Information Security Analyst

Xceedance

Haryana

On-site

INR 1,200,000 - 1,800,000

Full time

10 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Xceedance in Gurgaon/Noida seeks an experienced GRC Consultant to coordinate client security questionnaires and support SOX-related activities. The role requires 5–8 years of experience in governance, risk, and compliance coordination with a strong process mindset.

You will collaborate with Security Compliance, Legal, HR, and vendors, maintain a SharePoint evidence repository, and ensure timely, accurate submissions while upholding client confidentiality and data integrity.

Qualifications

  • Bachelor's degree in IT/IS/Security or related field.
  • 5+ years in GRC coordination and compliance operations.
  • Advanced Excel with macros and large datasets.
  • Strong English communication and cross-functional coordination.

Responsibilities

  • Serve as the single point of coordination for client-issued IT security/compliance questionnaires.
  • Log incoming requests and manage ~60-day turnaround commitments.
  • Route questionnaires to Security Compliance team and coordinate with SMEs.
  • Maintain the Received/Working/Sent folders and SharePoint response repository; reuse validated answers.
  • Cross-check current-cycle responses against prior submissions and escalate ambiguities for review.

Skills

GRC coordination
Client coordination
Cross-functional coordination
Excel (Advanced)
SharePoint proficiency
Documentation management
English communication
Attention to detail

Education

Bachelor's degree in IT/IS/Security

Tools

MS Word
SharePoint
Excel macros
GRC tools
Security questionnaire platforms

Job description

Experience Required:

5–8 Years

Location:

Gurgaon/ Noida

Role:

GRC Consultant

Security Questionnaire Manageme
  • nt· Serve as the single point of coordination for client-issued IT security/compliance questionnaires — cyclic and bi-annual in natur
  • e.· Log incoming requests from the shared distribution mailbox, loop in the account manager, and set/manage the standard ~60-day turnaround commitment to client s.
  • · Route each questionnaire to the corporate Security Compliance team, who own roughly 90% of standard responses, and independently coordinate with business subject-matter experts to complete the remaining client‑ or business‑specific question
  • Maintain the Received / Working / Sent folder structure and the historical SharePoint response repository; reuse and adapt previously validated answers to maintain consistency and speed of turnaroun
  • d.· Cross-check current-cycle responses against prior submissions for the same client, flag inconsistencies or outdated answers, and elevate ambiguous or sensitive items for review before final submissio
n.Access Recertification Manageme
  • nt· Coordinate the semi-annual access recertification cycle (for H1 typically starting January/February and completing through June, aligned with SOX audit timing) covering in-scope applications and shared-data security object
  • s.· Confirm application inventory and scope with application owners; submit and track data-pull requests to the Security Administration team via the internal ticketing syste
  • m.· Consolidate and clean raw access-extract data (application ownership details, AD extracts, user profiles) into a standardized Excel workbook, using macros, formulas, and pivot tables to de-duplicate entries and merge rows where necessary (with multi-group access details
  • ) Load the consolidated dataset into SharePoint, distribute recertification requests to business and IT reviewers, and track review decisions through to completio
  • n.· Compile audit-ready evidence packages (timestamps, reviewer decisions, access-removal confirmations) to support internal IT audit and SOX audit requirement
  • s. Coordinate with Legal, HR, or other business stakeholders as needed for non-standard questionnaire items and elevate unique/new/non-standard client audit requests to senior team member
s.Additional Activiti
  • es· Coordinate mandatory bi-annual security/privacy awareness training for employees and consultants with access to personal information — working with HR and the employee talent portal and managing SharePoint acknowledgment surveys or vendor points of contact for consultant population
  • s.· Support the annual BCP/DR test cycle: confirm test dates with application owners, ensure business tester availability, track communications, and document test outcomes and remediation ownershi
p.REQUIRED SKILLS & QUALIFICATIO
  • NS· Bachelor's degree in either Comp Science, Information Systems, Information Security, Privacy, Risk Management, IT/Information Systems Business Administration or a related fiel
  • d.· Overall 5+ years of experience with 3–5 years of experience in GRC coordination, compliance operations, IT audit/vendor-risk support, client assurance, and with project coordination roles; deep technical security background is not require
  • d.· Advanced Excel skills, including documentation, pivot tables, macros, formula-based reconciliation, and large-dataset consolidation/cleanu
  • p.· Strong working knowledge of MS Word, SharePoint, and shared-drive documentation management practice
  • s.· Excellent written and verbal English communication skills, with confidence handling client-facing as well as internal leadership correspondenc
  • e.· Demonstrated ability to coordinate across cross-functional stakeholders — IT, Security, Legal, HR, Business, and third-party vendors etc. and drive follow-ups to closur
  • e.· High attention to detail and consistency when validating recurring or comparative data set
  • s.· Ability to handle sensitive, PII-adjacent information responsibly and maintain confidentiality (the role does not require direct access to client applications or systems
  • ) Availability to overlap with US Eastern Time hours (through at least 12:00 PM ET) for real-time collaboration with the client teams/stakeholder
PREFERRED ATTRIBUT
  • ES· Familiarity with vendor/third-party risk concepts (e.g., SIG questionnaires) is an advantage; formal GRC or security certifications are good to have but not mandatory for this rol
  • e.· Prior experience supporting insurance, reinsurance, or financial services client
  • s.· Experience with GRC tools, security questionnaire platforms, audit evidence repositories, or workflow tracking tools is an advantag
  • e.· Good understanding of information security, privacy, risk, access management, business continuity, and compliance concepts; familiarity with ISO 27001, ISO 27701, SOC/SOC 2, NIST, GDPR, HIPAA etc. or client audit requirements is preferre
  • d.· Certifications such as ISO 27001 Foundation/Internal Auditor, ISO 27701, ISO/IEC 27001:2022 LI or LA, CISA, CRISC, or equivalent are good to hav
  • e.· Self-driven with strong ownership; comfortable ramping up through an apprenticeship/knowledge-transfer period alongside the client team before working semi-independentl
  • y.· Comfortable in a coordination-heavy role with cyclical rather than constant workload peaks, and able to flex into ad hoc requests as they aris
e.ROLE FOC
  • USThis role is focused on client security assurance, questionnaire and access-recertification coordination, security awareness and training facilitation, BCP/DR facilitation and management, documentation management, and cross-functional stakeholder follow-up — however not on hands-on technical security wor
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Analyst
Information Security Analyst

