30 Jul
|
dsk Solutions
|
Kurnool
30 Jul
dsk Solutions
Kurnool
About us
We are a UK and India-based technology consultancy delivering IT strategy, architecture, and programme management for Tier 1 and Tier 2 enterprises across Spacetech, Telecommunications, Retail, Financial services and Utilities. Our clients include global satellite operators and major UK telecoms and retail brands, and our work is built on industry standards including TM Forum ODA, MEF, TOGAF, and ARTS. This role sits on our India delivery team, working directly with UK-based enterprise clients on live production systems.
Role summary
We're looking for a GRC Analyst to support governance, risk, and compliance activity across our UK clients' security and technology programmes — control frameworks, risk assessments, policy, and audit readiness. This is a working GRC role embedded with delivery teams, not a purely document-review function sitting apart from the technical work.
Key responsibilities
• Run and maintain risk assessments and risk registers for client engagements, tracking treatment plans through to closure.
• Support implementation and ongoing operation of control frameworks — ISO 27001, NIST, SOC 2, and Cyber Essentials Plus.
• Draft and maintain security policies, standards, and procedures aligned to client requirements and applicable regulation.
• Conduct control testing and gather audit evidence, working directly with engineering and platform teams to close gaps.
• Support third-party and vendor risk assessments for client supply chains.
• Track regulatory obligations relevant to client sectors — UK GDPR, DORA (financial services), NIS2 (utilities/telecoms) — and flag compliance gaps.
• Contribute to emerging AI governance readiness work as clients respond to EU AI Act and related UK regulatory direction.
• Produce clear risk and compliance reporting for both technical and non-technical stakeholders.
What we're looking for
Required
• 3-6 years in GRC, information security compliance, or IT risk roles.
• Direct working experience with at least one major control framework (ISO 27001, SOC 2, or NIST), not just classroom knowledge.
• Experience maintaining a risk register and driving treatment plans to closure, not just recording risks.
• Robust written communication skills — able to produce policy and reporting documents that stand on their own for a UK client audience.
• Working understanding of the UK/EU regulatory landscape relevant to client sectors (GDPR, DORA, NIS2 as applicable).
• Excellent written and spoken English — client-facing, no intermediary.
• Comfortable working a 1pm-10pm IST overlap window to align with UK client hours.
Nice to have
• ISO 27001 Lead Implementer or Lead Auditor, CISA, or CRISC certification.
• Experience with GRC tooling (ServiceNow GRC, Archer, or equivalent) rather than spreadsheet-only tracking.
• Prior GRC work in telecoms, financial services, or utilities environments.
• Exposure to AI governance or model risk management concepts.
What we offer
• Direct exposure to UK client compliance and audit programmes, working alongside client risk and security teams rather than behind a ticket queue.
• A senior, embedded role within a small, high-trust delivery team, not a large offshore bench.
• Remote-first, India-based role with fixed UK-overlap hours.
• An above-industry-average package for working directly with top-tier UK clients.
How to apply
Please send your CV, current CTC, notice period, and a short answer to the following screening question to : Describe a control gap or compliance finding you identified — how did you assess the real risk, and how did you drive it to remediation rather than just logging it?
📌 GRC Analyst - Remote (India) (Kurnool)
🏢 dsk Solutions
📍 Kurnool