5+ Yrs - Bengaluru Only - IT Governance, Risk & Compliance (GRC) Specialist

Posted 10 Days Ago
Be an Early Applicant
Bengaluru North, Yelahanka, Bengaluru Urban, Karnataka, IND
In-Office
Senior level
HR Tech • Information Technology • Consulting
The Role
Manage IT governance, risk, and compliance programs across NIST, ISO, privacy, and security frameworks. Coordinate audits, collect evidence, track remediation, conduct IT risk assessments, and manage third-party vendor risk. Develop and improve security controls, policies, and governance processes while monitoring compliance metrics. Collaborate with IT, Security, Product, and Business stakeholders to embed compliance into operations and support continuous information security and regulatory improvements.
Summary Generated by Built In

Job Overview

We are seeking an experienced IT Governance, Risk & Compliance (GRC) Specialist to drive information security, compliance, audit readiness, and risk management initiatives across the organization.

The ideal candidate will have hands-on experience managing compliance programs aligned to NIST CSF 2.0, ISO 27001:2022, GDPR, DPDP Act, Third-Party Risk Management (TPRM), and related security frameworks. This role will work closely with IT, Security, Product, and Business teams to strengthen governance practices, manage audits, mitigate risks, and support continuous compliance improvements.



Requirements

Key Responsibilities

• Manage IT compliance and security governance programs including NIST CSF 2.0, ISO 27001:2022, GDPR, DPDP Act, and related frameworks.

• Coordinate internal and external audits, including evidence collection, auditor engagement, remediation tracking, and closure of findings.

• Conduct IT risk assessments and support enterprise risk management initiatives.

• Manage Third-Party Risk Management (TPRM) activities including vendor assessments, security questionnaires, risk scoring, and ongoing monitoring.

• Support development, implementation, and continuous improvement of security controls, policies, and governance processes.

• Collaborate with IT, Security, Product, and Business stakeholders to ensure compliance requirements are effectively embedded into operational processes.

• Track compliance metrics, risks, audit observations, and remediation activities.

• Support continuous improvement initiatives related to information security, risk management, and regulatory compliance.

Required Skills & Qualifications

• 5+ years of experience in IT Audit, IT Risk, Information Security, Governance Risk & Compliance (GRC), or related domains.

• Strong understanding of IT General Controls (ITGC), security controls, compliance programs, and data protection requirements.

• Experience managing internal and external audits, control testing, audit evidence collection, and remediation tracking.

• Hands-on experience with Third-Party Risk Management (TPRM), vendor assessments, security reviews, and risk evaluation processes.

• Working knowledge of:

  • NIST CSF 2.0
  • NIST SP 800-53
  • ISO 27001:2022
  • GDPR
  • DPDP Act

• Understanding of cloud environments (AWS preferred), SaaS platforms, and modern technology architectures.

• Excellent stakeholder management, communication, and documentation skills.

• Strong analytical, risk assessment, and problem-solving capabilities.

• B.E. / B.Tech in Computer Science, Information Technology, or related discipline.

Preferred Qualifications

• Prior experience in Security Engineering or Application Security before transitioning into GRC.

• Experience within Banking, Fintech, Insurance, Payments, or other regulated industries.

• Big 4 consulting experience in IT Risk Advisory, Cyber Risk, Audit, or Compliance.

• Professional certifications such as ISO 27001 Lead Implementer/Auditor, CISA, CRISC, CISSP, CISM, or equivalent are highly desirable.



Benefits
  • Opportunity to work on enterprise-wide Information Security, Compliance, and Risk Management initiatives.
  • Hands-on exposure to NIST CSF 2.0, ISO 27001:2022, GDPR, DPDP Act, and Third-Party Risk Management programs.
  • Collaboration with Security, Product, Engineering, and Compliance leadership teams.
  • High-impact role with visibility across audit, governance, and risk functions.
  • Flexible and fast-paced work environment.
  • Potential for contract extension based on performance and business requirements.


  • Skills Required

    • 5+ years of experience in IT Audit, IT Risk, Information Security, Governance Risk and Compliance, or related domains
    • Strong understanding of IT General Controls, security controls, compliance programs, and data protection requirements
    • Experience managing internal and external audits, control testing, evidence collection, and remediation tracking
    • Hands-on experience with Third-Party Risk Management, vendor assessments, security reviews, and risk evaluation
    • Working knowledge of NIST CSF 2.0, NIST SP 800-53, ISO 27001:2022, GDPR, and DPDP Act
    • Understanding of cloud environments, preferably AWS, SaaS platforms, and modern technology architectures
    • Excellent stakeholder management, communication, and documentation skills
    • Strong analytical, risk assessment, and problem-solving capabilities
    • B.E. or B.Tech in Computer Science, Information Technology, or a related discipline
    • Prior Security Engineering or Application Security experience before transitioning into GRC
    • Experience in Banking, Fintech, Insurance, Payments, or another regulated industry
    • Big Four consulting experience in IT Risk Advisory, Cyber Risk, Audit, or Compliance
    • ISO 27001 Lead Implementer or Auditor, CISA, CRISC, CISSP, CISM, or equivalent certification
    Am I A Good Fit?
    beta
    Get Personalized Job Insights.
    Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

    The Company
    6 Employees
    Year Founded: 2022

    What We Do

    NeoRealm Solutions is a Bangalore-based talent and transformation company focused on global recruitment and industry-ready skilling. It connects startups and enterprises with IT and non-IT professionals through agile recruitment solutions, serving energy, trading, fintech, engineering, and technology sectors. Its NeoRealm Academy trains professionals in energy-trading and risk-management platforms, including Openlink Endur, RightAngle, and Allegro, to build specialized talent pipelines.

    Similar Jobs

    Capital One Logo Capital One

    Sr. Director Product Management

    Fintech • Machine Learning • Payments • Software • Financial Services
    Hybrid
    Bengaluru, Bengaluru Urban, Karnataka, IND
    55000 Employees

    Capital One Logo Capital One

    Human Resources Business Partner

    Fintech • Machine Learning • Payments • Software • Financial Services
    Hybrid
    Bengaluru, Bengaluru Urban, Karnataka, IND
    55000 Employees

    Capital One Logo Capital One

    Senior Manager, Benefits (Total Rewards)

    Fintech • Machine Learning • Payments • Software • Financial Services
    Hybrid
    Bengaluru, Bengaluru Urban, Karnataka, IND
    55000 Employees

    Capital One Logo Capital One

    Director - HR Operations and Risk

    Fintech • Machine Learning • Payments • Software • Financial Services
    Hybrid
    Bengaluru, Bengaluru Urban, Karnataka, IND
    55000 Employees

    Similar Companies Hiring

    Compa Thumbnail
    Artificial Intelligence • HR Tech • Software • Business Intelligence
    Irvine, California
    75 Employees
    NODA AI Thumbnail
    Artificial Intelligence • Information Technology • Software • Cybersecurity
    Sydney, AU
    54 Employees
    Golden Pet Brands Thumbnail
    Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
    El Segundo, California
    178 Employees

    Sign up now Access later

    Create Free Account

    Please log in or sign up to report this job.

    Create Free Account