Principal GRC Specialist at B2B Product · Remote, Pune · 14 - 20 years · ₹25L - ₹50L / yr · Remote friendly · Posted 1 Sep 2025

What will you do?
Governance and Policy Development
· Develop, implement, and maintain governance policies, SOPs, and related documentation.
· Ensure all policies align with industry standards (e.g., FedRAMP, NIST SP 800-53, ISO 27001 family, and HIPAA).
· Monitor policy effectiveness and recommend updates based on organizational changes or regulatory updates.
Risk Management
· Conduct risk assessments to identify vulnerabilities, threats, and compliance gaps.
· Collaborate with cross-functional teams to design and implement remediation strategies.
· Maintain risk registers and monitor mitigation efforts.
Compliance Oversight
· Support the organization in achieving and maintaining FedRAMP certification.
· Manage periodic audits, security assessments, and readiness activities for compliance frameworks.
· Track and report on compliance metrics, audit findings, and resolution status.
Training and Awareness
· Develop and deliver training programs to enhance employee understanding of compliance policies and procedures.
· Act as a point of contact for compliance-related queries within the organization.
Incident Response and Reporting
· Support incident response processes to ensure effective investigation and reporting of compliance-related incidents.
· Collaborate with stakeholders to implement corrective actions and prevent recurrence.
Vendor and Third-Party Risk Management
· Assess third-party vendors for compliance with organizational policies and standards.
· Ensure contracts include appropriate compliance requirements.
What do you bring to the table?
Education & Experience
· Overall 12- 15 years of relevant experience
· Bachelor's degree in Information Technology, Cybersecurity, Risk Management, or related field (Master’s preferred).
· 3+ years of experience in governance, risk, and compliance roles, with specific experience in FedRAMP compliance.
Knowledge & Skills
· Strong understanding of FedRAMP, NIST SP 800-53, ISO 27001, and other relevant frameworks.
· Experience in drafting policies, procedures, and SOPs.
· Familiarity with GRC tools and platforms (e.g., Archer, ServiceNow GRC).
· Excellent communication and documentation skills.
· Analytical mindset with attention to detail.
Certifications (Preferred)
· Certified Information Systems Security Professional (CISSP)
· Certified Information Systems Auditor (CISA)
· Certified Information Security Manager (CISM)
· ISO 27001 Lead or Internal auditor

Similar jobs (6)
This role is focused on Cyber Security Risk, Governance, Risk & Compliance (GRC), IT Controls, and Security Audits, with strong emphasis on Backup, Disaster Recovery (DR), and Business Continuity (BCP).
Key responsibilities:
- Perform security control assessments against organizational policies, security standards, and regulatory requirements.
- Identify control gaps, risks, audit findings, and compliance issues, and monitor remediation until closure.
- Assess Backup, Disaster Recovery, and Business Continuity processes and controls.
- Validate backup availability, restoration/recovery procedures, DR readiness, and evidence of periodic DR/BCP testing.
- Conduct control testing and risk assessments and support internal/external security audits.
- Review security policies, procedures, standards, and governance frameworks for compliance.
- Maintain audit evidence, track findings, and coordinate with stakeholders for remediation.
- Support overall security governance, regulatory compliance, and IT risk management activities.
Required Skills
- Cyber Security Risk & Compliance / GRC
- IT Risk & Controls
- Security Control Assessment & Testing
- Security Audits
- Backup & Disaster Recovery
- BCP / DR
- Risk Assessment
- Compliance & Governance
- Security Policies & Standards
- Audit Finding & Remediation Management
Job Summary
We are looking for a Senior Compliance Analyst to manage and support cybersecurity compliance, GRC, risk assessments, audits, and client engagements. The candidate will evaluate security controls, identify compliance gaps, review evidence, and provide practical recommendations.
Key Responsibilities
- Conduct Compliance Audits, Gap Assessments, and Risk Assessments.
