Cutshort logo
For Employers
A Predictive analytics organization with well funded logo
grc operation
A Predictive analytics organization with well funded

grc operation at A Predictive analytics organization with well funded · Chennai · 3 - 6 years · ₹4L - ₹13L / yr (ESOP available) · Posted 3 Mar 2023

Hunt & Badge Consulting Pvt Ltd's logo

grc operation

at A Predictive analytics organization with well funded

3 - 6 yrs
₹4L - ₹13L / yr (ESOP available)
Chennai
Skills
IT governance
IT risk management
Compliance
GRC
IT risk
IT audit

What The Role Is

We are looking for an GRC Operations Officer based in Chennai. This is a new role within the growing IT Compliance function, where you will be responsible for handling audits, implementation of information security policies etc,. The successful candidate will be comfortable working with the team on implementing frameworks and providing support for internal and external stakeholders. Reporting to the IT Compliance Officer for our Chennai team, this role is integral to the successful growth of the team as well as wider company performance.  

What You’ll Do

  • Contribute and assist with continuous improvement of company policies, practices, and procedures
  • Review, modify and maintain existing practices and policies to reflect our operations and values within specific industry-standard frameworks like ISO and NIST, among others
  • Provide support for internal and third-party audits
  • Respond to due diligence and TPRM requests from customers and other interested parties.
  • Support internal staff with GRC-related questions and topics
  • Develop, maintain and execute awareness programs
  • Be a local representative of the company’s GRC group and manage the physical security requirements for the location
  • Work independently and prioritize multiple tasks and adapt to needed changes
  • Effectively communicate risks to diverse audiences, both in writing and verbally
  • Apply a risk-based approach to planning, executing, and reporting on audit engagements and auditing process;

What You’ll Bring

  • 2-5 years IT Security, IT risk, IT auditing, and/or IT Compliance experience within a technology company, accounting firm,  or others.
  • Bachelor's degree or equivalent work experience working in compliance/GRC team.
  • Exceptional organisational skills and attention to details.
  • Knowledge of applicable domestic and internationally recognized information security management, governance, and compliance principles, practices, laws, rules and regulations;
  • Information systems auditing, monitoring, controlling, and assessment process.

Perks & Benefits: 

  • Competitive base salary
  • Equity - every employee is a stakeholder in our enormous upside
  • A tech-first company culture driven by entrepreneurial thinking and talent
  • A great team working in unison towards the same mission
  • Transparency is what our product is built on—and so is our culture
  • Generous health insurance benefits for employees and their dependents
  • Parental leave.
  • Flexible work schedule and work-from-home options
  • Flexible PTO
Read more
Users love Cutshort
Read about what our users have to say about finding their next opportunity on Cutshort.
Shubham Vishwakarma's profile image

Shubham Vishwakarma

Full Stack Developer - Averlon
I had an amazing experience. It was a delight getting interviewed via Cutshort. The entire end to end process was amazing. I would like to mention Reshika, she was just amazing wrt guiding me through the process. Thank you team.
Companies hiring on Cutshort
companies logos

Similar jobs (3)

NAM Info Pvt Ltd
Ramya Munirathnam
Posted by Ramya Munirathnam
Bengaluru (Bangalore), Chennai, Hyderabad, Mumbai, Pune
5 - 7 yrs
₹6L - ₹12L / yr
Cyber Security
GRC
Security Compliance

This role is focused on Cyber Security Risk, Governance, Risk & Compliance (GRC), IT Controls, and Security Audits, with strong emphasis on Backup, Disaster Recovery (DR), and Business Continuity (BCP).

Key responsibilities:

  • Perform security control assessments against organizational policies, security standards, and regulatory requirements.
  • Identify control gaps, risks, audit findings, and compliance issues, and monitor remediation until closure.
  • Assess Backup, Disaster Recovery, and Business Continuity processes and controls.
  • Validate backup availability, restoration/recovery procedures, DR readiness, and evidence of periodic DR/BCP testing.
  • Conduct control testing and risk assessments and support internal/external security audits.
  • Review security policies, procedures, standards, and governance frameworks for compliance.
  • Maintain audit evidence, track findings, and coordinate with stakeholders for remediation.
  • Support overall security governance, regulatory compliance, and IT risk management activities.

