Responsibility
Job Position: IT GRC Specialist / Sr. Analyst
Experience: 10 Years
Employment Type: Contractual
Location: Mumbai
Work Model: Onsite – 5 Days Work From Office
Role Summary
The IT GRC Specialist / Sr. Analyst will support the organization’s IT Governance, Risk, and Compliance (GRC) program through hands-on risk assessments, compliance tracking, control testing, and audit coordination. This is primarily an individual contributor role working under the guidance of the IT GRC Lead/Manager.
Key Responsibilities
IT Governance
- Support maintenance of IT governance frameworks aligned with RBI Master Directions.
- Compile and publish periodic IT security governance reports covering metrics, KRIs/KPIs, and compliance status.
- Support process alignment by mapping IT controls to internal standards and business requirements.
IT Risk Management
- Conduct IT/cyber risk assessments across applications, infrastructure, networks, and end-user computing environments.
- Support data risk classification and maintain information asset inventories, including classification, ownership, and inherent risk.
- Review security evidence from a control perspective, including SIEM reports/alerts, firewall rule reviews, and network/security device configuration evidence.
- Track risk treatment plans and follow up with IT and business owners for closure.
- Support security awareness activities, including campaign coordination and completion metrics.
Compliance & Regulatory Reporting
- Track RBI circulars and advisories applicable to IT and cybersecurity and support impact assessment documentation.
- Prepare compliance checklists and evidence packs for RBI and Head Office reporting.
- Monitor reporting calendars and submission deadlines, including CSITE and internal mandated submissions.
- Escalate potential reporting delays and support implementation tracking for mandated controls.
- Maintain and document compliance status and supporting evidence.
IT Audit Management
- Support internal and external audit activities, including evidence collection, control walkthroughs, and documentation.
- Maintain audit trackers covering observation status, remediation progress, and closure evidence.
- Coordinate with control owners to support closure of audit findings and validate remediation evidence.
- Contribute to continuous control improvement initiatives identified through audits and risk assessments.
Mandatory Skills & Experience
- 10 years of experience in IT GRC, IT Risk, Compliance, or IT Audit, preferably within Banking / Financial Services.
- Working knowledge of RBI IT and cybersecurity expectations and banking audit practices.
- Strong hands-on experience in:
- IT risk assessment documentation and risk registers.
- Control evidence review and compliance tracking.
- Audit coordination and observation closure documentation.
- Familiarity with SIEM reporting concepts, VA/PT governance tracking, and baseline security controls.
- Strong communication and stakeholder coordination skills across IT, InfoSec, Business, and Audit teams.
Preferred Certifications
- CISA
- ISO 27001 Internal Auditor
- ISO 27001 Lead Auditor (LA)