- Assess controls against ISO 27001, SOC 2, PCI DSS, ISO 27701, ISO 42001, HIPAA, GDPR, DPDP, etc.
- Review policies, procedures, controls, and audit evidence.
- Identify gaps, risks, observations, and recommend remediation.
- Prepare Risk Registers, SoA, Control Matrices, Audit Reports, and Compliance Reports.
- Support clients during certification, surveillance, and external audits.
- Conduct client meetings, interviews, and control walkthroughs.
- Coordinate evidence collection and remediation tracking.
- Develop and review information security policies and procedures.
- Stay updated with cybersecurity standards, regulations, and best practices.
Required Skills
- Strong understanding of Information Security, GRC, Risk & Compliance.
- Good knowledge of ISO 27001:2022 and SOC 2.
- Understanding of cybersecurity controls, IT infrastructure, cloud security, IAM, vulnerability management, and security operations.
- Strong analytical, documentation, communication, and report-writing skills.
- Ability to independently manage client engagements.
Qualifications
- Bachelor's degree in Cybersecurity, IT, Computer Science, or related field.
- 2–6 years of relevant experience in GRC, IT Audit, Cybersecurity Compliance, or Consulting.
- Certifications such as ISO 27001 LA/LI, CISA, CISSP, CRISC, or relevant GRC certifications are preferred.
We are seeking an experienced Governance, Risk & Compliance (GRC) Lead to spearhead the
design, implementation, and maintenance of our ISO 27001 Information Security Management
System (ISMS). This is a hands-on leadership role responsible for establishing a robust security
governance framework, achieving ISO 27001 certification, and embedding a culture of
continuous security improvement across the organization.
Key Responsibilities
● ISMS Implementation & Certification: Lead end-to-end ISO 27001 implementation
from gap analysis through to successful Stage 1 and Stage 2 certification audits;
manage external auditor relationships
● Risk Management: Develop and operationalize the information security risk
management framework; conduct risk assessments, treatment planning, and risk
acceptance processes.
● Policy & Governance : Author, approve, and maintain the Statement of Applicability
(SoA), information security policies, standards, and procedures aligned with ISO 27001
Annex A controls.
● Control Implementation: Translate ISO 27001 Annex A controls into operational
security measures; coordinate with IT, Accounts, HR, Backoffice, and business units to
implement and validate controls.
● Compliance Monitoring: Establish continuous monitoring, internal audit programs, and
KPIs/KRIs to measure ISMS effectiveness; manage non-conformities and corrective
actions.
● Third-Party Risk: Oversee vendor security assessments and ensure supply chain
security controls meet organizational and ISO 27001 standards.
● Stakeholder Management: Report ISMS performance, risks, and compliance status to
senior leadership and the board; act as primary liaison for external auditors and
regulators.
Required Qualifications
● 5+ years of experience in information security governance, risk, and compliance
● Proven track record of leading at least one full ISO 27001:2022 certification cycle (gap
analysis → certification)
● Deep expertise in ISO 27001:2022 standard, Annex A controls, and ISMS
documentation requirements
● Strong understanding of risk assessment methodologies (e.g., ISO 27005, NIST RMF,
OCTAVE, FAIR)
● Familiarity with internal audit practices and managing external certification bodies
● Excellent stakeholder management and ability to influence across technical and non-
technical teams
● Strong documentation and communication skills — able to translate complex standards
into actionable guidance
Preferred Qualifications
● Experience implementing ISMS in fintech, healthcare, or regulated industries
● Experience with SOC 2, GDPR, NIST CSF, PCI-DSS, or other compliance frameworks
● Background in cloud security (AWS, Azure, GCP) and DevSecOps environments
● Knowledge of automation for compliance evidence collection and control testing
● Certifications: CISM, CRISC, CISA, ISO 27001 Lead Auditor, or ISO 27001 Lead
Implementer
Why Join Us
● Opportunity to build the security governance function from the ground up
● High-visibility role with direct impact on customer trust and market differentiation
● Collaborative environment that values security as a business enabler, not a blocker
Company Profile:
We are a one-stop financial services shop, widely known for quality of its advice, personalized
service and cutting-edge technology. We started our journey in 2008. Currently we are serving
more than 50,000 investors with a team of 100 members. Our core product offering is mutual
fund, FD, Govt. Bonds, Debenture, etc.
