
Senior Security GRC Analyst
- Bangalore, Karnataka
- Permanent
- Full-time
- Coordinate and manage IT SOX compliance program to perform testing, remediation, and reporting on control design and control effectiveness for ITGC, ITAC, and key reports
- Oversee and execute recurring compliance activities (e.g. user access reviews, change management reviews) to maintain compliance with relevant obligations
- Conduct security risk assessments and maintain security risk register, tracking mitigation plans and residual risks
- Drive the Business Continuity and Disaster Recovery (BC/DR) activities by partnering with business units to perform BIA, facilitate recurring exercises, etc.
- Coordinate and support internal and external audits, including evidence gathering, reviewing and managing audit findings
- Provide support on other Security GRC & Trust projects (i.e. Infosec Policies, Security Awareness, security risk management, third-party risk management, data and privacy security, etc)
- Implement and configure toolings for Security GRC and Trust
- Foster a culture of trust and accountability by collaborating with internal stakeholders (Engineering, Security Operations, IT, Legal, etc) to ensure alignment and effectiveness of the Security GRC & Trust program
- Develop, implement, and oversee a comprehensive Security GRC & Trust program aligned with industry best practices and regulatory requirements (e.g., SOC 1, SOC 2, ISO, PCI, NIST CSF, IT SOX)
- Must be a team player
- 5+ years of information security, security governance, risk management, and compliance.
- In-depth knowledge of industry best practices and security frameworks (e.g., NIST CSF, ISO 27001, SOC 2, SOC 1, PCI DSS, IT SOX).
- Strong understanding of relevant privacy security regulations (e.g., GDPR, CCPA, etc.)
- IT Internal Audit & external audit experience
- Knowledge of AWS, CI/CD process, and common Security tooling stack for enterprise technology companies
- Experience with development and operation of Security Trust program
- Experience with implement and configure Security GRC relevant tools
- Excellent communication, collaboration, and influencing skills.
- Ability to manage multiple priorities and deadlines in a fast-paced environment.
- Strong analytical and problem-solving skills.