Work Shift - 4 PM to 1 AM (IST)
100% Remote
Key Priorities :
· Deliver audit readiness and timely, high-quality evidence packages.
· Maintain control documentation and support continuous monitoring.
· Own risk and Plan of Action and Milestones (PoA&M;) reporting, including end-to-end deliverables and coordination with Engineering, Product, and IT.
Audit, Assessment and Cloud Compliance.
· Lead cloud SaaS applications through audit frameworks and assessments, including SOC 1, SOC 2, NIST 800-53, NIST 800-171, CMMC, ISO, FedRAMP, PCI DSS, CIS, CSA CSM, and other applicable security regulations.
· Lead or support end-to-end internal and external audit engagements, including scoping, evidence requests, control testing, issue tracking, and final report support.
· Assess and communicate administrative, technical, and security controls across Oracle Cloud Infrastructure (OCI), Amazon Web Services (AWS), and Microsoft Azure.
· Translate regulatory obligations and control requirements into transparent, testable expectations for technical teams.
Project Delivery, Automation and Stakeholder Coordination.
· Apply project management practices to plan, track, and deliver security assessments.
· Use Jira for epics and stories, backlog grooming, tracking, and stakeholder reporting.
· Use automation and AI responsibly to streamline evidence collection, control mapping, and recurring reporting, while maintaining appropriate human review.
· Coordinate inputs and follow-through across Engineering, Product, IT, auditors, and other stakeholders.
Reporting and Continuous Improvement :
· Define, build, and maintain recurring monthly and quarterly GRC metrics and dashboards.
· Present trends, risks, and remediation status to senior leadership.
· Draft, maintain, and socialize security policies, standards, and System Security Plans (SSPs), including control narratives, implementation details, and evidence references.
· Produce high-quality audit deliverables, including narratives, evidence packages, and status reports.
· Manage risk register items and PoA&Ms; end-to-end by identifying control gaps, partnering on remediation plans, and tracking progress through continuous monitoring.
Program Ownership and Documentation
· Own, or serve as backup owner for, key GRC programs by maintaining procedures, service-level agreements (SLAs), and audit and customer-request artifacts.
· Support policy management and security due diligence questionnaires for Requests for Information (RFIs) and Requests for Proposals (RFPs).
· Participate in initiatives that improve team processes and procedures.
· Maintain and curate annual compliance training content and help improve the training process.
· Participate in incident-response reviews and root-cause analyses by documenting control failures, corrective actions, and follow-up evidence through closure.
📌 GRC ANALYST (India)
🏢 Deltek
📍 India