Sr GRC Consultant

2 days ago


Mumbai, Maharashtra, India TechDefence Labs Full time US$ 90,000 - US$ 1,20,000 per year

Job Role: Sr GRC/GRC Analyst

Roles and Responsibilities:

This individual's primary day to day responsibilities is mentioned below (but are not limited to these):

  • Plan and conduct end-to-end cybersecurity risk assessments for ICT assets (networks, servers, applications, endpoints, cloud), including threat/vulnerability identification, likelihood/impact analysis, risk scoring, and treatment plans.
  • Lead third-party/vendor risk assessments: due diligence, security questionnaires, evidence reviews, control gap analysis, and ongoing monitoring aligned to ISO 27001 Annex A, SOC 2 trust services criteria, NIST controls, and GDPR requirements.
  • Map assessment findings to GRC frameworks and regulatory requirements; produce compliance-ready reports, risk registers, and executive summaries.
  • Collaborate with IT and engineering on security architecture reviews for networks, servers, and cloud; recommend hardening, segmentation, and secure configuration baselines.
  • Support policy, standard, and procedure development for risk management, vulnerability management, incident response, access control, and asset management.
  • Prepare materials for internal/external audits (ISO 27001, SOC 2) and respond to client security assessments and RFPs.
  • Evaluate and secure cloud environments (AWS, Azure, GCP) by conducting cloud-specific risk assessments, reviewing identity and access management, ensuring workload segmentation, and checking adherence to cloud security posture management best practices.
  • Assess compliance of cloud service providers with frameworks such as ISO 27017/27018, CIS Cloud Benchmarks, and guide the deployment of secure and resilient cloud architectures.
  • Formulation and testing of Business Continuity and Disaster Recovery Plans; identify ICT risks impacting availability and participate in tabletop and failover exercises to ensure preparedness.
  • Evaluate the use of cryptographic protocols and encryption solutions for data at rest, in transit, and in use across enterprise systems and cloud assets.
  • Knowledge of security controls like Authentication, Authorization, Data Security, IAM

Required Qualifications

  • Bachelor's degree in computer science, Information Security, Engineering, or equivalent practical experience.
  • 2+ years of hands-on experience in cybersecurity risk assessments of ICT environments, including VAPT oversight and remediation management.
  • Strong knowledge of networking (TCP/IP, routing, switching, firewalls, VPNs, proxies), server platforms (Windows/Linux), directory services, virtualization, and cloud basics.
  • Experience supporting ISO 27001 certification or SOC 2 Type 1/Type 2 readiness and audits.
  • Demonstrated experience implementing or assessing against GRC frameworks: ISO/IEC 27001/27002, SOC 2, NIST CSF/800-53/800-171, and GDPR security/privacy controls.
  • Experience with third-party risk management: security questionnaires, SIG/CAIQ or equivalent, due diligence evidence review, and continuous monitoring.
  • Proficiency with vulnerability management tools and VAPT methodologies; ability to interpret CVEs/CVSS and prioritize remediation.
  • Strong documentation and reporting skills with the ability to communicate technical risks to non-technical stakeholders.
  • Understanding of secure configuration benchmarks (e.g., CIS), patching cycles, logging/monitoring fundamentals, and incident response coordination.
  • Mandatory certifications CEH/Security +

Preferred Qualifications

  • Certifications: CISM, CISA, ISO 27001 Lead Auditor/Lead Implementer.
  • Hands-on exposure to SIEM, EDR, SAST/DAST, cloud security posture management, and container security basics.
  • Tools and Technologies:

o Vulnerability/VAPT: Nessus, Qualys, OpenVAS, Burp Suite, Nmap, Metasploit.

o Governance/Risk/Compliance: risk registers, control libraries, SIG/CAIQ, ISO 27001 documentation suites; ticketing for remediation tracking.

o Infrastructure: Windows/Linux server administration fundamentals, network device configuration review, cloud (AWS/Azure/GCP) security baselines.

o Monitoring: SIEM/EDR exposure for context during risk assessments and validation of remediation.


  • GRC Consultant

    2 weeks ago


    Navi Mumbai, Maharashtra, India Golden Opportunities Full time

    Job Title: GRC Consultant Location: Ghansoli, Navi Mumbai Job Description: Candidate should have 5+ years of experience as GRC Consultant. Risk Management: Identify, assess, and manage risks related to information security, privacy, and regulatory compliance. ISO 27001 Implementation: Lead the implementation and maintenance of ISO 27001 standards, including...


