Manager II - Information Security, GRC, SOC, Compliance

UST
Posted on
UST logo

Experience
5 - 8 yrs
Job Location
Kochi, India
Vacancy
1
Designation
Information Security Manager
Job Type
Not specified

Job Description

Job Description GRC (Governance, Risk Compliance) Analyst / Senior Analyst Experience

  • 3 5 years or 5 8 years of relevant experience in Governance, Risk Compliance (GRC), IT Risk, or IT Compliance.

Role Summary

We are seeking a GRC professional with strong expertise in IT governance, risk management, compliance frameworks, and control assessment. The ideal candidate will work closely with business and technology teams to strengthen the organizations compliance posture, manage risks, and support audit readiness through effective policy, control, and governance practices.

Must-Have Skills

  • 3 8 years of experience in IT Governance, Risk Compliance (GRC), IT Risk, or IT Compliance.
  • Strong understanding of industry compliance frameworks and regulatory standards such as NIST, ISO 27001, SOC 2, GovRAMP , and other relevant security/compliance frameworks.
  • Experience performing risk assessments , including issue and exception management, evaluating compensating controls, and determining residual risk.
  • Hands-on experience with IT control testing , including identifying appropriate audit evidence, validating control effectiveness, and supporting internal/external audits.
  • Experience developing and maintaining security policies, standards, procedures, and controls that are measurable, actionable, and aligned with business and regulatory requirements.
  • Strong knowledge of IT governance, risk management methodologies, and compliance best practices.
  • Excellent written and verbal communication skills, with the ability to communicate effectively with both business stakeholders and technical teams.
  • Strong analytical, documentation, and stakeholder management skills.

Good-to-Have Skills

  • Experience supporting SOC 2, ISO 27001, GovRAMP, or similar certification and audit programs.
  • Exposure to GRC platforms such as Archer, ServiceNow GRC, OneTrust, AuditBoard, or similar tools.
  • Knowledge of cloud security and compliance (AWS, Azure, or GCP).
  • Experience working with cross-functional teams in a fast-paced enterprise environment.
  • Relevant certifications such as CISA, CRISC, CISSP, ISO 27001 Lead Implementer/Lead Auditor , or equivalent are preferred.

Key Responsibilities

  • Conduct IT risk assessments and compliance reviews across business and technology environments.
  • Manage compliance issues and exceptions by assessing risks, reviewing compensating controls, and documenting residual risk.
  • Perform and coordinate IT control testing, ensuring evidence collected is sufficient and audit-ready.
  • Develop, review, and maintain security policies, standards, procedures, and control documentation.
  • Support internal and external audits by providing accurate documentation and responding to audit requests.
  • Partner with business and technology stakeholders to ensure compliance with organizational policies and regulatory requirements.
  • Track remediation activities and monitor compliance with established controls and governance processes.
  • Drive continuous improvement in governance, risk, and compliance practices across the organization.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.