GRC Analyst
Cubical Operations LLP
Job Description
Job Description – GRC Analyst (Governance, Risk & Compliance) Location: Mumbai Experience: 1–2 Years Department: Risk Advisory / Information Security / Compliance Employment Type: Full-Time About the Role We are looking for a proactive and detail-oriented GRC Analyst with 1–2 years of experience in Governance, Risk & Compliance and ISO audit processes. The candidate will support compliance initiatives, risk assessments, policy management, and internal/external audit activities to strengthen the organization’s information security and compliance framework. Key Responsibilities Support implementation and maintenance of Governance, Risk & Compliance (GRC) frameworks.
Assist in conducting ISO audits, including ISO 27001 compliance assessments and documentation reviews. Perform risk assessments and identify compliance gaps across processes and systems. Assist in preparation, review, and maintenance of policies, SOPs, and compliance documents.
Coordinate with internal teams for audit evidence collection and closure of audit observations. Monitor compliance with information security standards, regulatory requirements, and internal controls. Track remediation plans and follow up on corrective and preventive actions (CAPA).
Support vendor risk assessments and third-party compliance reviews where applicable. Prepare audit reports, compliance dashboards, and management updates. Stay updated on emerging regulatory requirements and industry best practices.
Required Skills & Competencies Basic understanding of Governance, Risk & Compliance (GRC) concepts. Knowledge of ISO 27001 standards, controls, and audit methodologies. Familiarity with risk assessment and compliance management processes.
Good documentation, analytical, and reporting skills. Strong communication and coordination abilities. Proficiency in MS Excel, Word, and PowerPoint.
Ability to work independently and manage multiple tasks effectively. Eligibility Criteria Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Commerce, or related field. 1–2 years of relevant experience in GRC, compliance, or ISO audit roles. Experience in handling ISO audit documentation and compliance activities is mandatory.
Preferred Certifications ISO 27001 Internal Auditor / Lead Auditor certification preferred. Knowledge of SOC 2, GDPR, HIPAA, or other compliance frameworks would be an added advantage. Preferred Profile Experience in consulting firms, IT services, fintech, or corporate compliance environments preferred.
Exposure to information security governance and regulatory audits is desirable.