Senior / Principal GRC Analyst

844 Altera Semiconductor Technology India Pvt. Ltd.

Bengaluru

On-site

INR 2,000,000 - 3,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

844 Altera Semiconductor Technology India Pvt. Ltd. is seeking a Senior / Principal GRC Analyst to architect and lead enterprise governance, risk, and compliance programs. This role demands strong hands-on cybersecurity knowledge and deep regulatory expertise applicable to ISO, GDPR, and CMMC.

The ideal candidate will have over 7 years' experience managing compliance programs, translating security frameworks into business-aligned outcomes, mentoring junior professionals, and interfacing with various stakeholders.

Qualifications

  • 7–12+ years of experience in GRC, security, privacy, or risk management.
  • Proven ownership of ISO 27001, GDPR/CCPA, and CMMC or NIST 800-171 programs.
  • Strong technical and regulatory interpretation skills.

Responsibilities

  • Define and maintain a risk-based GRC architecture aligned to ISO, NIST and regulatory requirements.
  • Lead enterprise, third-party, cloud, and AI-specific risk assessments.
  • Translate security architectures into compliant policies and standards.

Skills

Cybersecurity knowledge
Regulatory expertise
Risk management
Data protection
Compliance assessments
Incident response

Education

ISO 27001 Lead Implementer / Lead Auditor
CISSP
CISA
CRISC
CIPM
CIPP/US
CIPP/E

Tools

Microsoft Purview
Microsoft Defender
Microsoft Entra ID

Job description

Senior / Principal GRC Analyst

The Senior / Principal GRC Analyst is a senior individual contributor responsible for architecting, leading, and scaling enterprise governance, risk, and compliance programs across highly regulated, technology‑driven environments. This role owns implementation and continuous improvement of ISO/IEC 27001, ISO/IEC 42001 (AI Management Systems), GDPR, CCPA/CPRA, and CMMC, and acts as a trusted advisor to security leadership, engineering, legal, and executive stakeholders. The role requires strong hands‑on cybersecurity knowledge, deep regulatory expertise, and the ability to translate technical security architectures into audit‑ready, business‑aligned compliance outcomes.

