Senior GRC Analyst

3 weeks ago


Bengaluru, Karnataka, India Ethos Full time

About Ethos :

Ethos was built to make it faster and easier to get life insurance for the next million families.

Our approach blends industry expertise, technology, and the human touch to find you the right policy to protect your loved ones.

We leverage deep technology and data science to streamline the life insurance process, making it more accessible and convenient.

Using predictive analytics, we are able to transform a traditionally multi-week process into a modern digital experience for our users that can take just minutes Weve issued billions in coverage each month and eliminated the traditional barriers, ushering the industry into the modern age.

Our full-stack technology platform is the backbone of family financial health.

We make getting life insurance easier, faster and better for everyone.

Our investors include General Catalyst, Sequoia Capital, Accel Partners, Google Ventures, SoftBank, and the investment vehicles of Jay-Z, Kevin Durant, Robert Downey Jr and others.

This year, we were named on CB Insights' Global Insurtech 50 list and BuiltIn's Top 100 Midsize Companies in San Francisco.

We are scaling quickly and looking for passionate people to protect the next million families.

About The Role :

The GRC Analyst is responsible for supporting the organization's information security governance, risk, and compliance activities.

This role involves ensuring that the organizations security policies, procedures, and practices are aligned with regulatory requirements, industry standards, and best practices.

The ideal candidate will have a strong understanding of information Security & Privacy principles, Third Party Vendor Risk management, ITGC & SOC2 audit controls, and the ability to communicate complex security issues to various stakeholders.

Duties And Responsibilities :

Governance :.

- Develop, implement, and maintain information security policies and procedures.

- Ensure alignment of security governance frameworks with business objectives and regulatory requirements.

- Assist in the creation and maintenance of the information security governance structure.

Risk Management :.

- Conduct information security risk assessments and evaluate the effectiveness of existing controls.

- Identify, assess, and document risks related to information security & privacy across the organization.

- Conduct regular risk assessments for existing and potential vendors.

- Monitor and report on the organizations information security risk posture.

Compliance :.

- Ensure compliance with relevant information security regulations, standards, and frameworks (e.g, ISO 27001, SOC2, ITGC, NIST, PCI-DSS, CCPA, NYDFS, HIPAA).

- Conduct regular security compliance assessments and audits.

- Track and report on compliance gaps and work with relevant teams to address deficiencies.

- Stay current on emerging security regulations and industry best practices.

- Develop and deliver information security awareness and training programs to staff at all levels.

Reporting and Documentation :

- Maintain comprehensive and accurate documentation related to information security governance, risk, and compliance.

- Prepare and present reports on the organizations information security activities, risk assessments, and compliance status to senior management.

- Ensure all documentation is up-to-date and in compliance with regulatory and organizational requirements.

Qualifications And Skills :

- Bachelors degree in Information Security, Computer Science, Cybersecurity, or a related field.

- 3+ years of experience in information security, risk management and compliance.

- Strong knowledge of information security frameworks, standards, and regulations (e.g, ISO 27001, NIST, CCPA, PCI-DSS, NYDFS, HIPAA).

- Experience with security & privacy risk assessment and management methodologies.

- Extensive experience in Third Party/Vendor Risk Management (TPRM) with hands-on expertise in managing VRM tools (e.g,OneTrust, ProcessUnity, Vanta).

- Experience in supporting security audits (SOC2, Customer & Partners Audits) At least 2 complete audit cycles of SOC2.

- Excellent communication skills, with the ability to convey complex security concepts to non-technical stakeholders.

- Relevant certifications such as ISO 27001 LA LI, CISA, CRISC are highly desirable.

Dont meet every single requirement? If youre excited about this role but your past experience doesnt align perfectly with every qualification in the job description, we encourage you to apply anyway.

At Ethos we are dedicated to building a diverse, inclusive and authentic workplace.

We are an equal opportunity employer who values diversity and inclusion and look for applicants who understand, embrace and thrive in a multicultural world.

We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

Pursuant to the SF Fair Chance Ordinance, we will consider employment for qualified applicants with arrests and conviction records.

To learn more about what information we collect and how it may be used, please refer to our California Candidate Privacy Notice.

