04 Sep
|
XCEEDANCE
|
Gurugram
04 Sep
XCEEDANCE
Gurugram
Job Description
Experience Required: 5–8 Years
n
Location: Gurgaon/ Noida
n
Role: GRC Consultant
n
n
n
n Security Questionnaire Manageme
n
nt· Serve as the single point of coordination for client-issued IT security/compliance questionnaires — cyclic and bi-annual in natur
n
e.· Log incoming requests from the shared distribution mailbox, loop in the account manager, and set/manage the standard ~60-day turnaround commitment to client
n
s.· Route each questionnaire to the corporate Security Compliance team, who own roughly 90% of standard responses, and independently coordinate with business subject-matter experts to complete the remaining client- or business-specific question
n
s.· Maintain the Received / Working / Sent folder structure and the historical SharePoint response repository; reuse and adapt previously validated answers to maintain consistency and speed of turnaroun
n
d.· Cross-check current-cycle responses against prior submissions for the same client, flag inconsistencies or outdated answers, and escalate ambiguous or sensitive items for review before final submissio
n
n.Access Recertification Manageme
n
nt· Coordinate the semi-annual access recertification cycle (for H1 typically starting January/February and completing through June, aligned with SOX audit timing) covering in-scope applications and shared-data security object
n
s.· Confirm application inventory and scope with application owners; submit and track data-pull requests to the Security Administration team via the internal ticketing syste
n
m.· Consolidate and clean raw access-extract data (application ownership details, AD extracts, user profiles) into a standardized Excel workbook, using macros, formulas, and pivot tables to de-duplicate entries and merge rows where necessary (with multi-group access details
n
).· Load the consolidated dataset into SharePoint, distribute recertification requests to business and IT reviewers, and track review decisions through to completio
n
n.· Compile audit-ready evidence packages (timestamps, reviewer decisions, access-removal confirmations)
to support internal IT audit and SOX audit requirement
n
s.· Coordinate with Legal, HR, or other business stakeholders as needed for non-standard questionnaire items and escalate unique/new/non-standard client audit requests to senior team member
n
s.Additional Activiti
n
es· Coordinate mandatory bi-annual security/privacy awareness training for employees and consultants with access to personal information — working with HR and the employee talent portal and managing SharePoint acknowledgment surveys or vendor points of contact for consultant population
n
s.· Support the annual BCP/DR test cycle: confirm test dates with application owners, ensure business tester availability, track communications, and document test outcomes and remediation ownershi
n
p.REQUIRED SKILLS & QUALIFICATIO
n
NS· Bachelor's degree in either Comp Science, Information Systems, Information Security, Privacy, Risk Management, IT/Information Systems Business Administration or a related fiel
n
d.· Overall 5+ years of experience with 3–5 years of experience in GRC coordination, compliance operations, IT audit/vendor-risk support, client assurance, and with project coordination roles; deep technical security background is not require
n
d.· Advanced Excel skills, including documentation, pivot tables, macros, formula-based reconciliation, and large-dataset consolidation/cleanu
n
p.· Strong working knowledge of MS Word, SharePoint, and shared-drive documentation management practice
n
s.· Excellent written and verbal English communication skills, with confidence handling client-facing as well as internal leadership correspondenc
n
e.· Demonstrated ability to coordinate across cross-functional stakeholders — IT, Security, Legal, HR,
Business, and third-party vendors etc. and drive follow-ups to closur
n
e.· High attention to detail and consistency when validating recurring or comparative data set
n
s.· Ability to handle sensitive, PII-adjacent information responsibly and maintain confidentiality (the role does not require direct access to client applications or systems
n
).· Availability to overlap with US Eastern Time hours (through at least 12:00 PM ET) for real-time collaboration with the client teams/stakeholder
n
s
n
.
n
PREFERRED ATTRIBUT
n
ES· Familiarity with vendor/third-party risk concepts (e.g., SIG questionnaires) is an advantage; formal GRC or security certifications are good to have but not mandatory for this rol
n
e.· Prior experience supporting insurance, reinsurance, or financial services client
n
s.· Experience with GRC tools, security questionnaire platforms, audit evidence repositories, or workflow tracking tools is an advantag
n
e.· Good understanding of information security, privacy, risk, access management, business continuity, and compliance concepts; familiarity with ISO 27001, ISO 27701, SOC/SOC 2, NIST, GDPR, HIPAA etc. or client audit requirements is preferre
n
d.· Certifications such as ISO 27001 Foundation/Internal Auditor, ISO 27701, ISO/IEC 27001:2022 LI or LA, CISA, CRISC, or equivalent are positive to hav
n
e.· Self-driven with strong ownership; comfortable ramping up through an apprenticeship/knowledge-transfer period alongside the client team before working semi-independentl
n
y.· Comfortable in a coordination-heavy role with cyclical rather than constant workload peaks, and able to flex into ad hoc requests as they aris
n
e.ROLE FOC
n
n
- USThis role is focused on client security assurance, questionnaire and access-recertification coordination, security awareness and training facilitation, BCP/DR facilitation and management, documentation management, and cross-functional stakeholder follow-up — however not on hands-on technical security wor
n
n
k.
📌 Information Security Analyst (Gurugram)
🏢 XCEEDANCE
📍 Gurugram