Grc Analyst (Gurugram)

Grc Analyst (Gurugram)

07 Aug
|
Balance Hero India
|
Gurugram

07 Aug

Balance Hero India

Gurugram

About True Balance (Formerly Balancehero India)

Balancehero India Pvt. Ltd. (BHI), the wholly-owned subsidiary of Balancehero Co. Ltd., Korea which runs and operates the mobile app "True Balance" - a one-stop destination for financial services. Founded by Charlie Lee in Korea in 2014, Balancehero started its operations in India in the year 2016. It started off as a balance check application and the company has expanded its business model to financial services. The company aims to build a financial platform for the next billion which set the context for loans, utility services, pay later services, and commerce services. The Company's wholly-owned subsidiary True Credits Private Limited, is a licensed NBFC that aims to bridge the financial gap in India by making Finance available for all. True Credits lends through the True Balance mobile application.

About True Balance

Owned and operated by BalanceHero Group, True Balance is an RBI authorized Prepaid Payment Instrument (PPI) issuing entity. It offers loans through its subsidiary and RBI licensed Non-Banking Financial Company - True Credits Private Limited and other RBI licensed partners. Founded in 2016, as a mobile app for users in India to efficiently manage their phone calls and data usage, True Balance is now India's one of the top financial services platforms providing solutions to all the financial needs of its users - from obtaining instant loans, paying utility bills to do prepaid recharges seamlessly. To date, True Balance has raised more than US$84 million in equity funding from marquee global investors like Softbank, Naver, and Line to name a few. The company aims to become the go-to financial services platform for the next billion people in India, playing a key role in the nationwide push towards the goal of Digital India and advancing financial inclusion amongst the unbanked and underbanked people.

About True Credits

Established in 2019, True Credits is the RBI licensed NBFC that provides innovative financial services to empower the next billion unbanked users. They cater to the personal and business needs of consumers by providing fast and hassle-free finance.



True Credits is focused towards unbanked users who have created a huge demand for instant credit services in India.

Job Description

About the Role

We are seeking a seasoned Senior Governance, Risk, and Compliance (GRC) Analyst / Specialist with approximately 5 years of experience to lead and execute our core information security governance, risk management, and compliance operations.

In this role, you will own day-to-day GRC operations, acting as the primary operational point of contact for assurance activities. You will collaborate closely with internal engineering, IT, security operations, product, and legal teams, as well as external vendors. The ideal candidate is a self-starter who can drive continuous improvement, automate manual processes, and elevate the organization's overall security and compliance posture.

Key Responsibilities

1. Risk Management & Governance

- Maintain the enterprise and operational risk registers, conducting risk assessments across business and technology functions.
- Track risk treatment plans, monitor mitigation activities, and ensure timely closure of identified risks.
- Prepare GRC and security metrics, dashboards, and management reports, tracking KPIs and KRIs.

2. Third-Party Risk Management (TPRM)

- Manage end-to-end TPRM activities, including vendor onboarding assessments, due diligence reviews, and periodic reassessments.
- Review vendor security questionnaires, audit reports (SOC 2, ISO), certifications, and remediation plans.
- Maintain vendor risk registers, track outstanding findings, and monitor risk closure.

3. Compliance, Audit & Control Monitoring

- Perform control monitoring and effectiveness reviews to validate compliance with internal policies, ISO 27001, and regulatory obligations (e.g., RBI compliance).
- Support internal and external audits by coordinating evidence collection,



responding to auditor requests, and tracking remediation actions.
- Manage customer security assessments, due diligence requests, and security questionnaire responses.

4. Identity & Access Governance (IAM) & Asset Management

- Coordinate periodic user access, privileged access, and SSO reviews.
- Validate user provisioning, deprovisioning, role changes, and segregation of duties (SoD) controls.
- Conduct periodic asset inventory reviews to ensure asset ownership, classification, and lifecycle compliance.

5. Incident Management / SOC

- Monitor security alerts generated by SOC, SIEM, and application logs, coordinating with relevant technical teams for investigation and remediation.
- Track security incidents, document findings, monitor corrective actions, and escalate critical risks.
- Govern the vulnerability management process, tracking remediation timelines and reporting overdue vulnerabilities.

6. Security Operations

- Conduct periodic hardening reviews of cloud, servers, endpoints, and network devices.
- Perform patch compliance reviews for endpoints on a periodic basis.

Required Qualifications

- Education: Bachelor's degree in Information Security, Computer Science, Risk Management, or a related technical field.
- Experience: Approximately 5 years of dedicated experience in GRC, Information Security, Risk Management, Security Operations, IAM, and RBI compliance.
- Frameworks: Solid knowledge of ISO 27001, ISO 22301, SOC 2, NIST CSF, and CIS.
- Technical Skills: Hands-on experience with SIEM platforms, security monitoring tools, and vulnerability management governance.
- Soft Skills: Excellent stakeholder management, cross-functional collaboration, and strong documentation/reporting skills (advanced MS Excel/Word).

Preferred Qualifications

- Certifications: ISO 27001 Lead Implementer / Lead Auditor, CISA, CRISC, or equivalent security certifications.
- Industry Experience: Prior experience in NBFC, PPI, SaaS, FinTech, or fast-paced product-based organizations in a regulated industry.
- Cloud Governance: Direct exposure to cloud security governance, preferably within AWS

📌 Grc Analyst (Gurugram)
🏢 Balance Hero India
📍 Gurugram

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: grc analyst (gurugram) / gurugram

Subscribe to this job alert:

Get the latest job offers by email for: grc analyst (gurugram) / gurugram