11 Sep
|
The closing Gap
|
Bengaluru
11 Sep
The closing Gap
Bengaluru
We are seeking an experienced GRC Specialist with a strong background in defense, government/PSUs, critical infrastructure, or highly regulated air-gapped environments.
The candidate will be responsible for driving information security governance, conducting security and risk assessments, and ensuring compliance with CERT-In directives, MeitY guidelines, ISO 27001, NIST frameworks, and defense-grade security requirements.
Key Responsibilities
- Formulate, evaluate, and enforce information security policies for isolated, air-gapped, and critical infrastructure networks.
- Conduct end-to-end security audits aligned with ISO 27001, CERT-In directives, MeitY guidelines, and NIST SP 800-171/800-53 controls.
- Identify, assess, and mitigate technical and operational risks across IT, OT/SCADA, and specialized research networks.
- Conduct audits of third-party vendors, system integrators, and software deliverables, with a focus on hardware/software supply chain vulnerabilities and compliance.
- Establish data handling, data classification, and Data Loss Prevention (DLP) controls for intellectual property and sensitive R&D; data.
- Support governance protocols for incident management, forensic reporting, and compliance disclosures to relevant defense authorities/DCyA.
- Support information security governance and compliance activities across regulated and sensitive environments.
Required Qualifications
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity,
or a related engineering discipline.
- 5+ years of dedicated GRC experience.
- At least 2+ years of experience supporting defense, government (MoD/DPSUs), critical infrastructure, or air-gapped enterprise environments.
- Clean background and eligibility for high-level security clearance checks.
- Prior security clearance status is highly preferred.
Required Certification Candidates must hold at least one of the following:
- CISA
- CISM
- CRISC
- ISO 27001 Lead Auditor
CISSP is a major plus. Framework & Compliance Expertise
Solid understanding of
- CERT-In directives
- MeitY guidelines
- ISO 27001:2022
- NIST SP 800-53
- Cyber Crisis Management Plan (CCMP) execution
GRC Tools Experience with one or more of the following:
- Archer
- MetricStream
- ServiceNow GRC
Preferred Background Experience in any of the following environments is highly relevant:
- Defense
- Government / PSU
- Ministry of Defence (MoD) / DPSUs
- Critical Infrastructure
- Air-gapped / isolated enterprise environments
- IT / OT / SCADA environments
- Specialized research networks
Key Skills GRC | Information Security Governance | Risk Assessment | Security Audits | ISO 27001 | CERT-In | MeitY | NIST SP 800-53 | NIST SP 800-171 | CCMP | DLP | Data Classification | Third-Party Risk | Supply Chain Security | IT/OT Security | Air-Gapped Environments | Defense Security | Compliance
Work Location: In person
📌 GRC Specialist (Bengaluru)
🏢 The closing Gap
📍 Bengaluru