Required Skills

  • Cyber Security Risk & Compliance / GRC
  • IT Risk & Controls
  • Security Control Assessment & Testing
  • Security Audits
  • Backup & Disaster Recovery
  • BCP / DR
  • Risk Assessment
  • Compliance & Governance
  • Security Policies & Standards
  • Audit Finding & Remediation Management
Read more
Mumbai
5 - 7 yrs
₹8L - ₹15L / yr
ISO/IEC 27001:2005
Information security governance
Compliance
Risk Management
Stakeholder management

We are seeking an experienced Governance, Risk & Compliance (GRC) Lead to spearhead the

design, implementation, and maintenance of our ISO 27001 Information Security Management

System (ISMS). This is a hands-on leadership role responsible for establishing a robust security

governance framework, achieving ISO 27001 certification, and embedding a culture of

continuous security improvement across the organization.

Key Responsibilities

● ISMS Implementation & Certification: Lead end-to-end ISO 27001 implementation

from gap analysis through to successful Stage 1 and Stage 2 certification audits;

manage external auditor relationships

● Risk Management: Develop and operationalize the information security risk

management framework; conduct risk assessments, treatment planning, and risk

acceptance processes.

● Policy & Governance : Author, approve, and maintain the Statement of Applicability

(SoA), information security policies, standards, and procedures aligned with ISO 27001

Annex A controls.

● Control Implementation: Translate ISO 27001 Annex A controls into operational

security measures; coordinate with IT, Accounts, HR, Backoffice, and business units to

implement and validate controls.

● Compliance Monitoring: Establish continuous monitoring, internal audit programs, and

KPIs/KRIs to measure ISMS effectiveness; manage non-conformities and corrective

actions.

● Third-Party Risk: Oversee vendor security assessments and ensure supply chain

security controls meet organizational and ISO 27001 standards.

● Stakeholder Management: Report ISMS performance, risks, and compliance status to

senior leadership and the board; act as primary liaison for external auditors and

regulators.

Required Qualifications

● 5+ years of experience in information security governance, risk, and compliance

● Proven track record of leading at least one full ISO 27001:2022 certification cycle (gap

analysis → certification)

● Deep expertise in ISO 27001:2022 standard, Annex A controls, and ISMS

documentation requirements

● Strong understanding of risk assessment methodologies (e.g., ISO 27005, NIST RMF,

OCTAVE, FAIR)

● Familiarity with internal audit practices and managing external certification bodies

● Excellent stakeholder management and ability to influence across technical and non-

technical teams

● Strong documentation and communication skills — able to translate complex standards

into actionable guidance

Preferred Qualifications

● Experience implementing ISMS in fintech, healthcare, or regulated industries

● Experience with SOC 2, GDPR, NIST CSF, PCI-DSS, or other compliance frameworks

● Background in cloud security (AWS, Azure, GCP) and DevSecOps environments

● Knowledge of automation for compliance evidence collection and control testing

● Certifications: CISM, CRISC, CISA, ISO 27001 Lead Auditor, or ISO 27001 Lead

Implementer

Why Join Us

● Opportunity to build the security governance function from the ground up

● High-visibility role with direct impact on customer trust and market differentiation

● Collaborative environment that values security as a business enabler, not a blocker

Company Profile:

We are a one-stop financial services shop, widely known for quality of its advice, personalized

service and cutting-edge technology. We started our journey in 2008. Currently we are serving

more than 50,000 investors with a team of 100 members. Our core product offering is mutual

fund, FD, Govt. Bonds, Debenture, etc.



Read more
Potentiam Offshore Solutions Pvt Ltd
Bhavya Pallapu
Posted by Bhavya Pallapu
Bengaluru (Bangalore)
3 - 8 yrs
₹12L - ₹20L / yr
SOX 404
ITGC
NIST
ISO27001
CSF

Job title Sox Compliance Officer

Reporting to Potentiam company background (The Employer) Potentiam is a global provider of highly qualified professionals to European SMEs from our offices in Romania, South Africa and India. Potentiam works with clients in finance, energy, leisure, marketing, business services and technology industries, providing technical, professional multi- lingual highly motivated staff, most of whom have had experience of working for international companies. Staff cover a wide range of roles from accounting, marketing, data management, HR, sales/account management, engineering, technology, and operations. Potentiam manages our staff’s career development and personal development training, all infrastructure, HR and payroll with our clients directly managing day-to-day staff responsibilities and role training and development. Company website - https://potentiam.co.uk/

