11 Sep
|
NMT Security
|
Noida
11 Sep
NMT Security
Noida
About the role
We are a product-based startup building an AI-native automation platform for audit and assessment readiness. We are hiring a GRC professional who can operate across two fronts: keeping our own compliance posture audit-ready, and bringing real-world GRC judgement into how the product is built.
This is a hands-on role. You will own controls, evidence, and audit cycles end to end rather than sitting in a review layer above them. If you want to move beyond checklist compliance and understand how controls are designed, mapped, and automated, this role is built for that.
What you'll do
Framework implementation and audit readiness
- Implement and maintain the ISO 27001 ISMS — risk assessment, SoA, internal audits, management review, and surveillance/recertification support.
- Run SOC 2 Type II readiness and the observation period: control design, evidence cadence, sampling, exception tracking, and auditor coordination.
- Prepare and maintain audit artefacts so that every control has a defensible, repeatable evidence trail.
RBI and regulated-sector compliance
- Support ITGRC obligations under the RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices, and related circulars (Cyber Security Framework, Outsourcing of IT Services, IT Examination / CSITE expectations, System Audit Reports).
- Map regulatory clauses to internal controls and help customers and internal teams interpret what a requirement actually demands in practice.
- Track regulatory changes and translate them into control and policy updates.
Data privacy
- Support DPDPA implementation: consent and notice flows, data principal rights handling, data inventory and mapping, retention, breach notification readiness.
- Assist with privacy impact assessments and third-party/processor due diligence.
Risk and control operations
- Maintain the risk register:
identification, scoring, treatment plans, and follow-through on remediation owners and timelines.
- Run vendor risk assessments and periodic reviews.
- Draft and maintain policies, standards, and procedures; keep them versioned, approved, and actually usable.
- Handle customer security questionnaires, RFP security sections, and due-diligence requests.
Product collaboration
- Work with product and engineering to turn control logic, framework mappings, and evidence requirements into platform capability.
- Give practical feedback on where automation helps and where auditor judgement is still required.
What we're looking for
- 1–3 years of hands-on GRC, information security compliance, or IT audit experience.
- Working knowledge of RBI ITGRC and regulatory guidelines applicable to banks, NBFCs, or fintechs.
- Practical experience with ISO 27001 (implementation, internal audit, or audit support).
- Exposure to a full SOC 2 Type II cycle — readiness, evidence collection, or auditor interaction.
- Familiarity with DPDPA and its operational implications.
- Ability to read a control requirement and independently decide what evidence would satisfy an auditor.
- Clear written communication — policies, assessment reports, and customer responses are a large part of the job.
- Comfort working in a fast-moving startup where scope shifts and process is something you help build.
Good to have
- Exposure to NIST CSF, GDPR, HIPAA, or PCI-DSS.
- Certifications such as ISO 27001 Lead Auditor / Lead Implementer, or a privacy certification (CIPP/E, CIPM, DCPP, CDPSE). ISACA certifications (CISA, CRISC) are also valued.
- Experience with GRC or compliance automation tooling.
- Experience supporting audits in a cloud setting (AWS/Azure/GCP) and understanding of cloud security controls.
- Prior work in a banking, fintech, or SaaS environment serving regulated customers.
📌 Analyst / Senior Analyst — Governance, Risk & Compliance (GRC) (Noida)
🏢 NMT Security
📍 Noida