GRC Analyst/Senior Analyst- Hyderabad

7 days ago


Hyderabad India Deloitte Full time

Job Description Summary Position Summary Job Description: Governance, Risk, and Compliance (GRC) Analyst Position Title: IT Security Governance, Risk, and Compliance (GRC) Analyst Department: IT Security Reports To: Senior Manager, IT Security Job Type: Full-Time Role Summary The Governance, Risk, and Compliance (GRC) Analyst is responsible for supporting the organization's information security governance, risk, and compliance activities in alignment with ISO/IEC 27001:2022 and SOC 2 Trust Services Criteria. This role plays a key part in maintaining the Information Security Management System (ISMS), coordinating risk assessments, performing control testing, tracking remediation efforts, and ensuring the organization remains audit-ready at all times. The GRC Analyst collaborates closely with IT, Security Operations, Legal, Privacy, and Business Units to promote a strong risk and compliance culture across the organization. Key Responsibilities - Governance & ISMS Management - Maintain and update information security policies, standards, and procedures to align with ISO 27001 and SOC 2 frameworks. - Administer the Statement of Applicability (SoA) and ensure control implementation status is accurate. - Support the ongoing maintenance and continuous improvement of the organization's ISMS. - Coordinate policy review and attestation campaigns; ensure records of acceptance and compliance are maintained. - Assist with preparing documentation and metrics for ISMS Steering Committee or GRC Governance Board meetings. - Risk Management - Conduct and document information security risk assessments using approved risk methodologies. - Maintain and update the risk register, including risk scoring, treatment plans, and residual risk tracking. - Support third-party/vendor risk assessments by evaluating supplier security posture and compliance. - Track mitigation activities and verify completion of risk treatment actions. - Develop and monitor Key Risk Indicators (KRIs) and generate risk posture reports for management. - Compliance & Audit Support - Support internal and external ISO 27001 certification and SOC 2 Type II audit activities. - Coordinate evidence collection, control testing, and follow-up for internal and third-party audits. - Conduct periodic control self-assessments (CSA) to validate operational effectiveness of key controls. - Manage and track nonconformities, corrective and preventive actions (CAPA), and ensure timely closure. - Maintain awareness of evolving regulations and standards impacting the organization's compliance obligations. - Reporting & Continuous Improvement - Develop and maintain GRC dashboards and reports showing audit readiness, risk trends, and compliance posture. - Prepare materials and metrics for Management Reviews as required under ISO 27001 Clause 9.3. - Identify opportunities for process improvement and automation within GRC workflows. - Capture lessons learned from incidents, risk assessments, and audits to drive continuous improvement. - Tool Administration & Documentation - Support configuration and maintenance of GRC tools (e.g., ServiceNow GRC, Archer, OneTrust, or similar). - Manage document control processes and ensure all ISMS documentation complies with ISO 27001 Clause 7.5. - Ensure proper versioning, access control, and archival of compliance evidence and audit artifacts. Required Qualifications Category Requirements Education Bachelor's degree in Information Security, Computer Science, Risk Management, or related field. Equivalent work experience may be considered. Certifications (Preferred) ISO/IEC 27001:2022 Internal Auditor or Lead Implementer, SOC 2 Practitioner, CRISC or CISA. Experience 25 years of experience in GRC, Information Security, or Audit (preferably supporting ISO 27001 or SOC 2). Framework Knowledge Strong understanding of ISO 27001:2022, SOC 2 Trust Services Criteria, NIST CSF, and risk management principles. Technical Skills Familiarity with GRC platforms (e.g., ServiceNow GRC, Archer, OneTrust), risk assessment tools, and audit workflows. Soft Skills Strong analytical and writing skills, attention to detail, ability to communicate complex topics to non-technical stakeholders, and collaborative mindset. Our purpose Deloitte's purpose is to make an impact that matters for our people, clients, and communities. At Deloitte, purpose is synonymous with how we work every day. It defines who we are. Our purpose comes through in our work with clients that enables impact and value in their organizations, as well as through our own investments, commitments, and actions across areas that help drive positive outcomes for our communities. Our people and culture Our inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ideas and perspectives, and bring more creativity and innovation to help solve our clients most complex challenges. This makes Deloitte one of the most rewarding places to work. Professional development At Deloitte, professionals have the opportunity to work with some of the best and discover what works best for them. Here, we prioritize professional growth, offering diverse learning and networking opportunities to help accelerate careers and enhance leadership skills. Our state-of-the-art DU: The Leadership Center in India, located in Hyderabad, represents a tangible symbol of our commitment to the holistic growth and development of our people. Explore DU: The Leadership Center in India . Benefits To Help You Thrive At Deloitte, we know that great people make a great organization. Our comprehensive rewards program helps us deliver a distinctly Deloitte experience that helps that empowers our professionals to thrive mentally, physically, and financiallyand live their purpose. To support our professionals and their loved ones, we offer a broad range of benefits. Eligibility requirements may be based on role, tenure, type of employment and/ or other criteria. Learn more about what working at Deloitte can mean for you. Recruiting tips From developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters. Requisition code: 318367



