Information Technology Risk ManagementSupport & GRC Analyst (Noida)

Information Technology Risk ManagementSupport & GRC Analyst (Noida)

01 Oct
|
Shivalik Small Finance Bank
|
Noida

01 Oct

Shivalik Small Finance Bank

Noida

ITRM L2 Support & GRC Analyst

Job Title: IT Risk Management Analyst L2 Support

Department: Information Security / IT Governance

Location: Noida Sector 125

Experience: 5- 10 years

Employment Type: Full-Time

Required - Immedaite Joiner

1. Role Overview The IT Risk Management L2 Support & GRC Analyst will be responsible for supporting IT risk processes, regulatory compliance reporting, governance activities, technical risk assessments, internal/external audit support, and cybersecurity governance functions.

The role involves hands-on experience in risk analysis, compliance monitoring, evidence collection, report writing, VAPT interpretation, and mapping controls to frameworks such as RBI, CERT-In, UIDAI, NSDL, and HIPAA.

2. Key Responsibilities

A. IT Risk Management & Governance

- Conduct technology risk assessments, gap analysis, and risk scoring across IT systems, applications, infrastructure, and vendor environments.
- Assist in the development and maintenance of Risk Registers, Issue Trackers, and Corrective Action Plans.
- Perform RCSA (Risk Control Self-Assessment) activities, including identification of key risks, controls, and mitigation actions.
- Support IT risk governance meetings by preparing dashboards, status reports, and risk metrics.

B. GRC (Governance, Risk & Compliance) Operations

- Manage and update controls within GRC platforms (Archer, ServiceNow GRC, Metric Streamor internal equivalents).
- Map controls to frameworks such as, COBIT, HIPAA, PCI DSS (as applicable).
- Monitor control performance and support periodic control testing.
- Perform policy compliance assessments and track deviations/exceptions.

C. Regulatory Reporting & Compliance (RBI, IRDAI, CERT-In, NSDL, UIDAI)

- Prepare and submit periodic regulatory reports such as:




- RBI Cyber Security Incident Reporting, System Audit, Cyber Drill Compliance
- IRDAI Cyber Security Guidelines Compliance & Audit Inputs
- CERT-In Incident Reporting & Monthly/Quarterly Submissions
- UIDAI Security Audits & Compliance Reports

- NSDL/CRA guidelines compliance
- Liaise with internal stakeholders for gathering evidence and validating data for regulatory submissions.
- Track changes in regulatory requirements and ensure timely implementation in processes.

D. Audit Support (Internal, External, Statutory)

- Coordinate with IT, Infosec, and internal & external auditors for audits such as:
- CSITE, Statutory
- RBI/IRDAI/CERT-In mandated audits
- Internal IT & Cybersecurity audits

- Vendor security assessments
- Collect, verify, and organize audit evidence as per auditor expectations.
- Maintain audit trail, evidence repository, and noncompliance trackers.
- Map audit findings to risk categories and track closure of observations.

E. Technical Skills VAPT Understanding & Security Concepts

- Understand VAPT reports, identify technical vulnerabilities, and map them to risk impact.
- Work with SOC/Infra/Application teams for remediation tracking and evidence validation.
- Support patch management, vulnerability closure, and secure configuration initiatives.
- Understand common security domains: network security, application security, cloud controls, identity access management.

F.



Documentation & Report Writing

- Prepare high-quality risk reports, regulatory submissions, audit reports, and management dashboards.
- Draft Standard Operating Procedures (SOPs), compliance summaries, and policy updates.
- Document process gaps, risks, and required controls in a clear and structured manner.

3. Required Skills & Competencies Technical & Functional Skills

- Strong understanding of:
- RBI Cyber Security Framework & Baseline Controls
- CERT-In 2022 Guidelines
- HIPAA Security Rule (if applicable)
- Good knowledge of Vulnerability Assessment & Penetration Testing (VAPT) cycles.
- Experience in audit evidence management, documentation control, and compliance reporting.
- Ability to think analytically to identify and assess technology risks.

Soft Skills

- Excellent written communication (strong report-writing ability).
- Valuable stakeholder coordination across IT, Security, Operations, and Audit.
- Ability to work independently and in fast-paced regulatory environments.
- Problem-solving mindset, attention to detail, and structured thinking.

4. Educational Qualifications

- Bachelors degree in computer science, IT, Electronics, Cyber Security, or related field.
- Preferred Certifications (any one or more):
- CEH / Security+ / CCSP (optional)

- NIST CSF Foundation
- ITIL (for L2 support/gov processes)
- CRISC / CISA (added advantage)

5. Key Performance Indicators (KPIs)

- Timely submission of regulatory reports.
- Reduction in open audit findings.
- Closure timelines for vulnerabilities & risks.
- Accuracy and completeness of documentation.
- Compliance score improvement (RBI frameworks).
- Efficiency in RCSA completion & control testing

📌 Information Technology Risk ManagementSupport & GRC Analyst (Noida)
🏢 Shivalik Small Finance Bank
📍 Noida

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: information technology risk managementsupport & grc analyst (noida) / noida

Subscribe to this job alert:

Get the latest job offers by email for: information technology risk managementsupport & grc analyst (noida) / noida