(ref:hirist.tech)
  • GRC Analyst

    2 weeks ago


    Bengaluru, Karnataka, India Ushur Full time ₹ 5,00,000 - ₹ 8,00,000 per year

    About UsUshur delivers the world's first Customer Experience Automation platform built specifically for regulated industries. Purpose-built for delivering ideal self-service, Ushur infuses intelligence into digital experiences for the most delightful and impactful customer engagements. Equipped with guardrails and compliance-ready infrastructure, Ushur...


  • Bengaluru, Karnataka, India beBeeRisk Full time ₹ 1,50,00,000 - ₹ 2,50,00,000

    Senior GRC Risk AnalystOur organization is seeking a highly skilled Senior GRC Risk Analyst to join our team. As a key member of our risk management and compliance department, you will play a vital role in the design, implementation, and enhancement of risk management and compliance frameworks that protect our digital assets.This challenging role emphasizes...

  • Lead - GRC

    2 days ago


    Bengaluru, Karnataka, India greytHR Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Position Summary:GRC Lead will be responsible for overseeing and managing the QA team to ensure the highest standards of quality are met across all products and services. This role involves developing and implementing QA strategies, leading team projects, and collaborating with other departments to drive continuous improvement in quality processes....


  • Bengaluru, Karnataka, India Greenlight Financial Technology Full time US$ 90,000 - US$ 1,20,000 per year

    Greenlight is the leading family fintech company on a mission to help parents raise financially smart kids. We proudly serve more than 6 million parents and kids with our award-winning banking app for families. With Greenlight, parents can automate allowance, manage chores, set flexible spend controls, and invest for their family's future. Kids and teens...


  • Bengaluru, Karnataka, India beBeeCompliance Full time ₹ 90,00,000 - ₹ 1,20,00,000

    Job DescriptionWe are seeking a skilled professional to oversee and manage our QA team.Operate within a GRC environment of a large organization.Plan and conduct professional audits in accordance with established procedures.Prepare annual internal audit plans and conduct internal audits.Act as custodian of documents, ensuring the upkeep of all GRC...


  • Bengaluru, Karnataka, India MHP – A Porsche Company Full time

    We are looking for talented professionals to join our Governance, Risk, and Compliance (GRC) team, spanning leadership, consulting, and analyst roles. This is an exciting opportunity to work with ServiceNow GRC modules and contribute to strategic, operational, and technical GRC initiatives across our organization.Roles & ResponsibilitiesDepending on your...

  • GRC Analyst

    2 weeks ago


    Bengaluru, Karnataka, India Spire Systems Inc Full time

    Job Summary : We are seeking a detail-oriented and knowledgeable GRC Analyst to join our security and compliance team. The ideal candidate will be responsible for conducting vendor risk assessments, supporting internal governance, risk, and compliance initiatives, and ensuring adherence to industry frameworks and standards. This role requires deep technical...

  • GRC Consultant

    2 weeks ago


    Bengaluru, Karnataka, India Beinex Full time

    Aurex Inc, is looking for a GRC consultant role. As an integral member of the GRC Implementation team, the responsibility of the GRC Consultant is to carry out the implementation of GRC system for our customers related to policy compliance, security requirements governance, as well as risk management. The ideal candidate will have knowledge of risk...

  • Senior GRC Developer

    2 weeks ago


    Bengaluru, Karnataka, India beBeeGrcdeveloper Full time ₹ 15,00,000 - ₹ 20,00,000

    Job Title: ServiceNow GRC DeveloperAre you an experienced IT professional looking to advance your career in Governance, Risk and Compliance? Do you have a passion for delivering innovative solutions using the ServiceNow platform?We are seeking a skilled ServiceNow GRC Developer to join our team. As a key member of our organization, you will be responsible...

  • GRC Senior Consultant

    3 weeks ago


    Bengaluru, Karnataka, India Cubical Operations LLP Full time

    Job Title: GRC Consultant / Senior ConsultantLocation: BangaloreExperience: 2+ YearsShift Timing: General Indian Business HoursEmployment Type: Full-time, PermanentJob SummaryWe are looking for skilled professionals at the Consultant and Senior Consultant levels to join our Third Party Risk Management (TPRM) team. The role focuses on performing risk...