IT Compliance Manager – Web3 & Digital Assets
📍 Location: Dubai, UAE
💼 Employment Type: Full-Time
🏢 Department: Technology / Compliance
📊 Experience: 5+ Years
🌐 Industry: FinTech / Web3 / Digital Assets
About the Role
We are looking for an experienced IT Compliance Manager – Web3 & Digital Assets to lead technology compliance, IT governance, risk management, and cybersecurity controls within a regulated FinTech and digital-asset environment.
The ideal candidate will have strong experience in IT GRC, technology risk, cybersecurity governance, Web3/blockchain, digital assets, and regulatory compliance, with UAE regulatory experience being highly preferred.
Key Responsibilities
- Manage IT governance, compliance frameworks, policies, procedures, and technology risk assessments.
- Support compliance with UAE virtual asset and financial-services regulations, including VARA, DFSA, FSRA, and UAE Central Bank requirements, where applicable.
- Assess technology risks across blockchain infrastructure, crypto wallets, custody, APIs, cloud platforms, databases, smart contracts, and dApps.
- Review controls related to crypto deposits, withdrawals, transfers, wallet operations, and transaction monitoring.
- Develop and monitor controls aligned with ISO 27001, SOC 2, NIST, PCI DSS, and relevant regulatory requirements.
- Coordinate IT audits, regulatory audits, compliance assessments, evidence collection, and remediation activities.
- Maintain technology risk registers, control assessments, compliance reports, and management dashboards.
- Partner with Engineering, Product, Security, Legal, Risk, AML/KYC, Finance, and Operations teams.
- Embed compliance and technology-risk requirements into product development, system changes, and technology architecture.
- Support regulatory licensing, assessments, and ongoing compliance requirements for digital-asset services.
Requirements
- Bachelor's degree in IT, Computer Science, Cybersecurity, Finance, Risk Management, or a related discipline.
- 5+ years of experience in IT Compliance, IT GRC, Technology Risk, Cybersecurity Governance, or a related field.
- Experience in FinTech, banking, payments, cryptocurrency, blockchain, digital assets, or financial services.
- Strong understanding of Web3, blockchain networks, crypto wallets, digital-asset transactions, custody, and smart-contract risks.
- Hands-on experience with IT governance, risk assessments, control testing, audits, and compliance frameworks.
- Strong knowledge of ISO 27001, SOC 2, NIST, PCI DSS, ITGC, or similar frameworks.
- Experience working with auditors, regulators, and cross-functional technology teams.
- Strong analytical, documentation, communication, and stakeholder-management skills.
UAE / Web3 Experience – Preferred
- Experience with VARA, DFSA, FSRA, UAE Central Bank, or other UAE financial regulators.
- Experience supporting VASP licensing or regulatory approvals.
- Previous experience in crypto exchanges, digital-asset platforms, blockchain companies, Web3 startups, or FinTech organizations.
- Understanding of AML/KYC, transaction monitoring, custody, wallet security, and digital-asset controls.
Preferred Certifications
- CISA
- CISM
- CISSP
- CRISC
- ISO 27001 Lead Auditor / Lead Implementer
- CAMS
Key Skills
IT GRC | IT Compliance | Technology Risk | Web3 Governance | Blockchain Risk | Digital Asset Compliance | VASP Licensing | UAE Regulatory Compliance | ITGC | Cybersecurity Governance | ISO 27001 | SOC 2 | NIST | PCI DSS | IT Audit | Risk Assessment | Crypto Transaction Monitoring | Stakeholder Management
The recruiter has not been active on this job recently. You may apply but please expect a delayed response.
