24 Sep
|
Exxat Systems
|
Bengaluru
24 Sep
Exxat Systems
Bengaluru
Job Overview
We are lookingfor a detail-oriented and proactive GRC Analyst to join our growing securityand compliance team. In this role, you will be responsible for maintaining andadvancing our compliance posture across multiple regulatory frameworks,including SOC 2, HIPAA, FERPA, ISO 27001/27701/42001, TX-RAMP, and GDPR. Youwill work closely with our security, engineering and other teams to ensure ourplatform and operations meet the compliance regulations - critical to ourposition as a trusted leader in educational and healthcare organizations.
Responsibilities
- Evaluatecompliance alignment for SOC 2, HIPAA, ISO 27001, ISO 27701, ISO 42001,TX-RAMP, and GDPR, ensuring continuous audit readiness.
- Perform internalgap assessments and readiness evaluation against applicable frameworks andstandards, track remediation plans.
- Monitor theInformation Security Management System (ISMS) and Artificial IntelligenceManagement System (AIMS) KPIs and objectives in alignment with ISO 27001 andISO 42001 requirements.
- Coordinateinternal and external compliance audits - prepare evidence packages, manageauditor requests, and drive timely closure of audit findings.
- Monitor controldocumentation for internal and external audits.
- Collaborate withengineering, product, and DevOps teams to embed compliance requirements intothe SDLC and cloud infrastructure.
- Track, measure,and report key compliance metrics and KPIs on a regular basis.
- Supportclient-facing compliance activities, including responding to questionnaires,RFPs, and Third Party Risk Management (TPRM) inquiries from clients andprospects.
Profile Requirement
- Bachelors degree in information security, Computer Science, Information Systems, or a relatedfield.
- 3 - 5 years ofexperience in information security compliance, GRC, or a closely related role.
- Hands-on,demonstrable experience with two or more of the following frameworks: SOC 2,HIPAA, ISO 27001, ISO 27701, ISO 42001, TX-RAMP, GDPR.
- Experiencecoordinating or supporting audit readiness, evidence collection, and externalauditor engagements.
- Appropriateanalytical, documentation, and communication skills - translate technicalcompliance requirements into explicit guidance for both technical andnon-technical audiences.
- Ability to workcross-functionally and support concurrent compliance initiatives.
Good to Have
- Relevantcompliance certifications such as ISO 27001 Lead Implementer/Auditor orsimilar.
- Understanding ofgovernance frameworks like NIST SP 800-53/ CMF/ RMF.
- Prior experiencein a health-tech, edtech SaaS environment.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 GRC Analyst (Bengaluru)
🏢 Exxat Systems
📍 Bengaluru