…

GRC Consultant

Infosys · IT Services & Consulting

  • Bangalore, India
  • On-site
  • Posted today
  • IT & Infrastructure

Responsibilities

Implement and manage Governance, Risk, and Compliance (GRC) programs.

Perform enterprise risk assessments and maintain risk registers.

Define, review, and update security policies, standards, procedures, and controls.

Support regulatory compliance requirements such as ISO 27001, SOC 2, GDPR, HIPAA, PCI-DSS, SOX, NIST, and COBIT.

Conduct control testing, compliance assessments, and gap analyses.

Coordinate internal and external audits and track remediation activities.

Monitor compliance metrics and prepare governance reports and dashboards.

Work with business and technology teams to identify, assess, and mitigate risks.

Ensure third-party/vendor risk assessments are completed and reviewed.

Support cybersecurity governance initiatives and risk treatment plans.

Drive awareness programs related to risk and compliance requirements.

Required Skills

Strong understanding of GRC frameworks and methodologies.

Experience with risk assessment, risk management, and compliance monitoring.

Knowledge of ISO 27001, NIST CSF, COBIT, SOX, PCI-DSS, GDPR, HIPAA, or SOC frameworks.

Experience with GRC tools such as:

ServiceNow GRC

RSA Archer

OneTrust

MetricStream

AuditBoard

Understanding of information security controls and cybersecurity best practices.

Experience in audit management and control testing.

Strong analytical, documentation, and stakeholder management skills.

Preferred Skills

Experience in cloud compliance (Azure, AWS, GCP).

Knowledge of third-party risk management (TPRM).

Familiarity with Cybersecurity, IAM, Data Privacy, and Security Operations.

Experience in enterprise risk governance and reporting.

Technical requirements

Primary skills:Technology->SAP Functional->SAP GRC

Educational requirements

MCA,MSc,MTech,Bachelor of Engineering,BCA,BSc,BTech

Preferred skills

Technology->SAP Functional->SAP GRC

Experience: 3-5 years