24 Sep
|
Dtdc Express
|
Bengaluru
24 Sep
Dtdc Express
Bengaluru
GRC Analyst
Job Summary
We are seeking an analytical and detail-oriented GRC Analyst to support our cybersecurity and compliance initiatives. In this role, you will evaluate risk, manage internal and external audits, draft security policies, and ensure alignment with regulatory frameworks (e.g., ISO 27001-2022, 27005-2022). You will act as a bridge between technical engineering teams, internal stakeholders, and external auditors.
Key Responsibilities
- Framework Management & Audits: Prepare for, coordinate, and lead ISO 27001-2022, ISO 27005-2022. Collect evidence, conduct gap analyses, and manage remediation efforts for control failures.
- Risk Assessments: Identify, evaluate, and prioritize cybersecurity and operational risks across technical infrastructure, vendor networks, and internal processes. Maintain the enterprise Risk Register.
- Policy & Governance: Draft, review, and update internal security policies, standard operating procedures (SOPs), and governance documentation to reflect regulatory changes.
- Third-Party Risk Management (TPRM): Evaluate vendor and third-party security postures using questionnaires (CAIQ, SIG) and contract reviews to ensure supply-chain security.
- Regulatory Compliance & Data Privacy:
Monitor compliance with global privacy regulations (e.g., GDPR, CCPA/CPRA, India DPDP Act) and sector-specific laws.
- Security Awareness & Culture: Deliver security training to employees, track phishing awareness metrics, and advocate for security-first practices company-wide.
Required Skills & Qualifications 1. Education & Experience
- Bachelor's Degree, Information Security, equivalent experience.
- 25 years of experience in GRC, IT audit, information security, or risk management.
2. Frameworks & Regulatory Knowledge (Pick applicable)
- Standards: ISO/IEC 27001 / 27005
- Regulations: GDPR, CCPA, HIPAA, PCI-DSS, SOX.
3. Technical & Qualified Skills
- Control Evidence Gathering: Ability to read technical artifacts (IAM access logs, change request tickets, cloud configuration settings).
- Audit Management: Experience using GRC platforms
- Communication: Ability to explain complex technical risks to executive leadership and non-technical staff.
Preferred / Nice-to-Have Requirements
- Certifications (High Value):
- Entry/Mid-Level: CISA (Certified Information Systems Auditor), ISO 27001 Lead Auditor.
📌 Senior Executive (Bengaluru)
🏢 Dtdc Express
📍 Bengaluru