24 Sep
|
Trigent Software
|
Bengaluru
24 Sep
Trigent Software
Bengaluru
Business Analyst
Information Security Governance, Risk & Compliance (GRC) — Requirements & Analysis
Role Purpose
Bridge business and regulatory stakeholders and the technical delivery team within the Information
Security Governance, Risk, Compliance & Assurance (GRC) domain. The Business Analyst elicits,
analyzes, and documents requirements; owns the Business Requirements Document (BRD); and translates regulatory, control, evidence, risk, and workflow needs into clear user stories, acceptance criteria, and process designs for AI-enabled GRC solutions.
Key Responsibilities
- Requirements ownership: Own, refine, and maintain the BRD and a clear requirements traceability matrix from business need through to delivered capability.
- Elicitation: Run workshops and interviews with GRC, Risk, Audit, Compliance, and Information
Security SMEs and business control owners to capture detailed requirements.
- Process analysis: Document current-state vs target-state processes for compliance execution,
risk assessment, audit readiness, and evidence management; identify gaps and improvement opportunities.
- Control framework & taxonomy: Support definition and alignment of standardized control frameworks and taxonomies; map controls across regulations and standards (e.g., ISO 27001,
NIST, relevant central-bank requirements).
- Capability requirements: Specify requirements for regulatory ingestion (NLP), intelligent control mapping, workflow orchestration, the evidence lifecycle and reuse rules, risk-assessment engines, and executive dashboards/reporting.
- Backlog & user stories: Write user stories with clear acceptance criteria and, with the Product
Owner,
groom and prioritize the backlog — helping focus proof-of-concept and MVP scope on high-value use cases.
- Functional & non-functional requirements: Capture NFRs including role-based access control, audit logging, scalability, and integration with SIEM, IAM, and DevSecOps systems.
- Vendor fit/gap analysis: Support build–buy–hybrid evaluation through structured fit/gap analysis of candidate platforms (e.g., ServiceNow GRC, RSA Archer, MetricStream, OneTrust)
against business requirements.
- Data requirements: Define data requirements and quality expectations needed to train and operate AI/NLP models, in partnership with Data and ML Engineers.
- Validation & UAT: Develop test scenarios and acceptance criteria, support QA and User
Acceptance Testing, and confirm delivered features meet documented requirements.
- Change & sign-off: Manage requirement change requests, facilitate stakeholder reviews, and obtain formal sign-offs at each stage gate.
Required Qualifications & Experience
- Bachelor's degree in Business, Information Systems, Computer Science, or a related field.
Information Security Governance, Risk & Compliance (GRC) Confidential
- Business analysis certification preferred — CBAP, CCBA, PMI-PBA, or an Agile BA / Scrum credential.
- 5+ years of business-analysis experience, including delivery in GRC, risk, compliance, or information security — ideally in financial services.
- Strong requirements elicitation, process modeling (e.g., BPMN), use-case and user-story authoring.
- Experience producing BRDs, functional specifications, and requirements traceability.
- Experience supporting vendor evaluation and fit/gap analysis against documented requirements.
Technical & Domain Knowledge
- Working knowledge of GRC platforms and control frameworks (ISO 27001, NIST; awareness of central-bank regulatory expectations).
- Understanding of compliance, risk-assessment, audit-readiness, and evidence-management processes.
- Familiarity with AI/ML and NLP concepts and the data requirements that support them
(preferred).
- Comfort with backlog and analysis tooling (e.g., Jira / Azure DevOps) and process-modeling tools.
Core Competencies
- Exceptional written documentation and analytical rigor with strong attention to detail.
- Skilled facilitator able to translate between business, regulatory, and technical audiences.
- Structured, requirements-led thinking and the ability to prioritize for value.
- Team-oriented, proactive, and comfortable operating amid evolving requirements.
Preferred (Nice to Have)
- Experience in banking or financial services within the UAE / GCC region.
- Prior exposure to AI/ML or NLP projects and to agile delivery.
Success Measures
- Clear, complete, and traceable requirements that the delivery team can build against with minimal rework.
- Well-prioritized scope focused on high-value, defensible use cases.
- Accurate control mapping and evidence/workflow requirements that reduce duplication and support reuse.
- Successful UAT and stakeholder sign-off at each stage gate.
📌 Business Analyst (Bengaluru)
🏢 Trigent Software
📍 Bengaluru