Role & responsibilities
- Drive risk assessments and manage remediation plans with explicit ownership, timelines, and accountability structures
- Build and maintain KPI/KRI reporting dashboards for leadership to provide visibility into risk and compliance performance.
- Ensure policy adherence across business units and support the development and review of security policies, standards, and procedures.
- Conduct GRC maturity assessments against industry-leading frameworks (such as NIST CSF, ISO/IEC 27001, COBIT, etc.) to identify gaps and recommend improvements.
- Collaborate with clients to understand their regulatory landscape and risk appetite, ensuring all engagements are delivered to the highest quality and professional standards.
- Stay informed about evolving regulatory requirements, compliance trends, and GRC technologies, and incorporate this knowledge into client recommendations.
- Provide Subject Matter Expertise on governance, risk management,
and compliance best practices to clients across various sectors.
- Minimum of 3 years of experience delivering GRC projects, including framework implementation, risk assessments, and audit preparation.
- Proven track record of successfully executing complex projects within consulting or skilled services environments.
- In-depth understanding of GRC principles and domains (such as control mapping, risk quantification, policy governance, and regulatory compliance).
- Strong knowledge of governance and security frameworks (such as NIST CSF, ISO/IEC 27001, COBIT, SOC 2) is advantageous.
- Familiarity with GRC platforms and tools (such as ServiceNow GRC, Archer, OneTrust, or LogicGate) is beneficial.
- Professional certifications such as CRISC, CISA, or ISO 27001 Lead Auditor are a plus.
📌 Senior Associate - GRC Consultant | Risk Assessment (Kolkata)
🏢 PwC
📍 Kolkata