05 Aug
|
HCL Technologies
|
Noida
05 Aug
HCL Technologies
Noida
Subject Matter Expert (Support&Ops;)
Experience: 3 to 8 years
Location: Gautam Buddha Nagar, India
Skills: GRC, Governance, Risk Management, Compliance, ISO 27001, ISO 27701, SOC 2, GDPR, NIST, COBIT, ServiceNow GRC, Archer, MetricStream, OneTrust, ISO 31000, NIST RMF, HIPAA, CISA, CISM, CRISC, ISO 27001 Lead Auditor, ISO 27001 Implementer, CISSP, analytical skills, problem-solving skills, stakeholder management skills, attention to detail, documentation excellence
Job Summary
Role Overview
We are seeking a skilled GRC (Governance, Risk, and Compliance) professional to support and strengthen our enterprise risk management and regulatory compliance initiatives. The ideal candidate will have hands-on experience in risk assessments, audits, policy management, and compliance frameworks.
Key Responsibilities
Governance & Compliance
Develop, review, and maintain information security policies, standards, and procedures
Ensure compliance with global standards such as:
ISO 27001 / ISO 27701
SOC 2
GDPR / Data Privacy regulations
NIST / COBIT frameworks
Support internal and external audits (ISO, SOC, client audits)
Risk Management
Conduct risk assessments and gap analysis
Identify, analyze, and mitigate risks across IT and business processes
Maintain and update the risk register
Perform third-party/vendor risk assessments
Audit & Assurance
Coordinate audit activities and track remediation actions
Perform control validation and testing
Work with stakeholders to address audit findings and closure
Policy & Process Management
Draft and update policies aligned with industry standards
Ensure proper implementation of controls across business units
Conduct periodic policy reviews and awareness programs
Tool & Reporting
Work on GRC tools such as:
ServiceNow GRC
Archer
MetricStream
OneTrust (preferred)
Generate compliance reports, dashboards, and metrics for leadership
Stakeholder Management
Collaborate with IT, security, legal, and business teams
Provide advisory on compliance requirements and best practices
Required Skills & Qualifications
Experience
3–8+ years experience in GRC, InfoSec, Risk, or Compliance roles
Technical & Functional Skills
Strong understanding of:
Risk frameworks (ISO 31000, NIST RMF)
Security standards (ISO 27001, SOC 2)
Experience in audit handling and compliance tracking
Knowledge of regulatory requirements (GDPR, HIPAA, etc. preferred)
Tools
Experience with at least one GRC platform:
ServiceNow GRC / RSA Archer / MetricStream
Certifications (Preferred)
CISA / CISM / CRISC
ISO 27001 Lead Auditor / Implementer
CISSP (good to have)
Soft Skills
Strong analytical and problem-solving ability
Effective communication and stakeholder management skills
Attention to detail and documentation excellence
Ability to work in a fast-paced workplace
Education
Bachelor’s degree in Computer Science, IT, Cybersecurity, or related field
Master’s degree is a plus
Location
HCLTech Offices (Noida / Bangalore / Chennai / Remote options based on project)
📌 Subject Matter Expert (Support&Ops) (Noida)
🏢 HCL Technologies
📍 Noida