GRC Consultant
Infosys · IT Services & Consulting
- Bangalore, India
- On-site
- Posted today
- IT & Infrastructure
Responsibilities
Implement and manage Governance, Risk, and Compliance (GRC) programs.
Perform enterprise risk assessments and maintain risk registers.
Define, review, and update security policies, standards, procedures, and controls.
Support regulatory compliance requirements such as ISO 27001, SOC 2, GDPR, HIPAA, PCI-DSS, SOX, NIST, and COBIT.
Conduct control testing, compliance assessments, and gap analyses.
Coordinate internal and external audits and track remediation activities.
Monitor compliance metrics and prepare governance reports and dashboards.
Work with business and technology teams to identify, assess, and mitigate risks.
Ensure third-party/vendor risk assessments are completed and reviewed.
Support cybersecurity governance initiatives and risk treatment plans.
Drive awareness programs related to risk and compliance requirements.
Required Skills
Strong understanding of GRC frameworks and methodologies.
Experience with risk assessment, risk management, and compliance monitoring.
Knowledge of ISO 27001, NIST CSF, COBIT, SOX, PCI-DSS, GDPR, HIPAA, or SOC frameworks.
Experience with GRC tools such as:
ServiceNow GRC
RSA Archer
OneTrust
MetricStream
AuditBoard
Understanding of information security controls and cybersecurity best practices.
Experience in audit management and control testing.
Strong analytical, documentation, and stakeholder management skills.
Preferred Skills
Experience in cloud compliance (Azure, AWS, GCP).
Knowledge of third-party risk management (TPRM).
Familiarity with Cybersecurity, IAM, Data Privacy, and Security Operations.
Experience in enterprise risk governance and reporting.
Technical requirements
Educational requirements
MCA,MSc,MTech,Bachelor of Engineering,BCA,BSc,BTech
Preferred skills
Technology->SAP Functional->SAP GRC
Experience: 3-5 years