Role Overview: We are hiring an Information Security GRC professional to manage policies, audits, risk assessments, vendor security reviews, and security awareness initiatives. The role focuses on ensuring regulatory compliance and strengthening the organizations overall security posture.
Key Responsibilities:
- Develop, review, and maintain IT & Information Security policies and procedures
- Facilitate internal, external, and regulatory audits; manage evidence and closure of findings
- Conduct information security risk assessments and maintain risk registers
- Perform third-party/vendor security assessments and drive remediation
- Deliver security awareness and induction training programs
- Prepare governance dashboards, MIS, and monthly security review reports
- Review vendor contracts/MSAs for information security compliance
Eligibility Criteria:
- Bachelors degree in IT / Computer Science or related field
- 5 - 7 years of experience in Information Security GRC
- Strong knowledge of ISO 27001, GDPR, RBI and similar frameworks
- Experience with audits, risk management, and vendor assessments
- Certifications preferred: CISA, CISM, ISO 27001 LA/LI, CRISC
- Strong communication, presentation, and stakeholder management skills
#Hiring #InformationSecurity #CyberSecurityJobs #GRC #InfosecJobs
#RiskManagement #ITGovernance #ISO27001 #Compliance #GurgaonJobs