Location: Jaipur, Rajasthan (Work From Office)
Experience: 5+ Years
Job Type: Full-Time
We're looking for an IT Compliance Officer to lead information security and compliance initiatives across our SaaS products and IT infrastructure. You'll ensure compliance with industry standards while strengthening our security and governance framework.
Key Responsibilities
- Manage compliance for SOC 2, ISO 27001, GDPR, and ITGC.
- Coordinate security audits, VAPT, and risk assessments.
- Develop and maintain security policies, SOPs, and compliance documentation.
- Ensure data protection, access control, and incident response best practices.
- Collaborate with IT, Development, QA, and Product teams to improve security controls.
- Conduct compliance training and stay updated on cybersecurity regulations.
Requirements
- 5+ years of experience in IT Compliance, Information Security, or IT Audit (preferably in a SaaS/Product company).
- Strong knowledge of SOC 2, ISO 27001, ITGC, VAPT, Risk Management, and Compliance Audits.
- Experience with security documentation, audit processes, and risk assessments.
- Excellent analytical, communication, and documentation skills.
Preferred: ISO 27001 Lead Auditor, CISA, CISM, CompTIA Security+, or Six Sigma certification.
Apply Now
Application Form: https://zfrmz.com/pAKb2ynfomIsuNwRfRbV?utm_source=cutshort
Roles & Responsibilities:-
- Develop and maintain enterprise data governance strategies, policies, and standards aligned with business goals
- Manage Microsoft Purview accounts, collections, and RBAC; optimize for large-scale environments (50TB+)
- Design metadata repositories and maintain business glossaries and data dictionaries
- Implement ingestion workflows via ADF, REST APIs, PowerShell, Azure Functions
- Define classification rules and sensitivity labels (PII, PCI, PHI); integrate with MIP, DLP, Insider Risk Management
- Define KPIs and dashboards to monitor data quality across domains
- Maintain business glossary with domain owners and stewards; enforce approval workflows
- Automate governance processes using PowerShell, Azure Functions, Logic Apps
- Set up dashboards for audit logs, compliance reporting, and metadata coverage
- Collaborate across business, IT, legal, and compliance teams for role alignment
Ideal Candidate:-
- Strong Data Governance Lead Profile with deep Microsoft Purview and enterprise governance expertise
- Mandatory (Experience 1): Must have 7+ years of experience in data governance and data management with at least the recent 3+ years of exposure in Microsoft Purview
- Mandatory (Experience 2): Must have experience defining, leading, and operationalizing an enterprise data governance framework — strategy, policies, and standards aligned to business goals and regulatory compliance.
- Mandatory (Tech skill 1): Must be proficient in Microsoft Purview — accounts, collections, RBAC, classification/labelling, DLP, Unified Catalog, Data Map, eDiscovery, Compliance Manager, and lifecycle/records management (ideally at large scale, 50TB+).
- Mandatory (Tech skill 2): Must be strong in metadata management, lineage mapping (e.g. ADF → Synapse → Power BI), data classification, and security governance (PII/PCI/PHI, sensitivity labels, MIP/DLP)
- Mandatory (Tech skill 3): Must have experience with data governance tools such as Informatica (Axon), Collibra, Atlan, or IBM IG Catalog.
- Mandatory (Tech skill 4): Must have experience integrating governance with the Azure data stack (Data Lake, Synapse, SQL DB, Power BI) and Snowflake, and automating via ADF, REST APIs, PowerShell, Azure Functions / Logic Apps.
- Mandatory (Tech skill 5): Must have experience defining data quality KPIs/dashboards, remediation workflows, and business glossary/stewardship (domain owners, approval workflows, metadata audits)
- Mandatory (Compliance): Must have strong knowledge of GDPR, CCPA, HIPAA, and SOX compliance requirements.
- Mandatory (Skill): Must be able to bridge technical governance with business and compliance goals, collaborating across business, IT, legal, and compliance teams, and driving governance training and change management
- Mandatory (Company): B2B Tech/Consulting/B2B Software







