We are Hiring for Governance, Risk & Compliance (GRC) Specialist
Location: Pune
Department: Information Technology – Information Security
Experience: 5+ Years
CTC: Up to ₹25 LPA
Reporting To: Chief Information Security Officer (CISO)
Travel: Up to 10%
Shift: US Shift
About the Role
We are looking for an experienced GRC Specialist to manage and strengthen the organization's information security, risk, and compliance activities.
The person will be responsible for managing ISO 27001, ISO 42001, and SOC 2 compliance, supporting audits, conducting risk assessments, managing vendor security assessments, maintaining security policies, and responding to client security questionnaires.
The role will also support cybersecurity and AI governance initiatives and involve regular interaction with auditors, clients, vendors, and internal teams.
Key Responsibilities
Manage ISO 27001, ISO 42001, and SOC 2 compliance and audit activities.
Prepare audit documentation and evidence and coordinate with external auditors.
Develop and maintain information security policies, procedures, standards, and controls.
Maintain the organization's risk register and track risk mitigation activities.
Conduct vendor and third-party security risk assessments.
Review vendor security documents, including SOC 2 reports and penetration testing reports.
Complete client security questionnaires and security due diligence assessments.
Manage compliance activities using GRC and compliance management tools.
Monitor security frameworks and regulatory requirements such as NIST CSF, NIST RMF, and GLBA.
Support security audits, gap assessments, evidence collection, and closure of audit findings.
Manage security awareness training, phishing simulations, and policy attestations.
Support cybersecurity and AI governance projects, including gap assessments and documentation.
Coordinate compliance activities across different offices and business units.
Work with clients, auditors, vendors, CISO, and internal teams to address security and compliance requirements.
Required Experience
5+ years of experience in Information Security, GRC, IT Audit, Risk, or Compliance.
At least 2 years of experience managing ISO 27001 or SOC 2 audits/certifications.
At least 2 years of experience in vendor/third-party risk assessments.
At least 2 years of experience developing information security policies and procedures.
Good knowledge of ISO 27001, SOC 2, NIST CSF, NIST RMF, and GLBA.
Experience using GRC or compliance management platforms.
Experience working with clients, auditors, vendors, and internal stakeholders.
Experience in financial services, banking, mortgage, or other regulated industries is preferred.
Preferred Experience
Hands-on experience with ISO 42001 and AI Governance.
Understanding of AI risk management and compliance frameworks.
Experience administering GRC/compliance automation platforms.
Experience supporting cybersecurity or AI governance advisory projects.
Education
Bachelor's degree in information security, Computer Science, IT, or a related field.
Master's degree is preferred.
Preferred Certifications
Candidates with any of the following certifications will be preferred:
CISSP
CISA
CRISC
ISO 27001 Lead Auditor
ISO 27001 Lead Implementer
001 Lead Auditor / Lead Implementer
Key Skills
Strong knowledge of Information Security and GRC.
Good understanding of security frameworks and compliance requirements.
Ability to convert security requirements into practical controls and documentation.
Strong policy writing and documentation skills.
Good risk assessment and analytical skills.
Strong communication and presentation skills.
Good stakeholder management skills.
Ability to manage multiple audits, assessments, and deadlines.
Ability to work independently and take ownership of tasks.
Strong understanding of a risk-based approach to information security and compliance.
Interested candidates Contact
HR Madhuri Reddy R
📞 9136535233
📧 madhuri@careerguideline.com and also refer to the people who are seeking for job