Staff Risk & Compliance Analyst

RE1055 GE Renewable Energy Technologies Private Limited

Bengaluru

On-site

INR 900,000 - 1,300,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Relocation assistance

Job summary

GE Renewable Energy Technologies Private Limited is seeking a Staff Risk Analyst to oversee cybersecurity and risk governance across sites, ensuring SOX compliance and continuous improvement of controls. The role involves collaboration with process owners to document controls, track deficiencies, and support audits.

Ideal candidates have a background in IT GRC or IT audit, with knowledge of ERP environments (SAP/Oracle) and a willingness to learn COBIT, SOX, and regulatory changes.

Qualifications

  • Bachelor's degree in Computer Engineering, Computer Science, Information Systems, or related field.
  • 1–3 years in IT GRC, IT Audit, or related fields with foundational knowledge of SOX ITGCs and application controls; ERP exposure beneficial.
  • ERP awareness: basic understanding of SAP, Oracle; interest in Segregation of Duties concepts and access controls.
  • Willingness to learn and adapt in a fast-paced environment; interest in process improvement.

Responsibilities

  • Support IT governance framework and documentation updates under senior guidance.
  • Coordinate SOX testing activities and control assessments, maintain evidence.
  • Document controls, risk-control matrices, and test evidence per SOX requirements.
  • Track testing cycles, identify control gaps, and support remediation efforts.
  • Prepare SOX status reports for leadership and external auditors; maintain controls repository.

Skills

GRC concepts
Audit support
Data analysis

Education

Bachelor's degree in a related field

Tools

SAP
Oracle
Power BI

Job description

Job Description Summary

The Staff Risk Analyst will oversee the Cybersecurity and Risk function across different GE business sites, presence and interests.

Roles and Responsibilities
  • Support governance framework: Assist in maintaining the IT governance structure using established frameworks; help update documentation, track process adherence, and support standardization efforts under senior guidance.
  • SOX Compliance Management: Support the Power DT Sarbanes-Oxley compliance program by coordinating testing activities, managing documentation requirements, and ensuring timely completion of control assessments.
  • Collaborate with process owners to maintain accurate control narratives, risk-control matrices, and test evidence in accordance with SOX requirements.
  • Track testing cycles, identify control gaps or weaknesses, and facilitate management's remediation efforts.
  • Prepare SOX status reports for leadership and external auditors, maintain the SOX controls repository, and stay current on regulatory changes and industry best practices to ensure continuous compliance with financial reporting requirements.
  • End-to-End Deficiency Management: Lead comprehensive deficiency identification, tracking, and resolution processes across all GRC domains.
  • Collaborate with control owners and business stakeholders to document findings, assign remediation actions with clear deadlines, and monitor progress through to closure.
  • Maintain deficiency registers, provide regular status reporting to leadership, perform root cause analysis, and ensure timely escalation of overdue or high-risk items.
  • Drive continuous improvement by analyzing deficiency trends and recommending preventive measures to strengthen the organization's control environment.
  • Support key control domains: Assist in ERP control areas (Identity and Access Management/Privileged Access, SDLC/DevOps change, and IT operations) by performing routine control testing, maintaining evidence files, and supporting standardization initiatives.
  • Support policy development: Assist in drafting and updating IT policies and procedures for security, data management, and access control; help coordinate review processes, track acknowledgments, and maintain policy repositories to support continuous compliance.
  • Support risk management: Assist in risk assessment activities by gathering data, documenting findings, and maintaining risk registers; help identify and document risks associated with IT systems, including cybersecurity threats and data breaches, under senior supervision.
  • Support compliance audits: Serve as a key support resource for internal and external audits; assist in managing request lists, gathering evidence, organizing documentation, responding to routine inquiries, and tracking remediation progress for identified control deficiencies.
  • Monitor regulatory adherence: Help monitor changes in regulations and laws, such as SOX, NIS2, and GDPR; assist in maintaining control and policy mappings and support updates to ensure ongoing compliance.
  • Support training and awareness: Assist in developing training materials and coordinating training sessions for employees and stakeholders; help track participation and gather feedback to support understanding of compliance obligations and best practices.
  • Support reporting: Assist in building and maintaining reports and dashboards for senior management on IT risk posture, compliance status, and control effectiveness; help gather data, validate information, and prepare routine status updates.
What you’ll bring (Basic Qualifications)
  • Experience: Bachelor's degree in Computer Engineering, Computer Science, Information Systems, or a related field (or equivalent experience).
  • 1-3 years in IT GRC, IT Audit, or related fields with foundational knowledge of SOX ITGCs and application controls; any ERP exposure is beneficial.
  • ERP awareness: Basic understanding of ERP systems (SAP, Oracle) and interest in learning Segregation of Duties (SoD) concepts, access controls, and configuration standards.
  • Learning mindset: Demonstrated ability to learn quickly and adapt in a fast-paced environment; eagerness to understand business objectives and how control activities support organizational goals.
  • Continuous improvement: Strong curiosity, first-principles problem solving, and interest in process improvement and metrics-driven approaches.
  • Analytical skills: Good problem-solving and analytical skills to support control gap identification, risk assessment activities, and basic root-cause analysis under guidance.
  • Communication: Strong written and verbal communication skills; ability to document findings clearly and communicate effectively with both technical and non-technical stakeholders.
  • Collaboration: Demonstrated ability to work effectively in team environments, support cross-functional initiatives across IT, Finance, and business partners, and learn from senior team members.
  • Technology aptitude: Basic familiarity with GRC concepts and willingness to learn GRC/security tooling and dashboards; interest in contributing to process improvements and automation initiatives.
  • Professional development: Interest in pursuing relevant certifications such as CISA, CISM, or CRISC; openness to learning about COBIT frameworks and SOX requirements.
  • Audit support: Willingness to learn audit processes and evidence management; ability to organize documentation, respond to routine requests, and support audit coordination activities.
  • Data and reporting: Basic proficiency with data analysis tools and interest in learning dashboard development; familiarity with Excel and willingness to learn tools such as Power BI or Tableau.
What will make you stand out
  • Certifications: Interest in pursuing CISA certification within 1-2 years; basic understanding of SOX requirements; foundational knowledge of CISM, CRISC, or COBIT frameworks beneficial; willingness to learn about ISO 27001 standards.
  • ERP risk foundation: Basic understanding of ERP systems (Oracle EBS, preferred); willingness to develop knowledge of critical access controls, configuration standards, and automated control testing; exposure to Identity Governance and Administration (IGA) platforms (e.g., SailPoint, Saviynt) a plus.
  • Audit/exam support: Demonstrated organizational skills and attention to detail for supporting audit processes; ability to assist with evidence gathering, maintain PBC (Provided by Client) lists, and support routine audit inquiries; eagerness to learn internal and external audit processes (SOX) and contribute to smooth audit execution.
  • Data analysis and reporting: Basic proficiency with data analysis and visualization tools; familiarity with Excel and willingness to learn advanced reporting tools such as Power BI or Tableau; ability to support control analytics and assist in developing KPI/KRI reports under guidance; strong attention to detail in data validation and documentation.

