
GRC Analyst
- Kochi, Kerala
- Permanent
- Full-time
- Support the implementation and maintenance of ISO 27001:2022 standards by assisting in ensuring compliance with security controls and helping prepare for internal and external audits.
- Assist in conducting internal audits and security assessments, gathering and validating evidence to ensure compliance with regulatory requirements.
- Collaborate with senior team members during external compliance assessments and audits, providing support in audit preparation, evidence collection, and report generation.
- Identify and document security risks, help to assess their impact on the organization, and support the development of risk mitigation strategies.
- Contribute to the development and updating of information security policies, procedures, and related documentation, ensuring alignment with ISO 27001 and other regulatory frameworks.
- Participate in the monitoring and review of security controls, supporting efforts to enhance their effectiveness and alignment with business objectives.
- Provide analysis and reporting on the performance of security controls, helping identify areas for improvement and supporting the implementation of corrective actions.
- Gather and validate technical evidence for compliance reviews and audits, ensuring thorough and accurate documentation is maintained.
- Assist in the preparation of detailed reports, summarizing audit findings, risk assessments, and policy updates for leadership review.
- Communicate security and compliance requirements clearly and effectively to team members and stakeholders, ensuring understanding and alignment across the organization.
- Collaborate with cross-functional teams to ensure that GRC activities integrate seamlessly with broader business processes and goals.
- Maintain accountability for assigned tasks, ensuring deadlines are met and deliverables are completed with attention to detail.
- Ensure a customer-centric approach, understanding client and stakeholder needs while delivering solutions that add value.
- Demonstrate a proactive attitude toward learning and development, continually seeking to improve knowledge and skills in GRC and information security practices.