IT Governance, Risk and Compliance Analyst managing compliance initiatives like NIST and ISO standards in technology and security operations.
Responsibilities
Manage IT Compliance programs and support IT/ Security initiatives, including NIST CSF 2.0, ISO 27001:2022, GDPR, DPDP Act and other similar standards and frameworks.
Manage internal and external audits, including coordination with auditors, evidence collection, and remediation of findings.
Drive IT risk assessments, vendor risk management, and corrective action plans.
Collaborate with IT, security, and product teams to ensure operational practices meet compliance requirements.
Requirements
5+ years of experience in IT Audit, IT Risk, GRC, or Information Security.
Strong understanding of IT general controls, security operations, and data protection requirements.
Experience with IT audit management, evidence collection, and control testing.
Experience with end to end Third-party risk management including tiered vendor reviews, security questionnaires, risk scoring, and ongoing monitoring.
Hands-on knowledge of NIST CSF, NIST SP 800-53 and ISO 27001.
Knowledge of Cloud fundamentals (AWS), SaaS models, and modern infrastructure.
Excellent communication, documentation, and stakeholder management skills.
Strong analytical and problem-solving abilities.
B.E / B.Tech - IT /CS
Professional certifications such as CISM, CISSP.
Good to Have Prior security engineering or application security background before moving into GRC.
Experience in a regulated sector (Banking, Fintech, Insurance) or Big 4 Audit (IT Risk advisory) is highly preferred.
Compliance Specialist overseeing regulatory adherence for youth programs in Gainesville. Ensuring DCF compliance and supporting youth program safety and integrity.
Technologist at FortisBC ensuring compliance with BCUC Critical Infrastructure Protection Standards. Focus on integrating business technology and providing technical support.
Compliance Examiner Business Lead at Freddie Mac conducting on - site examinations and ensuring financial activities align with laws. Engaging with financial institutions to enhance operational effectiveness.
Compliance Professional supporting Freddie Mac's investment and ethics policies. Engaging with compliance risks and overseeing regulatory obligations to promote best practices.
Compliance Officer at Hewlett Packard Enterprise ensuring adherence to compliance regulations, managing AML programs, and conducting risk assessments. Driving compliance culture across markets and delivering training to employees.
Risk Manager at Cisco Capital ensuring regulatory compliance and effective risk management practices. Focus on safeguarding financial health and collaboration within an international environment.
Regulatory Reporting Specialist managing outsourced reporting service providers in Germany and Spain. Ensuring compliance with banking regulations and supporting audits and reviews.
Assisting partners at Clyde & Co with business inception processes and anti - money laundering procedures. Involves reviewing requests and conducting conflict checks within the firm's compliance framework.
Senior Analyst, OSS Compliance managing open - source software assets for The Hartford. Ensuring compliance and visibility into OSS usage as part of software asset management process.
Data Governance Implementation Analyst supporting implementation of Data Governance Operating Model for Compliance at BNY. Collaborating with business units to drive data quality standards.