05 Aug
|
Recognized
|
Mumbai
GRC Analyst – IT Risk, Compliance & Information Security
Company: Credila Financial Services Ltd. (Formerly HDFC Credila)
Location: Mumbai
Experience: 2–6 Years
Department: Technology
Employment Type: Permanent
About Credila
Credila Financial Services Limited (formerly HDFC Credila Financial Services Limited) is one of India's leading education-focused NBFCs. With deep expertise in higher education financing, Credila provides customized education loan solutions to students pursuing studies in India and abroad.
Since inception, Credila has supported over 178,000 students across 63 countries and 4,600 institutions, helping them achieve their academic aspirations.
Role Overview
We are looking for a GRC Analyst to support Technology Risk, Information Security Governance, Regulatory Compliance, and Internal Audit activities. The role involves risk assessments, compliance monitoring, audit coordination, policy management, and regulatory reporting while ensuring adherence to internal controls and industry frameworks.
Key Responsibilities
Governance & Compliance
- Support development and maintenance of IT policies, standards, SOPs, and control frameworks.
- Track compliance with internal policies and regulatory requirements.
- Maintain GRC repositories, risk registers, compliance trackers, and dashboards.
- Support compliance assessments against ISO 27001, SOC 1/SOC 2, RBI guidelines, and other applicable regulations.
Risk Management
- Conduct and support Technology Risk Assessments and Risk Control Self-Assessments (RCSA).
- Track risk mitigation plans, action items, and closure evidence.
- Support enterprise risk initiatives including Operational Risk and Technology Risk Management.
Audit Management
- Coordinate Internal Audits, External Audits, and Regulatory Reviews.
- Collect audit evidence and support control walkthroughs.
- Track audit observations, remediation plans, and closure status.
- Validate implementation of corrective actions.
Reporting & Stakeholder Management
- Prepare MIS reports, compliance dashboards, and management updates.
- Maintain accuracy of risk, audit, and compliance data.
- Coordinate with Technology, Information Security, Risk, Compliance, and Business teams.
- Follow up with control owners for timely closure of audit and compliance actions.
Required Skills
- Understanding of IT General Controls (ITGC).
- Knowledge of Information Security Governance and Technology Risk.
- Familiarity with ISO 27001, COBIT, NIST, SOC, and ITIL frameworks.
- Exposure to:
- Identity & Access Management (IAM)
- Change Management
- Asset Management
- Backup & Disaster Recovery
- Incident Management
- Capacity Monitoring & Alerting
- Robust documentation, analytical, and reporting skills.
- Excellent stakeholder management and communication abilities.
- Advanced MS Excel and PowerPoint skills.
Preferred Certifications
- CISA
- CRISC
- ISO 27001 Lead Auditor / Lead Implementer
- COBIT Foundation
Education
- Bachelor's Degree in Computer Science, Information Technology, Engineering, Cyber Security, Risk Management, or related field.
Ideal Candidate Profile
- 2–6 years of experience in IT GRC, Information Security, IT Audit, Risk Management, Compliance, or Cyber Governance.
- Experience in BFSI, NBFC, Banking, FinTech, Consulting, or Technology environments preferred.
- Exposure to regulatory compliance and audit management will be an advantage.
📌 GRC Analyst IT Risk, Compliance & Information Security (Mumbai)
🏢 Recognized
📍 Mumbai