  • Hyderabad, Telangana, India Deloitte Full time ₹ 12,00,000 - ₹ 24,00,000 per year

    Job Description: Governance, Risk, and Compliance (GRC) AnalystPosition Title: IT Security Governance, Risk, and Compliance (GRC) AnalystDepartment: IT SecurityReports To: Senior Manager, IT SecurityJob Type: Full-TimeRole SummaryThe Governance, Risk, and Compliance (GRC) Analyst is responsible for supporting the organization's information security...

  • Senior Analyst

    2 weeks ago


    Hyderabad, India Deloitte Full time

    Job Description Summary Position Summary Senior Analyst SERVICENOW GRC/IRM BA - Deloitte Support Services India Private Limited The Service Now COE function is accountable for the implementation of GRC/IRM, ITSM, ITBM and HRSD for multiple MFs from different regions. Work you'll do Role: The role incumbent will be part of the team responsible for end-to-end...

  • GRC Analyst

    10 hours ago


    Chennai, India Arting Digital Full time

    Job Description Position Title: GRC Analyst Experience : 1.5 yr Location : Chennai (Local candidate) Notice period : Immediate joiners Skill set : Certifications ISO27001, Lead Implementer,ISO22301 Lead Auditor,Lead Implementer ,cloud platform ,PCI ,NIST Cyber Security Framework,Cloud Compliance Framework Roles and responsibilities: - Work experience or...

  • IT GRC Junior Analyst

    3 weeks ago


    Hyderabad, India AVEVA Full time

    AVEVA is creating software trusted by over 90% of leading industrial companies. Job Title: IT GRC Junior Analyst Location: Hyderabad, India Employment Type: Full-time / Regular The job The IT GRC Junior Analyst supports AVEVA’s internal control certification activities under PCAOB/SOX. This role operates within the first line of defence and is responsible...

  • Security Analyst, GRC

    3 weeks ago


    Hyderabad, India CDK Global Full time

    BCDR Security Analyst - GRC The BCDR Analyst delivers comprehensive business continuity and disaster recovery services across the organization. The analyst is responsible for operating the current resilience program, identifying opportunities to enhance strategies, and implementing improvements to strengthen organizational preparedness. This role involves...

  • GRC Data Analyst

    3 weeks ago


    Pune, India A.P. Moller - Maersk Full time

    Job Description Maersk is a global leader in integrated logistics and have been industry pioneers for over a century. Through innovation and transformation, we are redefining the boundaries of possibility, continuously setting new standards for efficiency, sustainability, and excellence. At Maersk, we believe in the power of diversity, collaboration, and...

  • Senior Analyst

    2 weeks ago


    Hyderabad, Telangana, India Deloitte Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Job requisition ID :: 92870Date: Nov 19, 2025Location: HyderabadDesignation: Senior AnalystEntity: Deloitte South Asia LLPReact + AI developer

  • Sr.Data Analyst

    7 days ago


    Hyderabad, India SID Information Technologies Full time

    #Hiring #HyderabadJobs #CareerOpportunity #Senior #TechJobs #HealthcareAnalytics #ImmediateJoiner #SQL #Data #Analyst #QualityAssurance #ETLpipeline #ETL #DataAnalytics #DataPipelines #DataQuality #PySpark #AWS We're Looking for : A Senior Data Analyst (Advanced SQL+ Data Quality Assurance) for Healthcare Data Analytics (Hyderabad) Role Details: Sr. Data...

  • Sr.Data Analyst

    7 days ago


    Hyderabad, India SID Information Technologies Full time

    #Hiring #HyderabadJobs #CareerOpportunity #Senior #TechJobs #HealthcareAnalytics #ImmediateJoiner #SQL #Data #Analyst #QualityAssurance #ETLpipeline #ETL #DataAnalytics #DataPipelines #DataQuality #PySpark #AWS We're Looking for : A Senior Data Analyst (Advanced SQL+ Data Quality Assurance) for Healthcare Data Analytics (Hyderabad) Role Details: Sr. Data...

  • Grc Analyst

    1 week ago


    Bengaluru, Hyderabad, India Arroyo Consulting Full time ₹ 5,00,000 - ₹ 15,00,000 per year

    GRC Analyst/Internal Auditor Job DescriptionConduct comprehensive reviews of user access across our suite of SaaS applications to ensure proper security and segregation of duties.Execute test plans for IT General Controls (ITGCs) related to change management, logical access, and IT operations.Utilize your data analysis skills to identify control weaknesses,...