GRC SME – Banking DomainIn-Office Mumbai Metropolitan Region IT Service & Incident Management
GRC SME – Banking Domain
Job Summary
We are seeking an experienced GRC Subject Matter Expert (SME) to lead Governance, Risk, and Compliance activities within a banking environment. The candidate will be responsible for coordinating audits, managing compliance activities, tracking audit observations, following up with internal technology and business teams for remediation, and ensuring timely closure of open audit points.
Governance, Risk & Compliance Activities
· Lead Governance, Risk, and Compliance (GRC) activities across the organization.
· Act as the SME for banking compliance and audit management.
· Coordinate with internal and external auditors during audit engagements.
· Track and manage audit observations, compliance gaps, and remediation activities.
· Follow up with application, infrastructure, security, and business teams for timely closure of audit findings.
· Maintain audit trackers, compliance dashboards, and status reports.
· Ensure proper documentation and evidence collection for audit requirements.
Audit Management
· Lead internal, external, regulatory, and RBI audits.
· Coordinate audit meetings, walkthroughs, and evidence submissions.
· Ensure timely responses to audit queries and observations.
· Monitor closure status of audit findings and remediation plans.
· Escalate overdue audit observations and compliance risks to senior management.
· Prepare audit reports and management presentations.
RBI Compliance & Regulatory Support
· Lead compliance activities related to RBI guidelines and banking regulations.
· Understand and track RBI cybersecurity and IT compliance requirements.
· Coordinate implementation of regulatory recommendations across teams.
· Support audits related to RBI Cyber Security Framework, IS Audit, VAPT Compliance,
IT Governance, and Information Security Compliance.
Risk Management
· Identify and track information security and operational risks.
· Lead risk assessment and risk mitigation activities.
· Maintain risk registers and compliance records.
· Support control validation and remediation tracking.
Reporting & Documentation
· Prepare audit status reports, risk reports, and compliance dashboards.
· Maintain audit evidence repositories and compliance documentation.
· Generate periodic compliance and governance reports for management and regulators.
Required Skills
· Expert-level understanding of Governance, Risk & Compliance (GRC) processes and banking regulatory compliance.
· Robust experience handling banking audits and compliance activities.
· Knowledge of RBI audit and regulatory requirements.
· Understanding of Information Security controls, IT Governance, Risk Management, and audit lifecycle management.
· Strong documentation, reporting, and stakeholder management skills.
· Ability to drive closure of audit observations within regulatory timelines.
Preferred Certifications
· ISO 27001 Lead Implementer / Lead Auditor
· CISA
· CRISC
· CEH
· CISSP (Preferred)
· COBIT Foundation
· ITIL Foundation
Experience & Qualification
· 6–10 years of experience in GRC, audit, compliance, or information security, preferably within banking or financial institutions.
· Strong experience managing RBI and regulatory audits.
· Hands-on experience managing audit observations and compliance tracking.
· Bachelor’s degree in Computer Science, Information Security, Finance, or related field.
Good to Have
· Experience with GRC tools and compliance platforms.
· Exposure to cybersecurity operations and IT infrastructure.
· Knowledge of SIEM, IAM, PAM, and endpoint security concepts.
· Strong leadership, communication, and stakeholder management skills
📌 GRC SME – Banking Domain (Mumbai)
🏢 Neev
📍 Mumbai