Xceedance • Gurugram District

On-site
INR 800,000 - 1,200,000
Sr Security GRC & ISO 27001 Manager
Sr Security GRC & ISO 27001 Manager

UST • Thiruvananthapuram

On-site
INR 2,500,000 - 4,000,000
Senior Security GRC & ISO 27001 Manager
Senior Security GRC & ISO 27001 Manager

UST • Thiruvananthapuram

On-site
INR 1,500,000 - 2,100,000
Information Security GRC Analyst
Information Security GRC Analyst

Perydot • Mumbai

On-site
INR 600,000 - 1,000,000
Product GRC Consultant
Product GRC Consultant

CyRAACS™ • Bengaluru

On-site
INR 600,000 - 1,200,000
Information Security GRC Manager
Information Security GRC Manager

Mount Talent Consulting • Mumbai

On-site
INR 3,000,000 - 5,000,000
Senior GRC Analyst
Senior GRC Analyst

3M HEALTHCARE • Hyderabad

On-site
INR 1,500,000 - 2,200,000
Sr Engineer, Governance, Risk & Compliance
Sr Engineer, Governance, Risk & Compliance

NextGen Healthcare India • Bengaluru

On-site
INR 1,600,000 - 2,800,000
Staff Risk & Compliance Analyst
Staff Risk & Compliance Analyst

GE Vernova Consulting • Hyderabad, Bengaluru

On-site
INR 600,000 - 900,000
Relocation assistance provided
Staff Risk & Compliance Analyst
Staff Risk & Compliance Analyst

GE-Vernova- • Bengaluru

Hybrid
INR 800,000 - 1,500,000
Relocation assistance