09 Oct
|
Replicon
|
India
Priorities :
(1) Audit readiness and evidence delivery,
(2) Control documentation, continuous monitoring, and
(3) Risk/PoA&M; reporting, assigned deliverables end-to-end and coordinating inputs from Engineering, Product, and IT.
Core Role Requirements
- As a senior analyst: lead cloud SaaS applications through various audit frameworks and assessments such as SOC 1, SOC 2, NIST 800-53, NIST 800-171, CMMC, ISO, FedRAMP, PCI DSS, CIS, CSA CSM, or other information security regulations.
- Lead and/or support end-to-end audit engagements (internal and external), including scoping, evidence requests, control testing, issue tracking, and final report support.
- Assess and communicate administrative, technical, and security controls across major cloud platforms, including Oracle Cloud Infrastructure (OCI), Amazon Web Services (AWS), and Microsoft Azure.
- Demonstrate the ability to apply project management practices to plan, track, and deliver security assessments, including hands-on use of Jira for epics/stories, backlog grooming, and stakeholder reporting.
- Use automation and AI responsibly to streamline evidence collection, control mapping, and recurring reporting while maintaining appropriate human review.
Reporting & continuous improvement
- Define, build, and maintain recurring GRC metrics and dashboards (monthly/quarterly), and present trends, risks, and remediation status to senior leadership.
- Draft, maintain,
and socialize security policies/standards and System Security Plans (SSPs), including control narratives, implementation details, and evidence references.
- Communicate clearly with engineering, product, and auditors, and produce high-quality audit deliverables (e.g., narratives, evidence packages, and status reporting).
- Manage risk register items and PoA&Ms; end-to-end-identify control gaps, partner with stakeholders on remediation plans, and track progress through continuous monitoring. Program ownership & documentation
- Own (or serve as backup owner for) key GRC programs by maintaining procedures, SLAs, and artifacts for audits and customer requests (e.g., policy management and security due diligence questionnaires to support RFIs and RFPs).
- Actively participate in initiatives aimed at enhancing team processes and procedures.
- Help maintain and curate annual compliance training content and improve training process.
- Interpret control requirements and regulatory obligations accurately, and translate them into explicit, testable expectations for technical teams.
- Participate in incident response reviews and RCAs by documenting control failures, corrective actions, and follow-up evidence for closure. ","
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Principal GRC Analyst (India)
🏢 Replicon
📍 India