Governance, Risk and Compliance (GRC) Specialist
Location: Pune
Department: Information Technology – Information Security
CTC: Up to ₹25 LPA
Experience: 5+ Years
Reporting To: Chief Information Security Officer (CISO)
Travel: Up to 10%
Position Summary
We are looking for an experienced GRC Specialist to manage and improve the organization's information security, risk, and compliance programs.
The person will be responsible for ISO 27001, ISO 42001, and SOC 2 compliance , audit preparation, risk assessments, security policies, vendor assessments, and client security questionnaires.
The role will also support cybersecurity and AI governance projects and work closely with auditors, clients, vendors, and internal teams.
Key Responsibilities
- Manage ISO 27001, ISO 42001, and SOC 2 audit and certification activities.
- Prepare audit evidence, coordinate control testing, and work with external auditors.
- Create and maintain information security policies, procedures, standards, and controls .
- Maintain the organization's risk register and track risk mitigation activities.
- Conduct vendor and third-party security risk assessments .
- Review vendor security documents such as SOC 2 reports and penetration testing reports .
- Complete client security questionnaires and due diligence assessments .
- Manage and track compliance activities using GRC/compliance platforms .
- Monitor applicable security and regulatory requirements such as NIST CSF, NIST RMF, and GLBA .
- Support security audits, evidence collection, gap assessments, and closure of audit findings.
- Manage security awareness training, phishing simulations, and policy attestations .
- Support cybersecurity and AI governance advisory projects , including gap analysis and documentation.
- Coordinate compliance activities across different offices and business entities.
- Work with clients, auditors, vendors, and internal teams to resolve security and compliance requirements.
Required Experience
- 5+ years of experience in Information Security, GRC, IT Audit, Risk, or Compliance.
- Minimum 2 years of experience managing ISO 27001 or SOC 2 audits/certifications .
- Minimum 2 years of experience in vendor/third-party risk assessments .
- Minimum 2 years of experience creating information security policies and procedures .
- Good understanding of ISO 27001, SOC 2, NIST CSF, NIST RMF, and GLBA .
- Experience working with GRC or compliance management tools .
- Experience communicating with clients, auditors, and vendors .
- Experience in financial services, banking, mortgage, or other regulated industries is preferred.
Preferred Experience
- Experience with ISO 42001 / AI Governance .
- Experience with AI risk and compliance frameworks .
- Experience administering GRC/compliance automation platforms.
Education
- Bachelor's degree in Information Security, Computer Science, IT, or a related field .
- Master's degree is preferred.
Certifications
Any of the following certifications would be preferred:
- CISSP
- CISA
- CRISC
- ISO 27001 Lead Auditor
- ISO 27001 Lead Implementer
- ISO 42001 Lead Auditor / Lead Implementer
Key Skills
- Strong knowledge of Information Security and GRC .
- Good understanding of security frameworks and compliance requirements.
- Ability to convert security requirements into practical controls and documentation .
- Strong documentation and policy-writing skills.
- Good analytical and risk-assessment skills.
- Strong communication and presentation skills.
- Ability to manage multiple audits, assessments, and deadlines.
- Ability to work independently and proactively.
- Good stakeholder management skills.
- Risk-based approach to information security and compliance.
Ideal Candidate
The ideal candidate should have strong hands-on experience in GRC, audits, risk assessments, compliance, and information security documentation . The candidate should be comfortable working with CISOs, auditors, clients, vendors, and technical teams and should be able to manage multiple compliance activities independently.
Keywords: GRC, Information Security, ISO 27001, ISO 42001, SOC 2, NIST, Risk Assessment, Vendor Risk, IT Audit, Security Compliance, Security Policies, CISA, CISSP, CRISC.