GRC Consultant Information Security | ISO 27001 | Risk & Compliance (2-3 Yrs)
- Experience: 2-3 Years
- Location: Trivandrum / Kochi (Hybrid) relocation candidates welcome
- Employment Type: Full-Time, Permanent
- Salary: Up to 40,000/month
- Education: B.Tech/B.E./BCA or equivalent in Computer Science, IT, or related field
Azpirantz Technologies is hiring a GRC Consultant Information Security to join our growing Governance, Risk & Compliance team. This is a client-facing consulting role for a security professional with 2-3 years of hands-on experience in ISO 27001 implementation, risk assessments, and compliance audits. You'll work directly with clients on security assessments, policy development, and framework implementation across ISO 27001, ISO 22301, ISO 31000, NIST, and CIS.
Key Responsibilities:
- Support consulting engagements in Information Security, Business Continuity, Data Privacy, IT Governance, and Risk Management
- Conduct AS-IS assessments, gap assessments, risk assessments, and compliance assessments
- Develop and implement information security policies, procedures, guidelines, and templates
- Perform compliance assessments against ISO 27001, ISO 27002, ISO 22301, ISO 31000, NIST, and CIS frameworks
- Identify, document, and track security gaps, risks, and non-conformities through to closure
- Prepare assessment reports, technical documentation, and client-facing presentations
- Build and monitor GRC KPIs, metrics, and compliance dashboards
- Translate client business requirements into practical security and GRC deliverables
- Advise clients on applicable standards, security controls, and industry best practices
- Support institutionalization of security and compliance processes within client organizations
- Travel to client locations (domestic and occasionally international) as project needs require.
Required Skills & Experience:
- 2-3 years of experience in Information Security, GRC, Risk & Compliance, or IT Governance
- Strong working knowledge of ISO 27001 and ISO 27002
- Hands-on experience with security risk assessments and compliance audits
- Familiarity with ISO 22301, ISO 31000, NIST, CIS, or equivalent frameworks
- Understanding of security controls, policies, and risk mitigation practices
- Exposure to application security, network security, endpoint security, server security, and SIEM/security monitoring concepts
- Solid technical writing, documentation, and report-preparation skills
- Excellent verbal and written communication comfortable presenting to both technical and non-technical stakeholders
- Bachelor's degree in Computer Science, Engineering, IT, or related field
Preferred Certifications: ISO 27001 LA/LI, ISO 22301 LA/LI, CompTIA, CRISC,(any of these will be an added advantage)
Other Requirements:
- Valid passport and willingness/eligibility for international travel when required
- Must own a personal laptop for work
- Willingness to work hybrid out of Trivandrum or Kochi, or relocate
Key Skills: GRC, Information Security, ISO 27001, ISO 27002, ISO 22301, ISO 31000, NIST, CIS Controls, Risk Assessment, Compliance Audit, Gap Assessment, IT Governance, Business Continuity, Data Privacy, Security Consulting, Vulnerability Assessment, Client Management, Security Documentation, CISA, CISSP, CRISC
How to Apply:
Send your updated CV to
[email protected] or contact (phone hidden)
📌 GRC Consultant | Information Security (Kochi)
🏢 InfosecTrain
📍 Kochi