Senior GRC Analyst

Posted 8 Days Ago
Be an Early Applicant
Hiring Remotely in India
Remote
2M-3M Annually
Senior level
Edtech • Software
The Role
Own and mature the organization’s governance, risk, and compliance programs. Responsibilities include maintaining security policies and risk registers, conducting risk and vendor assessments, managing control libraries, coordinating audits, testing controls, tracking remediation, supporting privacy and incident response compliance, administering GRC platforms, and responding to customer security questionnaires. The role advises leadership and cross-functional teams while improving security governance and compliance against frameworks including NIST CSF, ISO 27001, SOC 2, and GDPR.
Summary Generated by Built In

Are you looking for an opportunity to help solve one of today's biggest business challenges? AI is changing the pace of business, and organizations everywhere are struggling to help their workforce, partners, and customers keep up. At Litmos, we're building the Learning Acceleration Platform that helps organizations build human capability faster—and we're looking for people who are passionate about making a meaningful impact for customers while growing alongside a collaborative, people-first team.

Litmos is the Learning Acceleration Platform that helps organizations build capability faster, adapt at the speed business changes, and scale learning to anyone, anywhere. Combining an intuitive platform, AI-powered capabilities, trusted content, expert services, and a broad ecosystem of integrations, Litmos helps organizations accelerate workforce productivity, improve customer adoption and retention, enable high-performing partners, and reduce organizational risk through continuous learning.

Organizations such as Hewlett Packard Enterprise, Graco, Sabre, and Russell Mineral Equipment trust Litmos to accelerate learning across their workforce, partners, and customers. Today, more than 11K customers with 30 million learners across 150 countries and 37 languages use Litmos to build the capabilities their organizations need to succeed. Backed by Francisco Partners, one of the world's leading technology investment firms, we're investing in the future of learning—and the people who are building it. Learn more at www.litmos.com.


We are seeking an experienced and strategic Senior GRC Analyst to join our information security team. With 3-5  years of hands-on experience, you will serve as a subject matter expert across governance, risk, and compliance — owning critical programs, driving process maturity, and acting as a trusted advisor to leadership and cross-functional stakeholders. This role goes beyond execution; you will shape the direction of our GRC program and ensure the organization's risk and compliance posture keeps pace with an evolving regulatory and threat landscape. 

Responsibilities 

Governance 

  • Develop, review, and maintain security policies, standards, and procedures, ensuring they remain current and aligned with business needs 
  • Manage the policy exception tracking process, including intake, review, and escalation 
  • Coordinate policy acknowledgment and sign-off across business units 
  • Support and help improve the organization's security awareness training program 
  • Prepare governance metrics and reporting for leadership and board-level stakeholders 

Risk Management 

  • Own and maintain the enterprise risk register, ensuring risks are accurately documented, scored, and tracked 
  • Conduct risk assessments for new projects, systems, and vendors, as well as periodic reviews of existing risks 
  • Facilitate risk scoring and prioritization sessions with business and technical stakeholders 
  • Track risk treatment plans and follow up with owners to ensure timely remediation 
  • Manage the third-party vendor risk assessment program, including questionnaires and ongoing monitoring 
  • Support business impact analysis (BIA) and business continuity planning efforts 

Compliance 

  • Map and maintain control libraries aligned to frameworks such as NIST CSF, ISO 27001, SOC 2, GDPR 
  • Coordinate internal and external audit engagements, including evidence collection and stakeholder communication 
  • Perform control testing and gap assessments, documenting findings and recommending remediation 
  • Track open audit findings through to closure 
  • Monitor regulatory and framework changes, assess organizational impact, and recommend updates 
  • Support data privacy compliance activities related to GDPR, CCPA, or other applicable regulations 

