
GRC Analyst
24 hours ago
Job Description: GRC Analyst
Location: New Delhi, India
Company: ThrivePass
Experience - 5+ years
About ThrivePass
At ThrivePass, we empower organizations to offer benefits that truly matter. Our platform supports employee wellbeing, compliance, and growth through innovative technology, data-driven insights, and exceptional user experiences. Our culture is rooted in our CARE values:
- Courageous – We embrace new challenges and bold ideas.
- Authentic – We value transparency and show up as our true selves.
- Resourceful – We find creative solutions and make things happen.
- Excellent – We take pride in our work and hold ourselves accountable.
About the Role
We are seeking a Senior Compliance Analyst to lead and maintain our adherence to global regulatory and industry standards, such as SOC 2 Type II ,ISO27001, GDPR, HIPAA, and CCPA . This role is crucial for supporting our audit-readiness, improving policy frameworks, and driving a company-wide culture of compliance. You'll work cross-functionally with internal teams and external auditors to ensure our systems and practices align with the latest compliance requirements.
Key Responsibilities
Regulatory Compliance & Audit Readiness
- Stay current with relevant regulations, including SOC 2, GDPR, HIPAA, and CCPA.
- Conduct regular gap assessments , develop remediation plans , and ensure ongoing compliance.
- Prepare documentation and coordinate with third-party auditors and assessors .
- Creating, reviewing, and updating internal policies, standards, and procedures to align with regulatory requirements and best practices.
- Manage compliance automation tools such as Vanta AI and complete vendor risk questionnaires.
- Evaluating the security posture and compliance of vendors and other third parties to minimize supply chain risks.
Business Continuity & Risk Management
- Lead and document Business Continuity and Disaster Recovery (BCDR) testing.
- Support internal risk assessments and vendor management programs.
- Work with stakeholders to address gaps and exposures caused due to risks.
- Conducting risk assessments to identify, analyze, and evaluate potential threats to the organization's assets, operations, and reputation. This includes developing and implementing risk mitigation strategies and maintaining a risk register.
Training & Enablement
- Promote a culture of compliance across the organization.
- Facilitate internal security awareness and compliance training programs.
- Act as a resource to teams on compliance-related matters without stalling innovation.
Program Oversight & Metrics
- Define and track KPIs to measure compliance program effectiveness.
- Drive continuous improvements and ensure compliance is embedded in business processes.
- Support legal, IT, and product teams in evaluating data protection requirements.
- Preparing and presenting reports to management and stakeholders on the organization's risk and compliance posture.
Requirements
Must-Have:
- Proven experience in a compliance, risk, or audit function.
- Strong knowledge of SOC 2, GDPR, HIPAA, CCPA , and vendor management.
- Familiarity with compliance tools like Vanta.
- Excellent communication and documentation skills.
- Experience working with cross-functional teams .
- Skilled in drafting and managing policies and procedures .
Nice-to-Have:
- Experience with security awareness platforms (e.g., KnowBe4).
- Familiarity with ITSM systems like Freshservice.
- Knowledge of AI/automation in compliance workflows .
- Relevant certifications: CISA, CRISC, or equivalent .
Why Join ThrivePass?
- Work in a fast-paced, mission-driven company with a meaningful product.
- Learn and grow through exposure to emerging tools and technologies.
- Be part of an inclusive, value-driven culture that prioritizes trust and impact.
-
GRC Analyst
1 week ago
Delhi, Delhi, India Hitachi Vantara Corporation Full time ₹ 9,00,000 - ₹ 12,00,000 per yearOur CompanyWe're Hitachi Digital, a company at the forefront of digital transformation and the fastest growing division of Hitachi Group. We're crucial to the company's strategy and ambition to become a premier global player in the massive and fast-moving digital transformation market. Our group companies, including GlobalLogic, Hitachi Digital Services,...
-
Lead ServiceNow GRC Developer
3 weeks ago
Delhi, Delhi, India QBrainX Full timeJob Title : ServiceNow GRC Lead DeveloperExperience Level : 7+ YearsLocation: Remote (India)Job Type : Full-TimeDepartment : IT / Governance, Risk & Compliance (GRC)Position Summary:We are looking for a ServiceNow GRC Lead Developer to join our growing remote team. The ideal candidate will have 7+ years of experience, with a strong focus on ServiceNow...
-
Lead ServiceNow SecOps Engineer
4 weeks ago
Delhi, Delhi, India PMD NowSolutions Full timeResponsibilities :- Design, implement, and maintain ServiceNow Security Operations (SecOps) solutions, focusing on Vulnerability Response, Security Incident Response, and Threat Intelligence.- Develop and implement integrations with other security tools and systems.- Create and optimize workflows and automation within the ServiceNow SecOps platform.- Provide...
-
Information Security Analyst
3 weeks ago
Delhi, Delhi, India Talent Integrators Full timeThis role is pivotal in developing, implementing, and monitoring security policies, ensuring compliance, and managing risk across the firm. The ideal candidate will have expertise in Governance, Risk, and Compliance (GRC) and will play a key role in tracking vulnerabilities, managing security alerts, and overseeing learning modules.Responsibilities and...
-
Aujas Cybersecurity
3 weeks ago
Delhi, Delhi, India AUJAS CYBERSECURITY LIMITED Full timeRole : VMS Track Lead - CybersecurityLocation : DelhiExperience : 7+ years in Cybersecurity, with 3 - 4 years in Vulnerability Management (VMS) and Penetration Testing (PT)Qualification : BE/B.Tech/M.Tech/MSc/MCA or equivalent in Computer Science, Information Security, or related fieldPreferred Certifications : CISP/CISSP, CCIE Security, CEH, GCFA,...
-
NopalCyber - Presales Architect
3 weeks ago
Delhi, Delhi, India NOPAL SUPPORT SERVICES PRIVATE LIMITED Full timeJob Statement : NopalCyber makes cybersecurity manageable, affordable, reliable, and powerful for companies that need to be resilient and compliant. Managed extended detection and response (MXDR), attack surface management (ASM), breach and attack simulation (BAS), and advisory services fortify your cybersecurity across both offense and defense. AI-driven...