Core Responsibilities (All Environments)
  • Define and maintain a risk‑based GRC architecture aligned to ISO, NIST, privacy, and regulatory requirements.
  • Lead end‑to‑end implementations of:
    • ISO/IEC 27001 (ISMS ownership, risk methodology, SoA, internal audits)
    • ISO/IEC 42001 (AI governance, AI risk and control design)
    • GDPR and CCPA/CPRA privacy programs
    • CMMC / NIST SP 800‑171
  • Translate security architectures and technical controls into compliant policies, standards, and evidence.
  • Lead enterprise, third‑party, cloud, and AI‑specific risk assessments.
  • Serve as primary interface for auditors, assessors, regulators, customers, and partners.
  • Drive efficiency using GRC platforms, security telemetry, and AI‑assisted compliance tooling.
  • Mentor junior GRC professionals and influence cross‑functional teams without direct authority.
Technical Cybersecurity Skills & Expectations
  • Security Architecture & Controls
    • Strong understanding of defense‑in‑depth architectures, including network segmentation, firewalls, IDS/IPS, and endpoint detection & response (EDR/XDR)
    • Identity and access management including SSO, MFA, RBAC
    • Ability to assess and validate technical control effectiveness, not just paper compliance.
  • Cloud & SaaS Security
    • Hands‑on familiarity with cloud security models (AWS, Azure, GCP concepts)
    • Shared responsibility, logging and monitoring, encryption at rest and in transit, secure CI/CD, and infrastructure‑as‑code risks
    • Map cloud security controls to ISO 27001, NIST, and CMMC requirements.
  • Data Protection & Privacy Engineering
    • Data classification and labeling, DLP, encryption, key management, data residency, and cross‑border data transfer controls
    • Work with engineering teams on privacy‑by‑design implementations.
  • Vulnerability & Risk Management
    • Vulnerability management lifecycle, secure configuration baselines, risk acceptance, compensating controls, and technical debt
    • Assess real‑world risk rather than checklist compliance.
  • Incident Response & Monitoring
    • Detection, containment, and post‑incident reviews
    • Regulatory and contractual notification requirements
    • Validate IR plans against ISO and regulatory expectations.
  • AI & Emerging Technology Risk
    • Understanding of AI‑related security and governance risks: training data integrity, model lifecycle and access control, bias, explainability, and accountability considerations
    • Exposure to AI‑enabled security and compliance tools preferred.
Industry‑Specific Skills
  • Defense / Government Contractors
    • CMMC L1–L3 and NIST SP 800‑171 technical control interpretation
    • CUI protection, enclave design, boundary controls
    • Vendor and subcontractor security assurance, DFARS‑aligned audit and evidence readiness
  • Semiconductor / Hardware & Manufacturing
    • Protection of design IP, fabrication data, and production systems
    • Supplier and foundry security risk assessments
    • Alignment of cyber, physical, and operational security controls
    • Global compliance and data localization considerations
  • SaaS / Cloud‑Native
    • Cloud‑native ISMS design, secure SDLC and CI/CD risk governance
    • Customer audits, security questionnaires, trust signals
    • AI feature governance and responsible data usage
Qualifications
  • 7–12+ years of experience in GRC, security, privacy, or risk management.
  • Proven ownership of ISO 27001, GDPR/CCPA, and CMMC or NIST 800‑171 programs.
  • Strong technical and regulatory interpretation skills.
  • Ability to operate independently at senior or principal IC level.
  • ISO 27001 Lead Implementer / Lead Auditor, CISSP, CISA, CRISC, CIPM, CIPP/US, CIPP/E certifications preferred.
  • Experience with Microsoft security and compliance platforms (Purview, Defender, Entra ID) or equivalent.
  • Exposure to AI governance frameworks, tools, or regulations.
Role Leveling Expectations
  • Senior GRC Analyst leads major compliance initiatives and acts as SME for key frameworks.
  • Partners closely with security and engineering, defines enterprise GRC strategy and architecture.
  • Advises executives on material cyber and regulatory risk, shapes AI governance and future compliance roadmaps.
  • Mentors and raises overall GRC maturity.
Job Type & Location

Regular
Primary Location: Bengaluru, Karnataka, India
Additional Locations: Posting Statement

Equal Employment Opportunity

All qualified applicants will receive consideration for employment without regard to race, color, religion, religious creed, sex, national origin, ancestry, age, physical or mental disability, medical condition, genetic information, military and veteran status, marital status, pregnancy, gender, gender expression, gender identity, sexual orientation or any other characteristic protected by local law, regulation, or ordinance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

Altera • Bengaluru

On-site
INR 3,000,000 - 4,500,000
Governance, Risk and Compliance (GRC) Specialist
Governance, Risk and Compliance (GRC) Specialist

Career Guideline • Pune District

On-site
INR 1,500,000 - 2,500,000
Senior GRC Analyst
Senior GRC Analyst

Litmos • India

On-site
INR 2,400,000 - 3,200,000
Senior GRC Analyst
Senior GRC Analyst

3M HEALTHCARE • Hyderabad

On-site
INR 1,500,000 - 2,200,000
Product GRC Consultant
Product GRC Consultant

CyRAACS™ • Bengaluru

On-site
INR 600,000 - 1,200,000
GRC Lead / Security Compliance Lead
GRC Lead / Security Compliance Lead

Gnani Innovations Private Limited. • India

On-site
INR 350,000 - 600,000
Technical Manager
Technical Manager

Incedo Inc. • Gurugram District

On-site
INR 2,500,000 - 5,000,000
Senior GRC Analyst
Senior GRC Analyst

Tetuan Valley • India

On-site
INR 900,000 - 1,200,000
Variable Compensation
Senior Manager – GRC
Senior Manager – GRC

ITHR 360° CONSULTING FZE • Delhi

On-site
INR 1,800,000 - 3,000,000
Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

Powerbridge • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Health insurance
Long-term benefit savings plan
Professional development opportunities