Framework (CSF)
ISO 27001 controls
Risk assessment
Documentation management

Education

Bachelor’s degree in Engineering

Tools

Security+
CEH
ISO 27001 Lead Implementer
CISA
CISM

Job description

We are looking for a detail‑oriented and proactive GRC professional with hands‑on experience in SOC 2 Type 1 and Type 2, NIST CSF, NIST SP 800‑53 and ISO 27001 controls.

Job Responsibilities
  • Lead and support the implementation, maintenance, and continuous improvement of information security compliance programs, specifically focusing on SOC 2 Type 1 and Type 2, NIST Cybersecurity Framework (CSF), NIST Special Publications (SP 800‑53), and ISO 27001.
  • Develop, review, and update security policies, procedures, and guidelines to align with relevant compliance frameworks and regulatory requirements.
  • Conduct risk assessments and gap analyses against SOC 2, NIST, and ISO 27001 controls to identify areas for improvement and ensure audit readiness.
  • Prepare and compile documentation, evidence, and responses for audit requests efficiently and accurately.
  • Support the identification, assessment, and mitigation of information security risks in accordance with established risk management frameworks (e.g., NIST RMF).
  • Contribute to risk assessments and business impact analysis.
  • Maintain comprehensive documentation of security controls, compliance activities, and remediation plans.
  • Prepare regular reports on compliance status, key metrics, and areas of concern for management and stakeholders.
  • Perform comprehensive third‑party risk assessments to evaluate vendor compliance with information security policies.
  • Develop and maintain TPRM processes to monitor and mitigate risks associated with external vendors.
  • Ensure effective communication and documentation of third‑party risk assessments.
  • Assist in drafting and updating organizational policies and procedures for governance and compliance.
Job Specifications
Qualification
  • Bachelor’s degree in Engineering or closely related coursework in technology development disciplines
  • Certifications – Security+, CEH, ISO 27001 Lead Implementer/Lead Auditor, CISA, CISM (good to have, but not mandatory)
Experience
  • Total Experience: 5‑8 years
  • Total Experience: 2‑4 years
Knowledge and Experience
  • Demonstrable experience with the implementation and/or auditing of SOC 2 Type 1 and Type 2.
  • Solid understanding and practical experience with NIST Cybersecurity Framework (CSF) and NIST Special Publications (e.g., SP 800‑53).
  • Knowledge of various security domains such as network security, application security, data privacy, and vulnerability management.
  • Strong understanding of information security principles and related compliance controls. Ability to articulate the relevance of the security controls.
  • Experience in delivery of Information Security risk and compliance advisory services.
  • Experience in management consulting and information security audits.
  • Experience around technology risk assessments.
  • Hands‑on experience in GRC projects.
  • Proficient in preparation of reports, dashboards and documentation.
  • Ability to research and develop new risk‑based security offerings.
  • Comfortable working in a project‑based / client serving model.
Seniority level

Mid‑Senior level

Employment type

Full‑time

Job function

Consulting

Industry

IT Services and IT Consulting

Referrals increase your chances of interviewing at NopalCyber by 2x

Get notified about new Specialist jobs in Hyderabad, Telangana, India.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC Consultant @ Mumbai
GRC Consultant @ Mumbai

Quess IT Solutions • Mumbai

On-site
INR 1,800,000 - 2,400,000
Cyber Security GRC Consultant @ Mumbai
Cyber Security GRC Consultant @ Mumbai

Quess IT Solutions • Mumbai

On-site
INR 1,600,000 - 2,800,000
Product GRC Consultant
Product GRC Consultant

CyRAACS™ • Bengaluru

On-site
INR 600,000 - 1,200,000
GRC - Security Analyst
GRC - Security Analyst

Jobgether • India

On-site
INR 1,200,000 - 1,800,000
Fully remote in India
Full-time employment
Exposure to multiple security framesk—
+2
Senior GRC Analyst
Senior GRC Analyst

3M HEALTHCARE • Hyderabad

On-site
INR 1,500,000 - 2,200,000
Consultant-Cyber Security Audit Group
Consultant-Cyber Security Audit Group

Codians • Delhi

On-site
INR 900,000 - 1,500,000
Consultant -GRC
Consultant -GRC

Value Point Systems Pvt Ltd • Bengaluru

On-site
INR 111,600 - 279,000
Business Continuity Manager @ Mumbai
Business Continuity Manager @ Mumbai

Quess IT Solutions • Mumbai

On-site
INR 1,400,000 - 2,000,000
GRC Analyst / GRC Specialist (Information Security)_True Balance- NBFC
GRC Analyst / GRC Specialist (Information Security)_True Balance- NBFC

True Credits Pvt. Ltd. • Gurugram District

On-site
INR 1,200,000 - 2,400,000
Governance, Risk & Compliance (GRC) Specialist
Governance, Risk & Compliance (GRC) Specialist

Guideline Inc • Pune District

On-site
INR 2,250,000 - 2,750,000
Travel up to 10%
US shift