Day-to-Day Operations 

  • Own and administer the GRC platform (e.g., Archer, Vanta, Drata, ServiceNow GRC), driving adoption and continuous improvement  
  • Lead responses to complex customer security questionnaires, RFPs, and due diligence requests  
  • Serve as the compliance lead for incident response activities, ensuring documentation, notification obligations, and regulatory requirements are met  
  • Act as the primary GRC point of contact for IT, Legal, HR, Finance, and business unit teams — driving control ownership and accountability across the organization 

Qualifications 

  • Bachelor's degree in Information Security, Computer Science, Business, or a related field (or equivalent experience) 
  • 3-5 years of experience in GRC, IT audit, information security, or a closely related role 
  • Working knowledge of at least two major compliance frameworks (NIST CSF, ISO 27001, SOC 2, HIPAA, PCI-DSS, etc.) 
  • Experience collecting audit evidence and managing audit engagements 
  • Familiarity with GRC tools and platforms 
  • Strong written communication skills — able to translate technical risk concepts for non-technical audiences 
  • Highly organized with the ability to manage multiple workstreams and deadlines simultaneously 

Nice to Have 

  • Relevant certifications: CompTIA Security+, CISA, ComptTIA CC, CRISC, CGEIT, or CCSP 
  • Experience with cloud environments (AWS, Azure, GCP) and cloud security frameworks 
  • Exposure to data privacy regulations (GDPR, CCPA) 
  • Experience responding to customer security questionnaires 
  • Experience with AI laws and regulations 

Salary Range: ₹24,00,000 to ₹32,00,000 plus 10% bonus

As a learning company we believe in the potential of everyone; if you don't have experience in all the details mentioned in this job post, then we still encourage you to apply and we'll get back to you as soon as we can.  

We are an equal opportunity workplace employer. We are committed to the values of Equal Employment Opportunity and provide accessibility accommodations to applicants with physical and/or mental disabilities.

Applicants will receive consideration for employment without regard to their age, race, religion, national origin, ethnicity, age, gender (including pregnancy, childbirth, et al), sexual orientation, gender identity or expression, protected veteran status, or disability.

Skills Required

  • Bachelor's degree in Information Security, Computer Science, Business, or a related field, or equivalent experience
  • 3-5 years of experience in GRC, IT audit, information security, or a closely related role
  • Working knowledge of at least two major compliance frameworks, such as NIST CSF, ISO 27001, SOC 2, HIPAA, or PCI-DSS
  • Experience collecting audit evidence and managing audit engagements
  • Familiarity with GRC tools and platforms
  • Strong written communication skills and ability to explain technical risk concepts to non-technical audiences
  • Highly organized with the ability to manage multiple workstreams and deadlines simultaneously
  • Relevant certification such as CompTIA Security+, CISA, CompTIA CC, CRISC, CGEIT, or CCSP
  • Experience with cloud environments such as AWS, Azure, or GCP and cloud security frameworks
  • Exposure to data privacy regulations including GDPR or CCPA
  • Experience responding to customer security questionnaires
  • Experience with AI laws and regulations
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
213 Employees
Year Founded: 2007

What We Do

Litmos is an online training platform that makes the management and delivery of web & mobile training courses easy. Our platform is fully extensible with our powerful API and out-of-the-box connectors. Litmos is one of the fastest growing learning technology providers in the world, supporting millions of users, in 130 countries in over 24 languages. We pride ourselves on our customer centric approach and continual innovation in the marketplace. It is our mission to enable training to be deployed in minutes not months by any organization.

Similar Jobs

Dynatrace Logo Dynatrace

Sr Talent Acquisition Advisor

Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Big Data Analytics • Automation
Remote or Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
5600 Employees

Quillbot Logo Quillbot

Manager, Paid Media

Artificial Intelligence • Edtech • Mobile • Natural Language Processing • Productivity • Software
Easy Apply
Remote
India
232 Employees

JPMorganChase Logo JPMorganChase

Data Scientist

Financial Services
Remote or Hybrid
2 Locations
289097 Employees

Atlassian Logo Atlassian

Principal Engineer

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
In-Office or Remote
Bengaluru, Bengaluru Urban, Karnataka, IND
11000 Employees

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account