Senior GRC Analyst

3M HEALTHCARE

Hyderabad

On-site

INR 1,500,000 - 2,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

3M HEALTHCARE is seeking a Senior GRC Analyst to lead compliance assessments for standards including NIST 800-171, ISO 27001, NIST 800-53 (FedRAMP), PCI, MLPS, and IRAP, while driving broader security compliance initiatives.

You will coordinate audits, manage risk across teams, and implement improvements to strengthen the organization’s security posture, working closely with stakeholders and auditors.

Qualifications

  • 8+ years of experience in cybersecurity programs, audits, risk management, compliance, or remediation.
  • Experience with cloud platforms (AWS, Azure, Google Cloud).
  • Familiarity with NIST 800-171, NIST RMF, PCI-DSS, SOC 2, ISO 27001/27701 and related frameworks.

Responsibilities

  • Lead audits for frameworks including ISO 27001/27701, PCI-DSS, NIST 800-171, NIST 800-53 (FedRAMP), and IRAP.
  • Utilize AI/automation tools to enhance GRC processes and workflows.
  • Manage risk, compliance, and governance initiatives across teams.
  • Coordinate with process owners, auditors, and consultants to ensure findings are tracked and addressed.
  • Conduct risk assessments, security audits, and third‑party/vendor risk reviews.

Skills

Auditing & regulatory compliance
Risk assessment
Communication skills
Stakeholder management
Analytical thinking

Education

Bachelor's degree in Information Systems/Computer Science/Information Security

Tools

AWS
Azure
GCP

Job description

Responsibilities

We are looking for an exceptional Senior GRC Analyst to join our growing team. In this role, you will lead compliance assessments for frameworks such as NIST 800-171, ISO 27001, NIST 800-53 (FedRAMP), PCI, MLPS and IRAP, while also driving broader security compliance efforts. The ideal candidate will use strong analytical, communication, and problem‑solving skills to evaluate controls, identify gaps, and recommend improvements across security domains. You will also be responsible for:

  • Lead and participate in both internal and external audits for frameworks including ISO 27001/27701, PCI‑DSS, NIST 800-171, NIST 800‑53 (FedRamp), and IRAP
  • Experience using or exploring AI/automation tools to enhance, streamline, or scale Governance, Risk, and Compliance (GRC) processes and workflows
  • Manage and oversee risk, compliance, and governance initiatives across teams
  • Coordinate with process owners, control owners, auditors, and consultants to ensure findings are tracked and addressed
  • Conduct risk assessments, security audits, and third‑party/vendor risk reviews
  • Review contracts to ensure security and compliance requirements are met
  • Identify process gaps and recommend improvements to enhance the organization’s security posture
  • Communicate risks and compliance requirements clearly to both technical and non‑technical stakeholders
  • Perform regular user access reviews
  • Develop and track remediation plans for identified risks and issues
  • Maintain and update the risk register
  • Oversee vendor security assurance processes
  • Collaborate with stakeholders to design and implement effective internal controls aligned with regulatory standards
  • Support risk and security discussions across cross‑functional teams
  • Build strong working relationships across departments
  • Take on additional responsibilities as needed
Requirements
Qualifications / Experience / Technical Skills

Please note that the working hours for this position are from 2:00 PM to 11:00 PM IST (overlap with U.S. Pacific Time required)

  • 8+ years of experience in cybersecurity programs, audits, risk management, compliance, or remediation
  • Experience working with cloud platforms such as AWS, Azure, or Google Cloud
  • Proven ability to negotiate and prioritize risk remediation with internal stakeholders
  • Bachelor’s degree in Information Systems, Computer Science, Information Security, or a related field
  • Strong understanding of security controls, including cloud environments, firewalls, IDS/IPS, and vulnerability management
  • Familiarity with NIST 800-171 and NIST Risk Management Framework (NIST 800-53)
  • Experience auditing frameworks such as PCI‑DSS, SOC 2, and ISO 27001/27701
  • Relevant certifications (CISSP, CISA, PCI ISA, ISO, or similar) are preferred
  • Ability to manage multiple priorities independently with minimal supervision
Soft Skills / Personal Characteristics
  • Strong communication skills with the ability to translate compliance requirements into technical actions
  • High energy and adaptability in a fast‑paced environment
  • Strong collaboration and a knowledge‑sharing mindset
  • Excellent time management and organizational skills
  • High attention to detail, integrity, and ethical standards
  • Willingness to learn and take on new challenges
Additional requirements
  • May involve some international travel
  • This position requires overlap with U.S. Pacific Time (PST) working hours. Candidates should be available and flexible to work from 2:00 PM to 11:00 PM IST.
  • Strong hands‑on experience with PCI audits, ISO 27001, NIST 800-171, FedRamp, SOC 2, and potentially IRAP is required.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security GRC Analyst
Lead Security GRC Analyst

Providence India • Hyderabad

On-site
INR 2,500,000 - 4,000,000
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

844 Altera Semiconductor Technology India Pvt. Ltd. • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Senior GRC Analyst - 26157
Senior GRC Analyst - 26157

Pearl Street Technologies • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

Altera • Bengaluru

On-site
INR 3,000,000 - 4,500,000
Product GRC Consultant
Product GRC Consultant

CyRAACS™ • Bengaluru

On-site
INR 600,000 - 1,200,000
Technical Manager
Technical Manager

Incedo Inc. • Gurugram District

On-site
INR 2,500,000 - 5,000,000
Senior GRC Analyst - 26157
Senior GRC Analyst - 26157

Enverus • India

On-site
INR 800,000 - 1,200,000
Lead GRC
Lead GRC

Ashley Global Capability Center • Chennai District

On-site
INR 1,200,000 - 1,800,000
GRC Specialist
GRC Specialist

NopalCyber • Hyderabad

On-site
INR 800,000 - 1,200,000
Senior GRC Analyst
Senior GRC Analyst

Tetuan Valley • India

On-site
INR 900,000 - 1,200,000
Variable Compensation