Job Type: Full time
Remote: Hybrid
GRC Consultant - Information SecurityLocation: Preferably Trivandrum / Kochi (Hybrid) OR Willing to RelocateExperience: 2–3 YearsSalary: Up to ₹40,000 per monthEmployment Type: Full-TimeJob DescriptionWe are looking for a GRC Consultant with 2–3 years of experience in Information Security, Governance, Risk, and Compliance. The candidate will be responsible for supporting client consulting engagements, security assessments, compliance activities, documentation, and implementation of information security processes.Key Responsibilities:Support consulting engagements related to Information Security, Business Continuity, Data Privacy, IT Governance, and Risk Management.Conduct AS-IS assessments, gap assessments, risk assessments, and compliance assessments.Assist in developing and implementing information security policies, processes, procedures, guidelines, and templates.Conduct compliance assessments against frameworks and standards such as ISO 27001, ISO 27002, ISO 22301, ISO 31000, NIST, and CIS.Identify and document security gaps, risks, and non-conformities and support corrective action closure.Prepare technical reports, presentations, assessment reports, and client documentation.Develop and track KPIs, metrics, and compliance reports.Work with clients and internal stakeholders to understand business requirements and translate them into appropriate security and GRC deliverables.Provide guidance on applicable security standards, controls, processes, and best practices.Support implementation and institutionalization of security and compliance processes within client environments.Travel occasionally to client locations,
including international locations, based on project requirements.Required Skills & Qualifications:2–3 years of relevant experience in Information Security, GRC, Risk, Compliance, IT Governance, or related areas.Strong understanding of ISO 27001 and ISO 27002.Experience in security risk assessments and compliance assessments.Knowledge of ISO 22301, ISO 31000, NIST, CIS, or similar frameworks.Understanding of information security controls, policies, processes, and risk mitigation.Familiarity with application security, network security, endpoint security, server security, and SIEM/security monitoring concepts.Good technical documentation and report-writing skills.Strong written and verbal communication skills.Ability to interact effectively with technical and non-technical stakeholders.Bachelor's degree in Computer Science, Engineering, Information Technology, or a related field.Additional Requirements:Willingness to travel occasionally to client locations as required by projects.Valid passport and eligibility to undertake international travel when required.Candidate should have a personal laptop for work-related activities.Preferred Certifications:Certifications such as ISO 27001 LA/LI, ISO 22301 LA/LI, CISA, CISSP, CRISC, CCSK, CompTIA CASP, or PMP will be an added advantage.Key Competencies:Client-facing skillsRisk assessment and analysisInformation Security & GRCCompliance and auditDocumentation and reportingStakeholder managementProject coordinationBusiness and technical understandingHow to Apply?Interested candidates can share their updated CV at:Email:
[email protected]: (phone hidden)
📌 GRC Consultant – Information Security (Thiruvananthapuram)
🏢 Infosec Train
📍 Thiruvananthapuram