GRC Advisor
REA
- Gurgaon, Haryana
- Permanent
- Full-time
- Help teams navigate security for their projects and systems, making sense of controls (technical, procedural, physical) and risks.
- Conduct cyber risk assessments, third-party due diligence and Business Impact Analyses (BIAs) for new tech and systems, designing smart ways to manage those risks.
- Perform technical security control assessments and contribute to ensuring our key systems meet security standards and compliance needs.
- Work with delivery partners and internal teams to clearly communicate security requirements and ensure they're met.
- Advise on secure solution architectures, identify potential risks in designs, and propose effective countermeasures.
- Contribute to our vulnerability assessment efforts by analysing assets, performing assessments, and helping teams adopt the right controls.
- Assist in investigating suspected attacks and support our incident response efforts with your security expertise.
- Help maintain and optimize operational security processes, especially for our cloud and automated systems.
- Engage effectively with stakeholders across REA, understanding their needs and championing good security practices.
- Provide detailed and specific advice on security topics where you have expertise, helping teams make informed decisions.
- Solid understanding of security controls, risk assessment methodologies, and Business Impact Analysis.
- Can break down security concepts, risks, and requirements for diverse audiences.
- Experience performing security risk assessments, technical security assessments, or contributing to assurance / accreditation activities.
- You can spot potential security issues in designs, processes, and systems and suggest practical, effective solutions.
- You enjoy working with different teams (tech, business, partners) to embed security and achieve shared goals.
- Knowledge of frameworks like NIST, ISO 27001, or specific compliance areas (e.g., PCI, Privacy)
- You can manage your advisory workload, contribute effectively to projects, and keep good records.
- Maybe it's cloud security, application security, identity, or a specific GRC area we value focused expertise.
- You can work effectively with stakeholders, understand their perspectives, and provide valuable, respected advice.
- You're keen to stay updated on security trends, threats, and best practices.
- Youve got experience working with different cloud environments like AWS, Google or Azure.
- A hybrid and flexible approach to working.
- Transport options to help you get to and from work, including home pick-up and drop-off.
- Meals provided on site in our office.
- Flexible leave options including parental leave, family care leave and celebration leave.
- Insurance for you and your immediate family members.
- Programs to support mental, emotional, financial and physical health & wellbeing.
- Continuous learning and development opportunities to further your technical expertise.