
GRC Analyst
- New Delhi
- Permanent
- Full-time
- Assist in the development and maintenance of GRC policies, procedures, and standards.
- Monitor compliance with internal policies and external regulations (e.g., GDPR, ISO 27001, SOX).
- Support internal and external audits, including evidence collection and remediation tracking.
- Conduct risk assessments across business units and IT systems.
- Maintain the risk register and track mitigation plans.
- Support business continuity and incident response planning.
- Third-Party Risk Management (TPRM)
- Perform due diligence and risk assessments on new and existing vendors.
- Maintain a third-party inventory and risk classification.
- Collaborate with procurement, legal, and business units to ensure vendor compliance with security and privacy requirements.
- Monitor vendor performance and reassess risk periodically.
- Prepare dashboards and reports for leadership on risk posture, compliance status, and third-party risk.
- Track and report on key risk indicators (KRIs) and key performance indicators (KPIs).
- Bachelor's degree in Information Security, Risk Management, Business, or related field.
- 2-4 years of experience in GRC, risk management, or compliance roles.
- Familiarity with regulatory frameworks (e.g., NIST, ISO 27001, SOC 2, HIPAA).
- Experience with third-party risk management tools and processes.
- Strong analytical, communication, and stakeholder management skills.
- Proficiency in GRC platforms (e.g., Archer, ServiceNow GRC, OneTrust) is a plus.
- Preferred Certifications
- Certified in Risk and Information Systems Control (CRISC)
- Certified Information Systems Auditor (CISA)
- ISO 27001 Lead Implementer or Auditor
- About us