  • Mumbai, Maharashtra, India AMUS HIRING Full time ₹ 5,00,000 - ₹ 10,00,000 per year

    Company DescriptionAMUS HIRING specializes in providing remote technical and non-technical professionals across various industries, including Freight Forwarding, Logistics, Transport, and Supply Chain. We offer a vast pool of skilled candidates for full-time and dedicated roles, ensuring you find the best talent at the lowest cost. Our platform saves...

  • SAP GRC Consultant

    2 days ago


    Mumbai, Maharashtra, India Infocus Technologies Full time US$ 80,000 - US$ 1,20,000 per year

    Role & responsibilities -A strong understanding of GRC frameworks, tools, and processesExperienced with GRC modules like Access Request Management (ARM), Access Risk Analysis (ARA), and Emergency Access Management (EAM).Should have idea about basic GRC tablesRole admin/ User adminMass Role buildAnalyzing the request in case it ends into an error / Analysis...

  • sap- grc

    3 weeks ago


    Mumbai, Maharashtra, India Talentmatics Full time

    We are looking for an experienced SAP GRC (Governance, Risk, and Compliance) Consultant to configure, support, and optimize our SAP GRC processes. The role involves working closely with finance, audit, compliance, and business teams to ensure effective risk management, regulatory compliance, and integration with related SAP modules.Required Skills:-- Strong...

  • GRC Consultant

    2 days ago


    Navi Mumbai, Maharashtra, India Kaivale Technologies Full time US$ 90,000 - US$ 1,20,000 per year

    Position - GRC ConsultantExperience - 4+ YearsLocation - Navi MumbaiNotice Period - Immediate up to 30 daysRoles & ResponsibilitiesKey Responsibilities:·      Risk Management: Identify, assess, and manage risks related to information security, privacy, and regulatory compliance.·      ISO 27001 Implementation: Lead the implementation and...

  • sap- grc

    2 weeks ago


    Mumbai, Maharashtra, India Talentmatics Full time

    We are looking for an experienced SAP GRC (Governance, Risk, and Compliance) Consultant to configure, support, and optimize our SAP GRC processes. The role involves working closely with finance, audit, compliance, and business teams to ensure effective risk management, regulatory compliance, and integration with related SAP modules. Required Skills:- ...


  • Mumbai, Maharashtra, India Hudson Manpower Full time ₹ 15,00,000 - ₹ 20,00,000 per year

    Location: Andheri Mumbai Position Overview We are seeking a highly skilled SAP S/4HANA Security & GRC Consultant with 6–8 years of experience, preferably in the utility business sector. The role is critical in ensuring the confidentiality, integrity, and availability of SAP S/4HANA systems, protecting sensitive business data, and maintaining compliance...

  • GRC Consultant

    3 days ago


    Mumbai, Maharashtra, India Cubical Operations LLP Full time

    Job Title: GRC Consultant (ISMS / ISO 27001 / IT Audit)Experience: 2+ YearsLocation: Mumbai (On-site)Notice Period: Immediate Joiners PreferredEmployment Type: Full-timeJob Description:We are seeking a highly motivated and detail-oriented GRC Consultant with over 2 years of experience in Information Security Management Systems (ISMS), ISO 27001...


  • Mumbai, Maharashtra, India AMUS HIRING Full time ₹ 45,000 - ₹ 55,000 per year

    Company DescriptionAMUS HIRING provides remote hiring services to save time and money for businesses by offering a pool of skilled candidates. Specialized in Freight Forwarding, Logistics, Transport, and Supply Chain industries, AMUS HIRING offers full-time, dedicated professionals experienced in various fields. Located in Mumbai, AMUS HIRING ensures quick...

  • Senior GRC Consultant

    4 hours ago


    Mumbai, Maharashtra, India VaporVM Full time

    Job DescriptionWe are seeking a highly skilled Senior Security Engineer (GRC & Advisory) to join our Cybersecurity & Advisory Services team. The ideal candidate will play a pivotal role in driving security governance, risk management, and compliance initiatives, while providing strategic advisory services to clients. This role requires a mix of deep...