GRC Consultant – Information Security
Location: Preferably Trivandrum / Kochi | Candidates willing to relocate may also apply
Experience: 2–5 Years
Salary: Up to ₹40,000 per month
Employment Type: Full time (Onsite)
We are looking for a GRC Consultant – Information Security with 2–5 years of relevant experience in Information Security, Governance, Risk, and Compliance (GRC).
The candidate will be responsible for supporting client consulting engagements, security and compliance assessments, risk assessments, documentation, and the implementation and institutionalization of information security processes.
Key Responsibilities
- Support consulting engagements related to Information Security, Business Continuity, Data Privacy, IT Governance, and Risk Management.
- Conduct AS-IS assessments, gap assessments, risk assessments, and compliance assessments.
- Assist in developing and implementing information security policies, processes, procedures, guidelines, and templates.
- Conduct compliance assessments against frameworks and standards such as ISO 27001, ISO 27002, ISO 22301, ISO 31000, NIST, and CIS.
- Identify and document security gaps, risks, and non-conformities, and support corrective action and closure activities.
- Prepare technical reports, presentations, assessment reports, compliance reports, and client documentation.
- Develop and track KPIs, metrics, risk registers, and compliance reports.
- Work closely with clients and internal stakeholders to understand business requirements and translate them into appropriate security and GRC deliverables.
- Provide guidance on applicable security standards, controls, processes, and industry best practices.
- Support the implementation and institutionalization of security and compliance processes within client environments.
- Travel occasionally to client locations,
including international locations, based on project requirements.
Required Skills & Qualifications
- 2–5 years of relevant experience in Information Security, GRC, Risk, Compliance, IT Governance, or related areas.
- Strong understanding of ISO 27001 and ISO 27002.
- Hands-on experience in security risk assessments and compliance assessments.
- Good knowledge of ISO 22301, ISO 31000, NIST, CIS, or similar frameworks.
- Understanding of information security controls, policies, processes, and risk mitigation practices.
- Familiarity with application security, network security, endpoint security, server security, and SIEM/security monitoring concepts.
- Strong technical documentation and report-writing skills.
- Excellent written and verbal communication skills (English)
- Ability to interact effectively with both technical and non-technical stakeholders.
- Bachelor's degree in Computer Science, Engineering, Information Technology, or a related field.
Additional Requirements
- Willingness to travel occasionally to client locations as required by projects.
- A valid passport and eligibility to undertake international travel when required.
- Candidates should have a personal laptop for work-related activities.
Preferred Certifications
Certifications in any of the following areas will be an added advantage:
- ISO 27001 Lead Auditor / Lead Implementer
- ISO 22301 Lead Auditor / Lead Implementer
- CISA
- CISSP
- CRISC
- CCSK
- CompTIA Security / CASP
- PMP
- Key Competencies
- Client-facing skills
- Risk assessment and analysis
- Information Security & GRC
- Compliance and audit
- Documentation and reporting
- Stakeholder management
- Project coordination
- Business and technical understanding
How to Apply
Interested candidates can share their updated CV with us:
Email:
[email protected]
Contact or whatsapp: (phone hidden)
📌 GRC Consultant | 4.8LPA | Trivandrum (Noida)
🏢 Infosec Train
📍 Noida