Senior GRC Analyst

Litmos

India

On-site

INR 2,400,000 - 3,200,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Litmos, the Learning Acceleration Platform, seeks a Senior GRC Analyst to own governance, risk, and compliance programs. You will lead policy development, risk assessments, and third-party risk, while guiding governance reporting to leadership and ensuring alignment with GDPR, SOC 2, ISO 27001 and other standards.

You will administer the GRC platform, respond to security questionnaires, and coordinate cross-functional remediation efforts with IT, Legal, HR, and Finance to strengthen Litmos

Qualifications

  • Bachelors degree in Information Security, Computer Science, or a related field (or equivalent experience)
  • 3-5 years of experience in GRC, IT audit, information security, or a closely related role
  • Working knowledge of at least two major compliance frameworks (NIST CSF, ISO 27001, SOC 2, HIPAA, PCI‑DSS, etc.)
  • Experience collecting audit evidence and managing audit engagements
  • Familiarity with GRC tools and platforms

Responsibilities

  • Develop, review, and maintain security policies, standards, and procedures, ensuring they remain current and aligned with business needs
  • Manage the policy exception tracking process, including intake, review, and escalation
  • Coordinate policy acknowledgment and sign-off across business units
  • Support and help improve the organizations security awareness training program
  • Prepare governance metrics and reporting for leadership and board-level stakeholders
  • Own and maintain the enterprise risk register, ensuring risks are accurately documented, scored, and tracked
  • Conduct risk assessments for new projects, systems, and vendors, as well as periodic reviews of existing risks
  • Facilitate risk scoring and prioritization sessions with business and technical stakeholders
  • Track risk treatment plans and follow up with owners to ensure timely remediation
  • Manage the third-party vendor risk assessment program, including questionnaires and ongoing monitoring
  • Support business impact analysis (BIA) and business continuity planning efforts
  • Map and maintain control libraries aligned to frameworks such as NIST CSF, ISO 27001, SOC 2, GDPR
  • Coordinate internal and external audit engagements, including evidence collection and stakeholder communication
  • Perform control testing and gap assessments, documenting findings and recommending remediation
  • Track open audit findings through to closure
  • Monitor regulatory and framework changes, assess organizational impact, and recommend updates
  • Support data privacy compliance activities related to GDPR, CCPA, or other applicable regulations
  • Own and administer the GRC platform (e.g., Archer, Vanta, Drata, ServiceNow GRC), driving adoption and continuous improvement
  • Lead responses to complex customer security questionnaires, RFPs, and due diligence requests
  • Serve as the compliance lead for incident response activities, ensuring documentation, notification obligations, and regulatory requirements are met
  • Act as the primary GRC point of contact for IT, Legal, HR, Finance, and business unit teams — driving control ownership and accountability across the organization

Skills

GRC
IT audit
Information security
Audit evidence

Education

Bachelor's degree in Information Security

Tools

Archer
ServiceNow GRC
Vanta
Drata

Job description

Job Description:

Are you looking for an opportunity to help solve one of todays biggest business challenges? AI is changing the pace of business, and organizations everywhere are struggling to help their workforce, partners, and customers keep up. At Litmos, were building the Learning Acceleration Platform that helps organizations build human capability faster—and were looking for people who are passionate about making a meaningful impact for customers while growing alongside a collaborative, people-first team.

Litmos is the Learning Acceleration Platform that helps organizations build capability faster, adapt at the speed business changes, and scale learning to anyone, anywhere. Combining an intuitive platform, AI-powered capabilities, trusted content, expert services, and a broad ecosystem of integrations, Litmos helps organizations accelerate workforce productivity, improve customer adoption and retention, enable high-performing partners, and reduce organizational risk through continuous learning.

Organizations such as Hewlett Packard Enterprise, Graco, Sabre, and Russell Mineral Equipment trust Litmos to accelerate learning across their workforce, partners, and customers. Today, more than 11K customers with 30 million learners across 150 countries and 37 languages use Litmos to build the capabilities their organizations need to succeed. Backed by Francisco Partners, one of the worlds leading technology investment firms, were investing in the future of learning—and the people who are building it. Learn more at www.litmos.com.

We are seeking an experienced and strategic Senior GRC Analyst to join our information security team. With 3-5 years of hands‑on experience, you will serve as a subject matter expert across governance, risk, and compliance — owning critical programs, driving process maturity, and acting as a trusted advisor to leadership and cross-functional stakeholders. This role goes beyond execution; you will shape the direction of our GRC program and ensure the organizations risk and compliance posture keeps pace with an evolving regulatory and threat landscape.

