09 Sep
|
XCEEDANCE
|
Haryana
Job DescriptionExperience Required: 5–8 Years NLocation: Gurgaon/ Noida NRole: GRC Consultant NSecurity Questionnaire Manageme Nnt· Serve as the single point of coordination for client-issued IT security/compliance questionnaires — cyclic and bi-annual in natur Ne.· Log incoming requestsfrom the shared distribution mailbox, loop in the account manager, and set/manage the standard ~60-day turnaround commitment to client Ns.· Route each questionnaire to the corporate Security Compliance team, who own roughly 90% of standard responses, and independently coordinate with business subject-matter experts to complete the remaining client- or business-specific question Ns.· Maintain the Received/ Working / Sent folder structure and the historical SharePoint response repository; reuse and adapt previously validated answers to maintain consistency and speed of turnaroun Nd.· Cross-check current-cycle responses against prior submissions for the same client, flag inconsistencies or outdated answers, and escalate ambiguous or sensitive items for review before final submissio Nn.Access Recertification Manageme Nnt· Coordinate the semi-annual access recertification cycle (for H1 typically starting January/February and completing through June, aligned with SOX audit timing) covering in-scope applications and shared-data security object Ns.· Confirm application inventory and scope with application owners; submit and track data-pull requests to the Security Administration team via the internal ticketing syste Nm.· Consolidate and cleanraw access-extract data (application ownership details, AD extracts, user profiles) into a standardized Excel workbook, using macros, formulas, and pivot tables to de-duplicate entries and merge rows where necessary (with multi-group access details N).· Load the consolidateddataset into SharePoint, distribute recertification requests to business and IT reviewers, and track review decisions through to completio Nn.· Compile audit-ready evidence packages (timestamps, reviewer decisions, access-removal confirmations)
to support internal IT audit and SOX audit requirement Ns.· Coordinate with Legal, HR, or other business stakeholders as needed for non-standard questionnaire items and escalate unique/new/non-standard client audit requests to senior team member Ns.Additional Activitines· Coordinate mandatory bi-annual security/privacy awareness training for employees and consultants with access to personal information — working with HR and the employee talent portal and managing SharePoint acknowledgment surveys or vendor points of contact for consultant population Ns.· Support the annual BCP/DR test cycle: confirm test dates with application owners, ensure business tester availability, track communications, and document test outcomes and remediation ownershi Np.REQUIRED SKILLS & QUALIFICATIO NNS· Bachelor's degree in either Comp Science, Information Systems, Information Security, Privacy, Risk Management, IT/Information Systems Business Administration or a related fiel Nd.· Overall 5+ years of experience with 3–5 years of experience in GRC coordination, compliance operations, IT audit/vendor-risk support, client assurance, and with project coordination roles; deep technical securitybackground is not require Nd.· Advanced Excel skills, including documentation, pivot tables, macros, formula-based reconciliation, and large-dataset consolidation/cleanu Np.· Strong working knowledge of MS Word, SharePoint, and shared-drive documentation management practice Ns.· Excellent written andverbal English communication skills, with confidence handling client-facing as well as internal leadership correspondenc Ne.· Demonstrated ability to coordinate across cross-functional stakeholders — IT, Security, Legal,
HR, Business, and third-party vendors etc. and drive follow-ups to closur Ne.· High attention to detail and consistency when validating recurring or comparative data set Ns.· Ability to handle sensitive, PII-adjacent information responsibly and maintain confidentiality (the role does not require direct access to client applications or systems N).· Availability to overlap with US Eastern Time hours (through at least 12:00 PM ET) for real-time collaboration with the client teams/stakeholder Nsn.nPREFERRED ATTRIBUT NES· Familiarity with vendor/third-party risk concepts (e.G., SIG questionnaires) is an advantage; formal GRC or security certifications are valuable to have but not mandatory for this rol Ne.· Prior experience supporting insurance, reinsurance, or financial services client Ns.· Experience with GRC tools, security questionnaire platforms, audit evidence repositories, or workflow tracking tools is an advantag Ne.· Positive understanding ofinformation security, privacy, risk, access management, business continuity, and compliance concepts; familiarity with ISO 27001, ISO 27701, SOC/SOC 2, NIST, GDPR, HIPAA etc. or client audit requirements is preferre Nd.· Certifications such as ISO 27001 Foundation/Internal Auditor, ISO 27701, ISO/IEC 27001:2022 LI or LA, CISA, CRISC, or equivalent are good to hav Ne.· Self-driven with solid ownership; comfortable ramping up through an apprenticeship/knowledge-transfer period alongside the client team before working semi-independentl Ny.· Comfortable in a coordination-heavy role with cyclical rather than constant workload peaks, and able to flex into ad hoc requests as they aris Ne.ROLE FOCnn USThis role is focused on client security assurance, questionnaire and access-recertification coordination, security awareness and training facilitation, BCP/DR facilitation and management, documentation management, and cross-functional stakeholder follow-up — however not on hands-on technical security wor Nnk.
📌 Information Security Analyst (Haryana)
🏢 XCEEDANCE
📍 Haryana