This Job Description is intended to provide a high-level guide to the role. However, it is not intended to amend or otherwise restrict/expand the duties required from each individual employee as set out in their respective employment contract and/or as otherwise agreed between an employee and their manager.

Additional Information

Relocation Assistance Provided: Yes

Addressing the climate crisis is an urgent global priority and we take our responsibility seriously. That is our singular mission at GE Vernova: continuing to electrify the world while simultaneously working to help decarbonize it. If we want our energy future to be different…we must be different. Our mission is embedded in our name. We retain our treasured legacy, "GE," in our name as an enduring and hard-earned badge of quality and ingenuity. "Ver" / "verde" signal Earth’s verdant and lush ecosystems. "Nova," from the Latin "novus," nods to a new, innovative era of lower carbon energy that GE Vernova will help deliver. Together, we have The Energy to Change the World. www.gevernova.com

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Cyber Security Engineer
Sr Cyber Security Engineer

OG1121 Meridium Services and Labs Private Limited • Bengaluru

On-site
INR 1,800,000 - 3,200,000
DevSecOps Services Technical Lead
DevSecOps Services Technical Lead

OG1121 Meridium Services and Labs Private Limited • Hyderabad

On-site
INR 1,800,000 - 3,200,000
Relocation assistance
Engineer - OT Cybersecurity
Engineer - OT Cybersecurity

IF1860 GE Power Conversion India Private Limited • Chennai District

On-site
INR 2,000,000 - 3,000,000
Relocation assistance provided
Lead Engineer 2 - Controls Engineering
Lead Engineer 2 - Controls Engineering

RE1055 GE Renewable Energy Technologies Private Limited • Hyderabad

On-site
INR 1,800,000 - 3,000,000
Relocation assistance
Quality Assurance Engineering Specialist
Quality Assurance Engineering Specialist

RE1055 GE Renewable Energy Technologies Private Limited • Bengaluru

On-site
INR 800,000 - 1,200,000
Relocation Assistance Provided
Engineer - Controls Engineering
Engineer - Controls Engineering

IF1860 GE Power Conversion India Private Limited • Chennai District

On-site
INR 900,000 - 1,300,000
Relocation Assistance Provided
Lead Quality
Lead Quality

AL7564 GE Renewable R&D India Private Limited • Pune District

On-site
INR 1,500,000 - 2,100,000
Relocation assistance provided
Sr. Staff DevOps Engineer
Sr. Staff DevOps Engineer

OG1121 Meridium Services and Labs Private Limited • Hyderabad

On-site
INR 700,000 - 1,400,000
Engineer - Inspection Technologies
Engineer - Inspection Technologies

RE1055 GE Renewable Energy Technologies Private Limited • Bengaluru

On-site
INR 900,000 - 1,300,000
Relocation Assistance Provided
OT Cybersecurity Solution Architect
OT Cybersecurity Solution Architect

RE1055 GE Renewable Energy Technologies Private Limited • Hyderabad

On-site
INR 5,500,000 - 8,500,000