Company: Digital Defense
Job Type: Full-Time
Experience: 1–3 Years
Location: [Location / Remote / Hybrid]
Department: Governance, Risk & Compliance (GRC)
About the Role
Digital Defense is looking for a Risk & Compliance Analyst to support our cybersecurity governance, risk management, compliance assessments, and client security requirements.
The ideal candidate will have a strong understanding of information security, risk assessment, compliance frameworks, security controls, policies, and audit processes . You will work closely with internal teams and clients to identify security and compliance gaps, assess risks, document findings, and support remediation activities.
Key ResponsibilitiesRisk Management
- Conduct information security and cybersecurity risk assessments.
- Identify, assess, and document security risks, vulnerabilities, and control gaps.
- Maintain and update risk registers, risk treatment plans, and remediation trackers.
- Assist in evaluating risks associated with applications, infrastructure, vendors, and third parties.
- Support risk identification, mitigation, acceptance, and monitoring activities.
- Prepare risk assessment reports and management summaries.
Compliance & Security Frameworks
- Support compliance assessments against applicable standards and regulations.
- Work with frameworks such as:
- ISO 27001
- SOC 2
- NIST Cybersecurity Framework
- CIS Controls
- PCI DSS
- DPDP Act / Rules
- CERT-In requirements
- Industry-specific security requirements
- Review security policies, procedures, standards, and controls.
- Identify compliance gaps and recommend appropriate corrective actions.
- Maintain compliance documentation and evidence repositories.
Audit & Assessment Support
- Coordinate with internal and external stakeholders during security audits.
- Collect, validate, organize, and maintain audit evidence.
- Track audit observations, findings, and corrective action plans.
- Assist with internal control testing and compliance reviews.
- Prepare audit-ready documentation and reports.
Third-Party & Vendor Risk
- Support vendor and third-party security assessments.
- Review vendor security questionnaires, certifications, policies, and compliance documentation.
- Identify third-party security and compliance risks.
- Maintain vendor risk assessment records and remediation trackers.
Documentation & Reporting
- Prepare risk assessment, compliance, audit, and security reports.
- Maintain policies, procedures, risk registers, control matrices, and compliance trackers.
- Create management dashboards and periodic compliance reports.
- Communicate security and compliance findings clearly to technical and non-technical stakeholders.
Required Skills
- Strong understanding of cybersecurity, information security, risk management, and compliance .
- Knowledge of security controls, policies, procedures, and audit processes.
- Understanding of common cybersecurity frameworks and standards.
- Positive analytical and problem-solving skills.
- Strong documentation and report-writing abilities.
- Ability to analyze evidence and identify control gaps.
- Strong communication and stakeholder-management skills.
- Proficiency in Microsoft Excel, Word, PowerPoint, and documentation tools.
Preferred Certifications Candidates with any of the following certifications will be preferred:
- ISO 27001 Lead Auditor / Lead Implementer
- CISA
- CISM
- CRISC
- ISO 31000
- CompTIA Security+
- Other relevant GRC or cybersecurity certifications
Education Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Security, or a related field.
What We’re Looking For
We are looking for someone who is:
- Detail-oriented and analytical
- Strong at documentation and evidence management
- Comfortable working with clients and internal teams
- Interested in cybersecurity governance and regulatory compliance
- Able to understand technical security issues and translate them into business risks
- Proactive in identifying compliance gaps and improvement opportunities
- Willing to continuously learn evolving cybersecurity regulations and standards
Why Join Digital Defense?
- Work on real-world cybersecurity and GRC engagements.
- Gain exposure to multiple industries and security frameworks.
- Work with cybersecurity, risk, compliance, and technology professionals.
- Develop practical experience in cybersecurity governance and regulatory compliance.
- Opportunity to grow into specialized GRC, risk, audit, or cybersecurity consulting roles.
How to Apply Interested candidates can share their updated CV along with relevant certifications and experience details.
Email:
[email protected]
Website: digitaldefense.co.in
📌 Red Team Assessment (Maharashtra)
🏢 Digital Defense
📍 Maharashtra