GRC Analyst / GRC Specialist (Information Security)_True Balance- NBFC (Gurugram)

GRC Analyst / GRC Specialist (Information Security)_True Balance- NBFC (Gurugram)

24 Sep
|
True Credits
|
Gurugram

24 Sep

True Credits

Gurugram

Role: Senior GRC Analyst / GRC Specialist (Information Security)

Department: Information Security

Work Mode: Hybrid

About the Role

We are seeking a seasoned Senior Governance, Risk, and Compliance (GRC) Analyst / Specialist with approximately 5 years of experience to lead and execute our core information security governance, risk management, and compliance operations.

In this role, you will own day-to-day GRC operations, acting as the primary operational point of contact for assurance activities. You will collaborate closely with internal engineering, IT, security operations, product, and legal teams, as well as external vendors. The ideal candidate is a self-starter who can drive continuous improvement, automate manual processes, and elevate the organization's overall security and compliance posture.

Key Responsibilities

1. Risk Management & Governance

- Maintain the enterprise and operational risk registers, conducting risk assessments across business and technology functions.
- Track risk treatment plans, monitor mitigation activities, and ensure timely closure of identified risks.
- Prepare GRC and security metrics, dashboards, and management reports, tracking KPIs and KRIs.

2. Third-Party Risk Management (TPRM)

- Manage end-to-end TPRM activities, including vendor onboarding assessments, due diligence reviews, and periodic reassessments.
- Review vendor security questionnaires, audit reports (SOC 2, ISO), certifications, and remediation plans.
- Maintain vendor risk registers, track outstanding findings, and monitor risk closure.

3. Compliance, Audit & Control Monitoring

- Perform control monitoring and effectiveness reviews to validate compliance with internal policies, ISO 27001, and regulatory obligations (e.g., RBI compliance).
- Support internal and external audits by coordinating evidence collection, responding to auditor requests, and tracking remediation actions.
- Manage customer security assessments, due diligence requests,



and security questionnaire responses.

4. Identity & Access Governance (IAM) & Asset Management

- Coordinate periodic user access, privileged access, and SSO reviews.
- Validate user provisioning, deprovisioning, role changes, and segregation of duties (SoD) controls.
- Conduct periodic asset inventory reviews to ensure asset ownership, classification, and lifecycle compliance.

5. Incident Management / SOC

- Monitor security alerts generated by SOC, SIEM, and application logs, coordinating with relevant technical teams for investigation and remediation.
- Track security incidents, document findings, monitor corrective actions, and escalate critical risks.
- Govern the vulnerability management process, tracking remediation timelines and reporting overdue vulnerabilities.

6. Security Operations

- Conduct periodic hardening reviews of cloud, servers, endpoints, and network devices.
- Perform patch compliance reviews for endpoints on a periodic basis.

Required Qualifications

- Education: Bachelor's degree in Information Security, Computer Science, Risk Management, or a related technical field.
- Experience: Approximately 5 years of dedicated experience in GRC, Information Security, Risk Management, Security Operations, IAM, and RBI compliance.
- Frameworks: Solid knowledge of ISO 27001, ISO 22301, SOC 2, NIST CSF, and CIS.
- Technical Skills: Hands-on experience with SIEM platforms, security monitoring tools, and vulnerability management governance.
- Soft Skills: Excellent stakeholder management, cross-functional collaboration, and strong documentation/reporting skills (advanced MS Excel/Word).

Preferred Qualifications

- Certifications: ISO 27001 Lead Implementer / Lead Auditor, CISA, CRISC, or equivalent security certifications.
- Industry Experience: Prior experience in NBFC, PPI, SaaS, FinTech, or fast-paced product-based organizations in a regulated industry.
- Cloud Governance: Direct exposure to cloud security governance, preferably within AWS environments.

📌 GRC Analyst / GRC Specialist (Information Security)_True Balance- NBFC (Gurugram)
🏢 True Credits
📍 Gurugram

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: grc analyst / grc specialist (information security)_true balance- nbfc (gurugram) / gurugram

Subscribe to this job alert:

Get the latest job offers by email for: grc analyst / grc specialist (information security)_true balance- nbfc (gurugram) / gurugram