Responsibilities
Governance
  • Develop, review, and maintain security policies, standards, and procedures, ensuring they remain current and aligned with business needs
  • Manage the policy exception tracking process, including intake, review, and escalation
  • Coordinate policy acknowledgment and sign‑off across business units
  • Support and help improve the organizations security awareness training program
  • Prepare governance metrics and reporting for leadership and board‑level stakeholders
Risk Management
  • Own and maintain the enterprise risk register, ensuring risks are accurately documented, scored, and tracked
  • Conduct risk assessments for new projects, systems, and vendors, as well as periodic reviews of existing risks
  • Facilitate risk scoring and prioritization sessions with business and technical stakeholders
  • Track risk treatment plans and follow up with owners to ensure timely remediation
  • Manage the third‑party vendor risk assessment program, including questionnaires and ongoing monitoring
  • Support business impact analysis (BIA) and business continuity planning efforts
Compliance
  • Map and maintain control libraries aligned to frameworks such as NIST CSF, ISO 27001, SOC 2, GDPR
  • Coordinate internal and external audit engagements, including evidence collection and stakeholder communication
  • Perform control testing and gap assessments, documenting findings and recommending remediation
  • Track open audit findings through to closure
  • Monitor regulatory and framework changes, assess organizational impact, and recommend updates
  • Support data privacy compliance activities related to GDPR, CCPA, or other applicable regulations
Day‑to‑Day Operations
  • Own and administer the GRC platform (e.g., Archer, Vanta, Drata, ServiceNow GRC), driving adoption and continuous improvement
  • Lead responses to complex customer security questionnaires, RFPs, and due diligence requests
  • Serve as the compliance lead for incident response activities, ensuring documentation, notification obligations, and regulatory requirements are met
  • Act as the primary GRC point of contact for IT, Legal, HR, Finance, and business unit teams — driving control ownership and accountability across the organization
Qualifications
  • Bachelors degree in Information Security, Computer Science, Business, or a related field (or equivalent experience)
  • 3-5 years of experience in GRC, IT audit, information security, or a closely related role
  • Working knowledge of at least two major compliance frameworks (NIST CSF, ISO 27001, SOC 2, HIPAA, PCI‑DSS, etc.)
  • Experience collecting audit evidence and managing audit engagements
  • Familiarity with GRC tools and platforms
  • Strong written communication skills — able to translate technical risk concepts for non‑technical audiences
  • Highly organized with the ability to manage multiple workstreams and deadlines simultaneously
Nice to Have
  • Relevant certifications: CompTIA Security+, CISA, ComptTIA CC, CRISC, CGEIT, or CCSP
  • Experience with cloud environments (AWS, Azure, GCP) and cloud security frameworks
  • Exposure to data privacy regulations (GDPR, CCPA)
  • Experience responding to customer security questionnaires
  • Experience with AI laws and regulations
Salary Range:

₹24,00,000 to ₹32,00,000 plus 10% bonus

We are an equal opportunity workplace employer. We are committed to the values of Equal Employment Opportunity and provide accessibility accommodations to applicants with physical and/or mental disabilities.

Applicants will receive consideration for employment without regard to their age, race, religion, national origin, ethnicity, age, gender (including pregnancy, childbirth, et al), sexual orientation, gender identity or expression, protected veteran status, or disability.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

844 Altera Semiconductor Technology India Pvt. Ltd. • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

Altera • Bengaluru

On-site
INR 3,000,000 - 4,500,000
Senior GRC Analyst
Senior GRC Analyst

Tetuan Valley • India

On-site
INR 900,000 - 1,200,000
Variable Compensation
Governance, Risk and Compliance (GRC) Specialist
Governance, Risk and Compliance (GRC) Specialist

Career Guideline • Pune District

On-site
INR 1,500,000 - 2,500,000
Senior Manager – GRC
Senior Manager – GRC

ITHR 360° CONSULTING FZE • Delhi

On-site
INR 1,800,000 - 3,000,000
Senior GRC Analyst
Senior GRC Analyst

3M HEALTHCARE • Hyderabad

On-site
INR 1,500,000 - 2,200,000
Product GRC Consultant
Product GRC Consultant

CyRAACS™ • Bengaluru

On-site
INR 600,000 - 1,200,000
Security Analyst
Security Analyst

Litmos • Pune District

On-site
INR 2,400,000 - 3,200,000
GRC Analyst
GRC Analyst

Security Brigade • Delhi, Mumbai

Hybrid
INR 60,000 - 80,000
Competitive salary aligned to experience
Hybrid + remote-friendly
Sponsorship for relevant certifications
+2
GRC Analyst
GRC Analyst

Soffit Infrastructure Services (P) Ltd • Ernakulam

On-site
INR 800,000 - 1,200,000