GRC Consultant - ISO 27001 | Risk & Compliance (India)

GRC Consultant - ISO 27001 | Risk & Compliance (India)

05 Oct
|
Infosec Train
|
India

05 Oct

Infosec Train

India

GRC Consultant – ISO 27001 | Risk & Compliance | Travel Required | Valid Passport Mandatory

Important Requirements

- Location: Candidates based in Trivandrum/Kochi are preferred. Candidates from other locations must be willing to relocate.
- CTC: Budget is up to ₹4.5 LPA.
- Willingness to travel to client locations when required.
- Valid passport and eligibility for international travel, as some projects may require it.
- Personal laptop required for work-related activities.
- Work Mode: Hybrid / Client Site
- Experience: 2–4 Years

Are you a GRC professional looking to work on real Information Security consulting projects?

If you are based in Trivandrum/Kochi or willing to relocate, and have hands-on experience in ISO 27001, risk assessments, gap assessments and information security compliance, we would like to hear from you.

Core Flow of the Role

Assess → Identify Gaps & Risks → Build/Improve Controls & Documentation → Support Compliance → Work with Clients → Track Remediation

You will work with clients on Information Security and GRC projects, helping them understand their current security posture, identify gaps and risks, improve their controls and documentation, and strengthen their compliance practices.

What You Will Do

1. Information Security & GRC Assessments

- Conduct AS-IS, gap, risk and compliance assessments.
- Identify security gaps, risks, control weaknesses and non-conformities.
- Document findings and support corrective action and remediation.

2. ISO 27001 & Compliance

- Support ISO 27001 implementation, maintenance and compliance activities.
- Work with information security policies, procedures, standards, guidelines and control documentation.
- Support internal/external audit preparation and evidence collection.
- Help clients understand and implement applicable security controls.

3. Risk Management

- Identify and assess information security risks.
- Support risk registers, risk treatment plans and remediation tracking.




- Assist in mapping business requirements with appropriate security controls.

4. Client & Project Coordination

- - Interact with technical and non-technical client stakeholders.
- Understand client requirements and translate them into practical GRC deliverables.
- Participate in client meetings, assessments and review discussions.
- Coordinate with internal teams to close identified gaps.

- 5. Documentation & Reporting

- Prepare assessment reports, policies, procedures, presentations and compliance documentation.
- Track project actions, risks, findings and remediation status.
- Prepare basic compliance reports, KPIs and project updates.

What We Need

Must Have

- 2-4 years of experience in GRC, Information Security, IT Risk, IT Compliance, IT Audit or a related area.
- Hands-on working knowledge of ISO 27001 / ISO 27002.

Experience in at least one of the following:

1. ISO 27001 implementation
2. Security/risk assessment
3. Gap assessment
4. Compliance assessment
5. Information Security audit
6. Security control assessment

- Good understanding of information security controls, policies and risk management.
- Strong documentation and report-writing skills.
- Positive verbal and written communication.
- Comfortable interacting with clients and stakeholders and travelling
- Bachelor's degree in Computer Science, IT, Engineering, Cybersecurity or a related field.

Good to Have

- ISO 27001 Lead Auditor / Lead Implementer certification.
- Exposure to ISO 22301, ISO 31000, NIST, CIS or similar frameworks.
- Knowledge of Business Continuity, Data Privacy or IT Governance.
- CISA, CRISC, CISSP or other relevant certifications.
- Previous experience in consulting or client-facing Information Security projects.

How to Apply

Interested candidates can apply with their updated CV through LinkedIn or share it at:

? [email protected]

? (phone hidden)

Please mention “GRC Consultant – YOUR NAME” while sharing your resume.

GRC Consultant, GRC Analyst, Information Security Consultant, Information Security Analyst, IT Risk Analyst, IT Compliance Analyst, IT Auditor, ISO 27001 Consultant, Cybersecurity GRC Consultant

📌 GRC Consultant - ISO 27001 | Risk & Compliance (India)
🏢 Infosec Train
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: grc consultant - iso 27001 | risk & compliance (india) / india