01 Oct
|
Spekond
|
Bengaluru
Education
Bachelor's degree in information Security, Computer Science, Information Systems, or related field; equivalent experience considered
Notice Period - IMMEDIATE JOINEER
Role & responsibilities The GRC Analyst is responsible for the day-to-day operations of Entertainment Partners' information assurance governance, risk, and compliance program. This role serves as the primary operator and administrator of the GRC platform (Drata), owns risk register maintenance, coordinates evidence collection for continuous compliance activities, and supports internal and external audit engagements. The GRC Analyst also drives the integration of GRC workflows with EP's security toolchain and ticketing platforms, and leverages artificial intelligence tools to streamline repetitive compliance operations, accelerate evidence analysis, and improve overall program efficiency.
This role works cross-functionally with control owners across IT, Engineering, HR, Legal, and business operations to ensure EP's ISO 27001, SOC 2, and regulatory obligations are met on a continuous basis.
Technical Skills
- Proficiency in GRC platform administration (configuration, workflows, integrations, reporting)
- Working knowledge of ticketing and IT service management platforms (ServiceNow, Jira); ability to configure integrations and interpret ticket data for GRC evidence purposes
- Understanding of common compliance framework control domains: access control, vulnerability management, incident response, change management, BCDR
- Ability to evaluate control evidence including automated and AI-assisted outputs for adequacy and relevance against stated control requirements
- Practical experience using AI tools to accelerate analysis, drafting,
and review tasks; solid judgment in identifying where AI output requires human validation
- Familiarity with API-based integrations and automation concepts (no coding required; ability to configure, test, and troubleshoot integrations)
- Experience with data analysis and reporting tools (Excel, Power BI, Google Slides)
- Basic understanding of cloud environments (AWS) and SaaS security concepts
Professional Skills
- Strong organizational skills with the ability to manage multiple concurrent deadlines across diverse stakeholders
- Clear written and verbal communication skills; ability to translate technical compliance concepts for non-technical audiences
- Detail-oriented with a high bar for data quality and documentation completeness including output from automated and AI-assisted processes
- Collaborative approach to working with control owners; able to influence without authority
- Proactive self-starter who identifies opportunities to improve program efficiency through automation and AI and pursues them with appropriate governance
Key Performance Metrics
- Evidence collection completion rate and timeliness relative to audit schedules
- Integration health: percentage of active Drata connectors operating within defined SLA and delivering current evidence
- AI-assisted process adoption: number of recurring manual GRC tasks transitioned to AI-augmented workflows with documented human-review checkpoints
- Risk register currency: percentage of entries with Last Reviewed date within required window
- GRC platform health: percentage of controls with current, complete evidence
- On-time delivery of scheduled compliance reports and dashboards
- Corrective action closure rate and average days to close
📌 Grc Analyst (Bengaluru)
🏢 Spekond
📍 Bengaluru