IT GRC Specialist / Sr. Analyst 

Responsibility

Job Position: IT GRC Specialist / Sr. Analyst
Experience: 10 Years
Employment Type: Contractual
Location: Mumbai
Work Model: Onsite – 5 Days Work From Office


Role Summary

The IT GRC Specialist / Sr. Analyst will support the organization’s IT Governance, Risk, and Compliance (GRC) program through hands-on risk assessments, compliance tracking, control testing, and audit coordination. This is primarily an individual contributor role working under the guidance of the IT GRC Lead/Manager.


Key Responsibilities

IT Governance

  • Support maintenance of IT governance frameworks aligned with RBI Master Directions.
  • Compile and publish periodic IT security governance reports covering metrics, KRIs/KPIs, and compliance status.
  • Support process alignment by mapping IT controls to internal standards and business requirements.

IT Risk Management

  • Conduct IT/cyber risk assessments across applications, infrastructure, networks, and end-user computing environments.
  • Support data risk classification and maintain information asset inventories, including classification, ownership, and inherent risk.
  • Review security evidence from a control perspective, including SIEM reports/alerts, firewall rule reviews, and network/security device configuration evidence.
  • Track risk treatment plans and follow up with IT and business owners for closure.
  • Support security awareness activities, including campaign coordination and completion metrics.

Compliance & Regulatory Reporting

  • Track RBI circulars and advisories applicable to IT and cybersecurity and support impact assessment documentation.
  • Prepare compliance checklists and evidence packs for RBI and Head Office reporting.
  • Monitor reporting calendars and submission deadlines, including CSITE and internal mandated submissions.
  • Escalate potential reporting delays and support implementation tracking for mandated controls.
  • Maintain and document compliance status and supporting evidence.

IT Audit Management

  • Support internal and external audit activities, including evidence collection, control walkthroughs, and documentation.
  • Maintain audit trackers covering observation status, remediation progress, and closure evidence.
  • Coordinate with control owners to support closure of audit findings and validate remediation evidence.
  • Contribute to continuous control improvement initiatives identified through audits and risk assessments.

Mandatory Skills & Experience

  • 10 years of experience in IT GRC, IT Risk, Compliance, or IT Audit, preferably within Banking / Financial Services.
  • Working knowledge of RBI IT and cybersecurity expectations and banking audit practices.
  • Strong hands-on experience in:
    • IT risk assessment documentation and risk registers.
    • Control evidence review and compliance tracking.
    • Audit coordination and observation closure documentation.
  • Familiarity with SIEM reporting concepts, VA/PT governance tracking, and baseline security controls.
  • Strong communication and stakeholder coordination skills across IT, InfoSec, Business, and Audit teams.

Preferred Certifications

  • CISA
  • ISO 27001 Internal Auditor
  • ISO 27001 Lead Auditor (LA)

Apply Now

    Contact Us