GRC & InfoSec Executive

Xpentra
Posted on

Experience
1 - 4 yrs
Salary (CTC)
₹4L - ₹6.5L
Job Location
India
Vacancy
2
Designation
GRC Consultant
Job Type
Not specified

Job Description

Job Title: GRC & InfoSec Executive

Location: Mumbai
Job Type: Full-time
Schedule: Monday to Friday
Overview:
We are looking for a highly detailed-oriented and technically aware IT GRC and Information Security Executive to support Q2Pay Technologies governance, risk, compliance and information security initiatives.

This role is ideal for an ambitious professional with foundational experience in IT infrastructure, InfoSec controls and IT documentation who wants to play a key role in safeguarding our technology landscape. You will bridge the gap between technical execution and regulatory compliance, ensuring our processes remain secure, robust and audit-ready.
Key Responsibilities:
Documentation & Policy Management:

Draft, implement and maintain critical IT artifacts, including IT Operations policies, Information Security Policies, Standard Operating Procedures (SOPs), process documents and control descriptions.
Audit Readiness & Gap Analysis: Support internal and external audits by proactively preparing evidence collections, tracking remediation progress and closing audit findings. Identify vulnerabilities or missing links in current IT controls and documentation suggesting concrete measures to fix them.
Risk Assessment: Assist in IT Infrastructure risk identification, assessment and systematic tracking to mitigate potential vulnerabilities before they affect operations.
InfoSec Implementation Support: Partner with core technical teams to implement and verify basic information security controls, including access management, backup verifications and endpoint security controls.
Cross-Functional Coordination: Act as a central point of contact, working closely with IT Infrastructure, Developers, Application teams and external auditors to track open compliance tasks and ensure timely closure.


Required Skills:
Core Technical Knowledge: A strong foundational understanding of IT Infrastructure (Operating Systems, Databases, Networks, Applications and Hardware) alongside core Information Security principles.
Compliance Frameworks: Deep familiarity with industry-standard security frameworks such as ISO 27001, SOC 2, NIST and local regulations like DPDP.
Documentation Excellence: Exceptional technical and process documentation skills with a sharp eye for detail. You excel at spotting "what is missing" in a process or workflow.
Communication & Drive: Strong written and verbal communication skills, paired with a proactive mindset to take ownership of compliance trackers.

Preferred Qualifications
Educational Background: Bachelor's or Master's Degree in IT, Computer Science, Cyber Security or a closely related field.
Cloud Familiarity: Hands-on experience or familiarity with cloud computing platforms, particularly AWS, is a distinct advantage.
Certifications: Industry certifications such as ISO 27001 Lead Implementer/Auditor, CompTIA Security+ or CISA are highly preferred but not mandatory.


Why Join Us?
Fast-Track to Engineering Management: This role is designed with a clear career growth trajectory, offering a structured path to transition into an IT GRC Manager or Information Security Manager.
High Visibility & Impact: You will work directly with cross-functional engineering and infrastructure teams giving you a holistic view of the company's tech ecosystem and a direct hand in securing it.

Continuous Learning: Dive deep into cutting-edge cloud security environments and complex regulatory compliance frameworks within a fast-growing technology space.

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.