GRC Consultant (Thiruvananthapuram)

GRC Consultant (Thiruvananthapuram)

14 Sep
|
Amyntor Tech Solutions
|
Thiruvananthapuram

14 Sep

Amyntor Tech Solutions

Thiruvananthapuram

Experience: 1–2 Years

Employment Type: Full-Time

Department: Governance, Risk & Compliance (GRC)

Location: Trivandrum

About the Role:

We are looking for a motivated and detail-oriented GRC Consultant with 1–2 years of relevant experience in Governance, Risk & Compliance, Information Security, Cybersecurity, IT Audit, or related areas.

The candidate will support clients in implementing and maintaining information security and compliance programs, conducting risk assessments, preparing GRC documentation, supporting audits, and assessing compliance with applicable industry standards, regulatory requirements, and data privacy regulations.

The ideal candidate should have a good understanding of ISO 27001, cybersecurity fundamentals, risk management, and information security controls. Knowledge of India's Digital Personal Data Protection (DPDP) Act, 2023 will be an added advantage.

Key ResponsibilitiesGovernance, Risk & Compliance:

- Assist in the implementation and maintenance of Information Security Management Systems (ISMS).
- Support clients in identifying, assessing, and managing information security risks.
- Assist in preparing and maintaining risk registers, risk treatment plans, control matrices, and compliance trackers.
- Conduct gap assessments against applicable security standards, frameworks, and regulatory requirements.
- Support the implementation and monitoring of information security controls.
- Track risks, compliance requirements, audit findings, corrective actions, and remediation activities.
- Assist in preparing periodic GRC and compliance reports for management and clients.

ISO 27001 & ISMS:

- Support ISO/IEC 27001 implementation and maintenance activities.
- Assist in preparing and maintaining ISMS documentation.
- Support development and review of information security policies, procedures, standards, and guidelines.
- Assist with Statement of Applicability (SoA) preparation and control implementation.
- Support internal and external ISO audits by coordinating evidence and documentation.
- Assist in tracking and closing audit observations and non-conformities.

Risk & Security Assessments:

- Assist with information security and cybersecurity risk assessments.
- Identify security risks, vulnerabilities, and control gaps.
- Support risk analysis and development of appropriate risk treatment plans.
- Assist in reviewing the effectiveness of implemented security controls.
- Support third-party/vendor risk assessments and security due diligence activities.
- Coordinate with technical and business teams to understand existing security controls and processes.

Data Privacy & DPDP:





- Support assessments related to data protection and privacy requirements.
- Develop an understanding of India's Digital Personal Data Protection (DPDP) Act, 2023 and its applicability to organizations.
- Assist in identifying data privacy and protection gaps.
- Support documentation related to privacy controls, data handling, and compliance requirements.
- Assist in reviewing organizational processes involving collection, processing, storage, sharing, and protection of personal data.
- Support clients in implementing appropriate privacy and security controls.

Audit & Compliance:

- Support internal and external audits and compliance assessments.
- Coordinate with stakeholders for audit evidence collection and validation.
- Maintain audit evidence repositories and compliance documentation.
- Assist in preparing responses to audit findings and observations.
- Track corrective and preventive actions until closure.
- Support periodic compliance reviews and control testing.

Client & Project Coordination:

- Coordinate with client stakeholders to understand business and security requirements.
- Conduct meetings and discussions with technical and business teams as required.
- Prepare professional assessment reports, presentations, compliance reports, meeting minutes, and project documentation.
- Track project activities, deliverables, timelines, and dependencies.
- Communicate identified risks, gaps, and recommendations clearly to stakeholders.
- Work collaboratively with cybersecurity, IT, HR, legal, compliance, and business teams.

Required Skills & Knowledge

- Good understanding of Governance, Risk & Compliance (GRC) concepts.
- Good understanding of Information Security and Cybersecurity fundamentals.
- Knowledge of ISO/IEC 27001 and ISMS concepts.
- Understanding of information security risk assessment and risk management.
- Basic understanding of security controls and control frameworks.
- Strong documentation and report-writing skills.
- Good analytical and problem-solving skills.
- Good verbal and written communication skills.
- Ability to interact professionally with clients and internal stakeholders.
- Good working knowledge of Microsoft Word, Excel, and PowerPoint.
- Ability to manage multiple tasks and deliverables within defined timelines.





Preferred Knowledge Exposure to or knowledge of any of the following will be an advantage:

- ISO/IEC 27001 & ISO/IEC 27002
- Digital Personal Data Protection (DPDP) Act, 2023
- Data privacy and protection principles
- SOC 2
- NIST Cybersecurity Framework (NIST CSF)
- CIS Controls
- PCI DSS
- GDPR / Data Protection requirements
- Business Continuity Management
- Third-party / Vendor Risk Management
- Security and compliance assessments
- Vulnerability and security assessment processes

Qualifications

- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related discipline.
- Relevant professional certifications will be an advantage, including:
- ISO/IEC 27001 Foundation
- ISO/IEC 27001 Lead Implementer
- ISO/IEC 27001 Lead Auditor
- CISA
- CompTIA Security+
- Other relevant GRC, cybersecurity, risk, or privacy certifications

Experience 1–2 years of relevant experience in one or more of the following areas:

- GRC Consulting
- Information Security
- Cybersecurity Consulting
- IT Audit
- Compliance
- Risk Management
- ISMS Implementation
- Security Assessments
- Data Privacy / Compliance

Candidates with strong cybersecurity/GRC knowledge and relevant internship or project experience may also be considered.

Key Competencies

- Strong attention to detail
- Excellent documentation skills
- Analytical and structured approach to problem-solving
- Positive client-facing and communication skills
- Ability to understand business and technical requirements
- Strong willingness to learn and develop professionally
- Ability to work independently as well as part of a team
- Good time management and organizational skills
- Professional handling of confidential and sensitive information
- Ability to work across multiple client assignments

Career Chance This role provides an opportunity to build a strong career in Governance, Risk & Compliance, Cybersecurity, Information Security, and Data Privacy, with exposure to multiple security frameworks, regulatory requirements, audits, and client environments.

Company Profile:

Amyntor Tech Solutions Pvt Ltd steered by young and experienced professionals from different walks of life we offer a plethora of skills. We are headquartered at Thiruvananthapuram, Kerala and got a presence all over India. We are proud to introduce ourselves as sentinel Cybersecurity service provider. We are vehemently endorsed by our customers by giving references from the nook and corner of the world.

Pay: ₹20,000.00 - ₹25,000.00 per month

Benefits

- Cell phone reimbursement
- Commuter assistance

Work Location: Hybrid remote in Technopark, Thiruvananthapuram, Kerala

📌 GRC Consultant (Thiruvananthapuram)
🏢 Amyntor Tech Solutions
📍 Thiruvananthapuram

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: grc consultant (thiruvananthapuram) / thiruvananthapuram