GRC Analyst L3
On-siteBhubaneswar, Odisha, India
Job Summary
Conduct internal IT infrastructure audits across network, servers, cloud platforms, identity management, and access controls. Perform gap analyses against frameworks like PCI-DSS, ISO 27001, GDPR, and DPDP, identifying non-compliance and recommending remediation. Maintain and update policy, process, and control documentation including SOC docs, SOPs, and procedure manuals. Coordinate with IT administrators, security teams, and customer contacts to collect evidence, validate controls, and prepare for external audits. Track compliance timelines, findings, and remediation for internal reviews and customer assessments. Prepare compliance reports, dashboards, and artifacts such as network diagrams and control matrices for stakeholders. Support implementation of security controls around AD, Azure, MDM, DLP, and EPP based on audit requirements.
Required Qualifications
- Bachelor's degree in IT, Computer Science, Cybersecurity, or related field
- 4–6 years of experience in IT infrastructure, security, or compliance, preferably in a services or MSP environment
- Strong understanding of IT compliance frameworks (e.g., PCI‐DSS, ISO 27001, SOC2, GDPR, DPDPA or similar)
- Strong understanding of Internal audit and gap‐analysis methodologies
- Strong understanding of IT infrastructure components (networking, servers, cloud, AD, identity, endpoint security)
- Experience in documentation, evidence collection, and preparing audit reports
- Ability to translate technical configurations into compliance language and evidence
- Excellent written and verbal communication skills to deal with internal teams, auditors, and customers
Desired Qualifications
- Certifications such as CISA, CISSP, ISO 27001 Lead Auditor, PCI QSA, or similar
- Prior experience participating in external audits or customer compliance reviews
- Familiarity with ticketing, GRC, or audit‐management tools
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.