Login Sign Up

GRC Associate

ISECURION

0 - 3 years

Bengaluru

Posted: 01/07/2026

Job Description

Company Description ISECURION is a CERT-In empanelled and ISO 27001:2022 certified cybersecurity consulting company that helps organizations strengthen their security posture in a complex digital environment. The team focuses on practical, business-oriented security solutions that support compliance, risk reduction, and long-term cyber resilience. Services include Vulnerability Assessment & Penetration Testing (VAPT), compliance audits, cloud security, DFIR, risk assessments, and managed security services. ISECURION works closely with clients to identify security gaps, prioritize remediation, and align with industry best practices and regulatory standards. The company is driven by a passionate team committed to research, innovation, and delivering meaningful security outcomes.


Role Description We are seeking an experienced and detail-oriented GRC Associate to join our dynamic team at a prestigious client site near Kempegowda International Airport, Bengaluru. The ideal candidate will bring deep expertise in Business Continuity Management (BCM/BCP), ISO 22301, ISO 27001, Third-Party Risk Management (TPRM), and enterprise risk assessment frameworks. This is an excellent opportunity for an immediate joiner who thrives in a client-facing consulting environment.


Key Responsibilities


Develop, implement, maintain, and continuously improve Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP) aligned with ISO 22301 standards.

Conduct Business Impact Analysis (BIA) to identify critical business functions, recovery time objectives (RTOs), and recovery point objectives (RPOs).

Lead and coordinate BCP/DR tabletop exercises, simulations, and live drills; document findings and drive corrective actions.

Ensure organizational readiness for disruptions by maintaining crisis communication plans, escalation matrices, and recovery runbooks.

Monitor and report on BCM program maturity and present improvement roadmaps to senior management.

Drive ISO 27001 implementation, gap assessments, and certification/surveillance audit support for internal teams and clients.

Maintain the Information Security Management System (ISMS) including policies, procedures, Statement of Applicability (SoA), and risk treatment plans.

Perform internal ISMS audits, track non-conformities, and ensure timely closure of corrective and preventive actions (CAPAs).

Facilitate risk identification, evaluation, and treatment in accordance with ISO 27001 Annex A controls and organizational risk appetite.

Prepare and present audit reports, dashboards, and compliance metrics to stakeholders and senior leadership.

Design, execute, and manage end-to-end TPRM programs including vendor onboarding assessments, periodic reviews, and offboarding risk evaluations.

Conduct structured TPRM audits and on-site/remote assessments of third-party vendors and supply chain partners against defined security and compliance criteria.

Develop and maintain vendor risk scoring models, risk heat maps, and consolidated TPRM registers.

Coordinate with procurement, legal, and business units to ensure contractual security obligations (SLAs, NDA, DPA) are enforced and monitored.

Track and remediate vendor security gaps; escalate critical risks to appropriate risk owners.

Conduct comprehensive enterprise-level risk assessments covering information security, operational, cyber, and compliance risk domains.

Develop and maintain the organizational risk register, risk treatment plans, and Key Risk Indicators (KRIs).

Perform threat modelling, vulnerability assessments, and control effectiveness reviews as part of the risk lifecycle.

Support the Risk Committee by preparing risk reports, dashboards, and exception logs for governance forums.

Assist in developing and reviewing risk management policies, frameworks, and procedures aligned with industry best practices.

Support regulatory compliance initiatives including but not limited to DPDPA, RBI/SEBI guidelines, SOC 2, and other applicable frameworks.

Prepare and maintain compliance calendars, evidence repositories, and audit-ready documentation for certifications and regulatory reviews.

Develop GRC reports, Board-level presentations, and compliance dashboards to communicate risk posture clearly to stakeholders.

Participate in client-facing GRC advisory engagements, workshops, and awareness training sessions.

Stay current with evolving regulatory requirements, threat landscapes, and GRC best practices; update internal frameworks accordingly.

Collaborate with IT, Legal, HR, and Operations teams to embed security and risk culture across the organization.

Maintain GRC tools, trackers, and documentation repositories; ensure version control and audit trail integrity.

Support security incident response efforts from a GRC perspective documenting lessons learned and updating BCPs post-incident.

Mentor junior GRC associates and contribute to team knowledge-sharing sessions and capability building.

Assist in pre-sales GRC consulting activities including proposal writing, scope definition, and solution design.


Qualifications

Strong knowledge of ISO 27001, ISO 22301, NIST CSF, CIS Controls, and related frameworks

Expertise in Business Continuity and Disaster Recovery planning methodologies

Proven ability to conduct TPRM audits and manage vendor risk lifecycle

Experience with GRC platforms (e.g., ServiceNow GRC, RSA Archer, MetricStream, or similar)

Proficiency in risk register management, control testing, and audit evidence collection

Excellent report-writing, documentation, and presentation skills

Strong stakeholder management and communication abilities both written and verbal

Ability to work independently at client sites in a fast-paced consulting environment

  • Analytical mindset with strong attention to detail and structured problem-solving approach


Requirements:

  • 34 Years in GRC / Information Security domain
  • Minimum 3 years of hands-on ISO 27001 implementation & audit experience
  • Demonstrated experience in BCP development, BIA, and ISO 22301 compliance
  • Experience conducting third-party risk audits and vendor assessments
  • Proficiency in enterprise risk identification, analysis, and treatment
  • ISO 27001 LA/LI, ISO 22301 LA/LI, CRISC, CISA, CISM, or equivalent
  • B.E./B.Tech/MCA/MBA in IT, Computer Science, or related field
  • Must be available to work at client site near Kempegowda Airport, Bengaluru
  • Immediate Joiner Mandatory


HOW TO APPLY

Interested candidates are requested to send their updated resume with the subject line "GRC Associate Immediate Joiner" to hr@isecurion.com. Only candidates available for immediate joining and willing to work at the client site near Kempegowda International Airport, Bengaluru will be considered.

Services you might be interested in

We Search & Apply Jobs for You!

Our team scans through 1000s of opportunities and applies to roles best suited to your profile

Save 100+ hours and focus on what matters - cracking interviews and landing offers.