Skip to content
securityjobs

Jobs /GRC jobs in India /GRC Analyst

Security Brigade· 150+

GRC Analyst

  • Delhi / Mumbai · Hybrid
  • full time
  • ISO 27001
  • SOC 2
  • PCI DSS
  • RBI
  • SEBI
  • IRDAI
  • DPDP
  • GDPR
  • HIPAA
  • gap assessment
  • risk management
  • audit

About the role

Security Brigade is hiring a GRC Analyst to join our compliance and audit practice. You will work directly with enterprise customers across BFSI, fintech, healthcare, SaaS, and government to deliver structured compliance engagements across India and global frameworks: RBI, SEBI, IRDAI, CERT-In, UIDAI AUA-KUA, NPCI / UPI, SAR, ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR, and DPDP. You will run gap assessments, policy and control reviews, evidence collection, remediation planning, and audit-cycle closure, with evidence and tracking held in our Lemon platform. The role pairs you with senior compliance leadership for mentorship and with our offensive security teams for technical control validation.

What you’ll work on

  • Run gap assessments against the framework that applies to the customer (ISO 27001, SOC 2, RBI, SEBI, IRDAI, DPDP, etc.)
  • Map customer policies, processes, and technical controls to framework requirements
  • Lead evidence-collection workflows; coordinate with customer engineering, IT, and operations teams
  • Draft regulator-ready or auditor-ready deliverables: gap reports, control matrices, remediation trackers, and board-summary packs
  • Partner with our offensive security and audit teams to validate technical control effectiveness, not just policy presence
  • Manage engagement timelines and stakeholder communication
  • Drive remediation cycles and closure validation through to final certification or attestation
  • Contribute to internal frameworks, templates, and Lemon platform improvements

What we’re looking for

  • 2–4 years of GRC, compliance, internal audit, or risk-management experience in a services / consulting environment
  • Working knowledge of at least three major frameworks: ISO 27001, SOC 2, PCI DSS, RBI cybersecurity, SEBI CSCRF, IRDAI, HIPAA, GDPR, or DPDP
  • Comfortable running gap assessments, control reviews, and evidence-collection workflows end-to-end
  • Strong written communication: your reports go to CISOs, audit committees, and regulators
  • Comfortable working customer-side: meeting cadence, evidence requests, escalation handling
  • Ability to run multiple parallel engagements without dropping rigour
  • Working knowledge of cybersecurity controls, not just the paperwork: hands-on testing is our offensive team's job, but you should be able to reason about technical controls credibly

Benefits

  • Competitive salary aligned to experience
  • Hybrid + remote-friendly
  • Sponsorship for ISO 27001 Lead Auditor / Lead Implementer, CISA, CISM, or equivalent certifications tied to role progression
  • Direct mentorship from senior compliance leadership
  • Exposure to a wide compliance portfolio across India and global frameworks
  • Internal lab environment + research time

About Security Brigade

A CERT-In empanelled, ISO 27001 certified cybersecurity firm working with over 1,000 clients across BFSI, fintech, e-commerce and manufacturing since 2008. Home of ShadowMap and B-52.

Similar roles

  • Security BrigadeVerified employer

    PHP Developer, Lemon Platform

    2 weeks ago
    • Mumbai · Hybrid
    • Product & Platform Engineering
    • PHP
    • Laravel
    • Symfony
    • jQuery
    • MySQL
    • +3

    1 applicant276 views

  • Security BrigadeVerified employer

    Python Developer, Security Tooling

    2 weeks ago
    • Mumbai · Hybrid
    • Security Engineering & Development
    • Python
    • HTTP
    • TCP/IP
    • Linux
    • MySQL
    • +3

    243 views

  • Security BrigadeVerified employer

    Associate Cybersecurity Consultant

    2 weeks ago
    • Mumbai · Hybrid
    • Application Security
    • application security
    • penetration testing
    • OWASP Top 10
    • burp suite
    • manual testing
    • +3

    1 applicant250 views

  • Security BrigadeVerified employer

    Security Researcher (Web Application)

    2 weeks ago
    • Mumbai · Hybrid
    • Application Security
    • web application penetration testing
    • burp suite
    • OWASP
    • API security
    • manual testing
    • +1

    245 views

Hiring for a security role? Post it free. No account, no card, reviewed by a person, usually within a working day.