Potentiam’s client: It is a leading provider of independent medical examinations, peer reviews, bill reviews, Medicare compliance, record retrieval, document management and related services. It provide IME services through their medical panel of credentialed physicians and allied medical professionals. Their independent medical review process is fully contained within their private cloud network. Custom portals, applications, workflow enhancements and systems integration are part and parcel of their service. Their clients include property and casualty insurance carriers, law firms, third-party claim administrators and government agencies that use independent services to confirm the veracity of claims by sick or injured individuals under automotive, disability, liability and workers' compensation insurance coverages. They help clients in the U.S., Canada, the United Kingdom and Australia manage costs and enhance their risk management processes by verifying the validity of claims, identifying fraud and providing fast, efficient and quality IME services.

Industry: legal, insurance, and healthcare services.

Purpose of role:

We are seeking a Compliance Officer to join our compliance team. This role is responsible for auditing IT control activities, ensuring adherence to Sarbanes Oxley (SOx) requirements, and maintaining governance standards. The ideal candidate will work closely with external auditors, perform Entity-Level Controls (ELCs), and document narratives, processes, and procedures in a fast paced environment. Potentiam | Job Specification 2 of 2

Duties and responsibilities: Compliance & Audit Activities • Audit IT control operations performed by IT Controls Analysts to ensure compliance with SOx requirements. • Perform walkthroughs and testing of ITGCs and ELCs to validate control design and operating effectiveness. • Develop, maintain, and update SOx narratives, process flows, and control documentation. • Coordinate and liaise with external auditors during SOx audits and provide requested evidence. • Identify control gaps and recommend remediation plans in collaboration with stakeholders. • Experience with ISO 27001 and NIST CSF, including understanding of information security controls, risk management, control assessments, compliance requirements, and security governance practices. • Familiarity with Cyber Essentials Plus (CE+) and related security/compliance requirements, along with knowledge or experience using Vanta or similar GRC/compliance management platforms, is a strong plus. Governance & Reporting • Prepare compliance reports and dashboards for management review. • Ensure timely completion of SOx testing cycles and documentation updates. • Support risk assessments and contribute to strengthening the overall control environment. Collaboration & Communication • Work closely with IT, Finance, and Compliance teams to align SOx requirements with business processes. • Act as a point of contact for external auditors and internal stakeholders. • Provide training and guidance on SOx compliance and control documentation standards.

Skills/Experience • Experience in SOx compliance, auditing, and governance processes. • Strong knowledge of Entity-Level Controls (ELCs), ITGCs, and SOx documentation standards. • Experience with ISO 27001 and NIST CSF, including security controls, risk assessment, and compliance. • Familiarity with CE+ and Vanta or similar GRC/compliance platforms is a strong plus. • Ability to create and maintain narratives, process flows, and control matrices. • Excellent communication and stakeholder management skills. • Detail-oriented with strong analytical and problem-solving capabilities. Why Join Us? • Opportunity to play a critical role in compliance and governance initiatives. • Collaborative team environment with exposure to senior leadership and external auditors. • Professional growth in a dynamic, fast-paced environment.

Additional benefits • Health Insurance • Referral Bonus • Performance Bonus • Flexible Working options

Location and hours Bangalore Office / UK hours

Read less


Read more
Why apply to jobs via Cutshort
people_solving_puzzle
Personalized job matches
Stop wasting time. Get matched with jobs that meet your skills, aspirations and preferences.
people_verifying_people
Verified hiring teams
See actual hiring teams, find common social connections or connect with them directly.
ai_chip
Move faster with AI
We use AI to get you faster responses, recommendations and unmatched user experience.
Did not find a job you were looking for?
icon
Search for relevant jobs from 10000+ companies such as Google, Amazon & Uber actively hiring on Cutshort.
companies logo
companies logo
companies logo
companies logo
companies logo
Get to hear about interesting companies hiring right now
Company logo
Company logo
Company logo
Company logo
Company logo
Linkedin iconFollow Cutshort
Users love Cutshort
Read about what our users have to say about finding their next opportunity on Cutshort.
Shubham Vishwakarma's profile image

Shubham Vishwakarma

Full Stack Developer - Averlon
I had an amazing experience. It was a delight getting interviewed via Cutshort. The entire end to end process was amazing. I would like to mention Reshika, she was just amazing wrt guiding me through the process. Thank you team.
Companies hiring on Cutshort
companies logos