Cybersecurity GRC Analyst
Summary
A cybersecurity GRC analyst prepares audits, maps controls to policies, and partners with security teams to enforce compliance with frameworks like ISO 27001 and SOC 2 in a Bangalore-based role.
We are seeking a highly skilled, expert-level Cybersecurity GRC Analyst to provide external services until 31 October 2026. In this role, you will assist the end-to-end preparation and execution of upcoming audits, map technical controls to organizational policies, and provide collaborative support to our security architecture team. The ideal candidate possesses a strong background in traditional security frameworks and regulatory mandates, combined with the technical literacy needed to partner effectively with Security Operations, Engineering and Architecture functions to optimize compliance enforcement.
Requirements
Scope of Work
● Compliance & Frameworks: Assist the control and evidence collection management for key compliance frameworks, notably ISO/IEC 27001, SOC 2, NIS2, BSIG, and DORA.
● Audit: Assist the end-to-end preparation and execution of upcoming external security audits (including ISO/IEC 27001, ISO/IEC 27701, SOC 2).
● Architecture Support & Control Mapping: Partner with technical teams to evaluate cloud and system architectures. Translate governance policies into verifiable technical requirements and assess existing system configurations against corporate security baselines.
● AI Regulatory Control Execution: Partner with legal to translate the EU AI Act and global AI mandates into explicit technical requirements. Assess and validate that internal AI deployments, LLM-driven engineering pipelines, and product integrations conform to these technical compliance standards.
● GRC Engineering: Work with GRC Engineers to design and build automated compliance workflows, custom scripts, and data collection mechanisms to enable continuous control monitoring.
● GRC Platform Utilization.
Required Skills & Qualifications
● Experience: 3+ years in delivering cybersecurity GRC consultancy and 2+ in Engineering, Security Operations, Security Architect or related field
● Regulatory & Standard Expertise: Deep knowledge of ISO/IEC 27001 and SOC 2 frameworks. Comprehensive knowledge of current EU cybersecurity regulations (NIS2, CRA, DORA, EU AI Act) and ISO/IEC 42001. Familiarity with Common Criteria certification concepts and assurance requirements, including EAL4+ or comparable certification expectations, is an advantage.
● Audit Experience: Experience managing end-to-end audit lifecycles.
● Architectural Collaboration: Strong technical literacy to partner effectively with Security Architects, Engineering and Security Operations in evaluating cloud environments, identity architectures and software supply chain components to verify policy alignment
● Project Delivery Focus: Proven ability to onboard autonomously and deliver immediate project value within a defined 6-month timeline. Clear communication skills.
● AI Efficiency: Demonstrated ability to effectively leverage and integrate AI tools into daily workflows
● Open Source Knowledge: Familiarity with open-source software is an advantage
● Cybersecurity Certifications are an advantage.
Benefits
- Health insurance coverage for Father, Mother, Self, Spouse, and Kids.
- Long-term benefit savings plan with employer matching contributions.
- Opportunities for professional development and advancement within the organization.