Neorealm Solutions Logo

Neorealm Solutions

5+ Yrs - Bengaluru Only - IT Governance, Risk & Compliance (GRC) Specialist

Posted 11 Days Ago
Be an Early Applicant
In-Office
Bengaluru North, Yelahanka, Bengaluru Urban, Karnataka, IND
Senior level
In-Office
Bengaluru North, Yelahanka, Bengaluru Urban, Karnataka, IND
Senior level
Manage IT governance, risk, and compliance programs across NIST, ISO, privacy, and security frameworks. Coordinate audits, collect evidence, track remediation, conduct IT risk assessments, and manage third-party vendor risk. Develop and improve security controls, policies, and governance processes while monitoring compliance metrics. Collaborate with IT, Security, Product, and Business stakeholders to embed compliance into operations and support continuous information security and regulatory improvements.
The summary above was generated by AI

Job Overview

We are seeking an experienced IT Governance, Risk & Compliance (GRC) Specialist to drive information security, compliance, audit readiness, and risk management initiatives across the organization.

The ideal candidate will have hands-on experience managing compliance programs aligned to NIST CSF 2.0, ISO 27001:2022, GDPR, DPDP Act, Third-Party Risk Management (TPRM), and related security frameworks. This role will work closely with IT, Security, Product, and Business teams to strengthen governance practices, manage audits, mitigate risks, and support continuous compliance improvements.



Requirements

Key Responsibilities

• Manage IT compliance and security governance programs including NIST CSF 2.0, ISO 27001:2022, GDPR, DPDP Act, and related frameworks.

• Coordinate internal and external audits, including evidence collection, auditor engagement, remediation tracking, and closure of findings.

• Conduct IT risk assessments and support enterprise risk management initiatives.

• Manage Third-Party Risk Management (TPRM) activities including vendor assessments, security questionnaires, risk scoring, and ongoing monitoring.

• Support development, implementation, and continuous improvement of security controls, policies, and governance processes.

• Collaborate with IT, Security, Product, and Business stakeholders to ensure compliance requirements are effectively embedded into operational processes.

• Track compliance metrics, risks, audit observations, and remediation activities.

• Support continuous improvement initiatives related to information security, risk management, and regulatory compliance.

Required Skills & Qualifications

• 5+ years of experience in IT Audit, IT Risk, Information Security, Governance Risk & Compliance (GRC), or related domains.

• Strong understanding of IT General Controls (ITGC), security controls, compliance programs, and data protection requirements.

• Experience managing internal and external audits, control testing, audit evidence collection, and remediation tracking.

• Hands-on experience with Third-Party Risk Management (TPRM), vendor assessments, security reviews, and risk evaluation processes.

• Working knowledge of:

  • NIST CSF 2.0
  • NIST SP 800-53
  • ISO 27001:2022
  • GDPR
  • DPDP Act

• Understanding of cloud environments (AWS preferred), SaaS platforms, and modern technology architectures.

• Excellent stakeholder management, communication, and documentation skills.

• Strong analytical, risk assessment, and problem-solving capabilities.

• B.E. / B.Tech in Computer Science, Information Technology, or related discipline.

Preferred Qualifications

• Prior experience in Security Engineering or Application Security before transitioning into GRC.

• Experience within Banking, Fintech, Insurance, Payments, or other regulated industries.

• Big 4 consulting experience in IT Risk Advisory, Cyber Risk, Audit, or Compliance.

• Professional certifications such as ISO 27001 Lead Implementer/Auditor, CISA, CRISC, CISSP, CISM, or equivalent are highly desirable.



Benefits
  • