Information Security GRC Consultant

Aarcalev Technology Solutions

India

Remote

INR 900,000 - 1,500,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Fully remote role
Exposure to global compliance frameworks
Professional growth opportunities

Job summary

A cybersecurity solutions provider is seeking an Information Security GRC Consultant to lead governance, risk, and compliance projects. The role involves defining GRC strategy, conducting risk assessments, and ensuring compliance with various regulations. Candidates should have 3–5 years of experience in information security and relevant certifications. This is a fully remote position offering opportunities for professional growth in a collaborative environment.

Qualifications

  • 3–5 years of experience in information security, risk management, or compliance roles.
  • Experience in cybersecurity governance and regulatory compliance.
  • Hands-on experience with ISO certifications and audits.
  • Strong analytical, organizational, and communication skills.
  • Dynamic, hardworking, and eager to grow within a fast‑paced global environment.
  • 3–5 years of experience in information security, risk management, or compliance roles.
  • Experience in cybersecurity governance, risk, and regulatory compliance within organizations
  • knowledge of India, global and Middle East data protection and security regulations
  • Hands‑on experience managing ISO certifications, regulatory audits, and multi‑framework compliance programs
  • Experience in third‑party risk management, policy governance, and enterprise risk reporting
  • Require flexibility in working hours, to manage India, Middle East and Africa timings.

Responsibilities

  • Define and execute the Information Security GRC strategy.
  • Assist in designing and maintaining cybersecurity policies.
  • Conduct risk assessments to identify vulnerabilities.
  • Monitor adherence to regulatory requirements (e.g., DPDP, GDPR, NDPA, ISO 27001/ISO 20000/ ISO 22301, NIST 800-53, SOC 2, DESC, PDPL, PCI-DSS, HIPAA, HITRUST, NIS 2, ISO 21434 etc.). Experience with country specific regulations such as SAMA, NCA ECC, are highly desirable.
  • Conduct risk assessments to identify vulnerabilities and compliance gaps.
  • Collaborate with stakeholders to recommend mitigation strategies and track remediation progress.
  • Support internal and external audits, ensuring timely and accurate documentation.
  • Contribute to security awareness initiatives and training programs.
  • Stay updated on emerging cybersecurity threats, frameworks, and regulations.
  • Provide input to enhance GRC processes and tools for scalability across markets.
  • Technical experience and skills in controls design and documentation are highly desirable

Skills

Information Security
Risk Management
Compliance
Analytical skills
Communication skills
ISO 27001
CISM
CRISC
CGEIT
CISSP
ISO 27001 Lead Implementer

Education

Bachelor's degree in Information Security or related field
Professional certifications (CISM, CRISC, CISSP)

Tools

ISO 27001 Lead Implementer

Job description

Aarcalev is looking for an Information Security GRC Consultant to play a key role in delivering cybersecurity governance, risk, and compliance projects across our diverse, multi‑market operations. In this role, you’ll help support our clients in shaping enterprise‑wide GRC strategy, drive regulatory confidence, and embed security accountability across business, technology, and operations.

Key Responsibilities
  • Define and execute the Information Security GRC strategy aligned with enterprise risk management and business growth
  • Assist in designing, implementing, and maintaining cybersecurity policies, standards, and procedures
  • Support the institutionalization of GRC frameworks across multiple markets and business units.
  • Monitor adherence to regulatory requirements (e.g., DPDP, GDPR, NDPA, ISO 27001/ISO 20000/ ISO 22301, NIST 800-53, SOC 2, DESC, PDPL, PCI-DSS, HIPAA, HITRUST, NIS 2, ISO 21434 etc.). Experience with country specific regulations such as SAMA, NCA ECC, are highly desirable.
  • Conduct risk assessments to identify vulnerabilities and compliance gaps.
  • Collaborate with stakeholders to recommend mitigation strategies and track remediation progress.
  • Support internal and external audits, ensuring timely and accurate documentation.
  • Contribute to security awareness initiatives and training programs.
  • Stay updated on emerging cybersecurity threats, frameworks, and regulations.
  • Provide input to enhance GRC processes and tools for scalability across markets.
  • Technical experience and skills in controls design and documentation are highly desirable
Qualifications
  • Bachelor’s degree in Information Security, Computer Science, Cybersecurity, Risk Management,or related field
  • Professional certifications such as CISM, CRISC, CGEIT, CISSP, ISO 27001 Lead Implementer.
  • Ability to work independently in a remote, multicultural environment.
  • Strong analytical, organizational, and communication skills.
  • Dynamic, hardworking, and eager to grow within a fast‑paced global environment.
  • 3–5 years of experience in information security, risk management, or compliance roles.
  • Experience in cybersecurity governance, risk, and regulatory compliance within organizations
  • knowledge of India, global and Middle East data protection and security regulations
  • Hands‑on experience managing ISO certifications, regulatory audits, and multi‑framework compliance programs
  • Experience in third‑party risk management, policy governance, and enterprise risk reporting
  • Require flexibility in working hours, to manage India, Middle East and Africa timings.
What we offer:
  • Fully remote role, with need to travel within or outside of India as needed.
  • Exposure to complex, multi‑market operations and global compliance frameworks.
  • Professional growth opportunities in cybersecurity and GRC.
  • Collaborative, inclusive, and innovative work culture.
How to Apply

If you’re passionate about cybersecurity governance and eager to grow your career in GRC, we’d love to hear from you! Please submit your CV (mandatory) and a brief cover letter (optional) outlining your interest and relevant experience.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

Power Bridge • Arishinakunte

On-site
INR 1,200,000 - 2,400,000
Health insurance
Long-term benefit savings plan with em
Professional development opportunities
Cybersecurity Lead - GRC
Cybersecurity Lead - GRC

Medusind • Mumbai

On-site
INR 2,500,000 - 4,500,000
Senior GRC Analyst
Senior GRC Analyst

Tetuan Valley • India

On-site
INR 900,000 - 1,200,000
Variable Compensation
Lead -Governance, Risk and Compliance (GRC)
Lead -Governance, Risk and Compliance (GRC)

ARCON • Mumbai

On-site
INR 1,500,000 - 2,500,000
Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

Powerbridge • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Health insurance
Long-term benefit savings plan
Professional development opportunities
Cybersecurity Lead - GRC
Cybersecurity Lead - GRC

Medusind Solutions, Inc. • Mumbai

On-site
INR 1,500,000 - 2,100,000
Cybersecurity - Risk & Compliance Analyst
Cybersecurity - Risk & Compliance Analyst

Scybers • Chennai District

On-site
INR 900,000 - 1,500,000
Senior Role - GRC & Infosec
Senior Role - GRC & Infosec

NPCI Bharat BillPay Limited • Mumbai

On-site
INR 2,000,000 - 3,000,000
Infosec Analyst
Infosec Analyst

super.money • Bengaluru

On-site
INR 900,000 - 1,500,000
Competitive compensation
Shape GRC for a top UPI company in I
Sr. Information Security Engineer (GRC)
Sr. Information Security Engineer (GRC)

Osttra • Gurugram District

On-site
INR 1,800,000 - 2,600,000
The Trust employee ownership plan