GRC - Security Analyst in India at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a GRC - Security Analyst based in India.
This role supports the organization’s cybersecurity governance, risk, and compliance program, helping identify and manage security risks across technology, vendors, and business processes. You will contribute to the development and maintenance of security policies, controls, and governance practices while supporting audits and compliance assessments. The position provides broad exposure to frameworks such as SOC 2, HIPAA, HITRUST, and PCI DSS, depending on business requirements. You will collaborate closely with Information Security, IT, Legal, Privacy, Internal Audit, and business stakeholders to translate security issues into actionable business risks. The role also involves third-party risk management, evidence collection, remediation tracking, and security reporting. This is an opportunity for a detail-oriented cybersecurity professional to strengthen security maturity while continuously improving GRC processes and automation.
- Perform cybersecurity and technology risk assessments across systems, applications, vendors, and business processes, documenting risks and evaluating their potential business impact.
- Maintain information security policies, standards, procedures, control frameworks, risk registers, and governance documentation.
- Support compliance activities aligned with frameworks and regulations such as SOC 2, HIPAA, HITRUST, PCI DSS, and other applicable requirements.
- Assist with internal and external audits, regulatory examinations, security assessments, and customer compliance reviews by gathering, validating, and maintaining control evidence.
- Track audit findings, security risks, control deficiencies, exceptions, and remediation plans through resolution, working with control owners to assess effectiveness and implement improvements.
- Conduct third-party and vendor security assessments, including reviewing security questionnaires, certifications, audit reports, and supporting documentation.
- Support security awareness, policy acknowledgment, risk acceptance, and security exception processes while responding to customer and partner due diligence requests.
- Monitor changes in regulatory requirements, security standards, and cybersecurity practices and help translate relevant developments into governance improvements.
- Develop GRC metrics, dashboards, reports, and management documentation to communicate security and compliance status effectively.
- Partner with technical security teams to translate vulnerabilities and technical security issues into clear business risks and identify opportunities to automate and improve GRC processes.
- Bachelor’s degree in Cybersecurity, Information Technology, Information Systems, Risk Management, or a related field, or equivalent professional experience.
- 3+ years of experience in cybersecurity, governance, risk management, compliance, IT audit, or a related discipline.
- Relevant certification such as Security+, CISA, CRISC, or CGRC is preferred.
- Working knowledge of cybersecurity frameworks and standards such as HITRUST, SOC 2, PCI DSS, or comparable frameworks.
- Experience performing security risk assessments and evaluating the effectiveness of security controls.
- Familiarity with regulatory and compliance requirements relevant to technology-driven organizations.
- Some experience or exposure to incident response, with a strong interest in cybersecurity and a willingness to continuously learn.
- Strong analytical, organizational, planning, documentation, and problem-solving skills, with the ability to manage multiple assessments, findings, and deadlines.
- Excellent communication skills, with the ability to explain security, compliance, and risk concepts clearly to both technical and non-technical stakeholders.
- Strong attention to detail, ability to meet deadlines, and proficiency with Microsoft Office or comparable productivity and reporting tools.
- Curiosity about emerging technology and cybersecurity trends, with the ability to identify practical opportunities for improving security and IT infrastructure.
- Fully remote work arrangement in India.
- Full-time opportunity within an Information Technology and cybersecurity environment.
- Exposure to enterprise-wide cybersecurity governance, risk, compliance, and audit activities.
- Hands-on experience with recognized security frameworks including SOC 2, HIPAA, HITRUST, and PCI DSS.
- Opportunity to work cross-functionally with Information Security, IT, Legal, Privacy, Internal Audit, and business teams.
- Broad experience in third-party risk management, security assessments, audit readiness, and regulatory compliance.
- Opportunity to contribute to GRC automation, process improvement, reporting, and security maturity initiatives.
- Approximately 10% travel as needed.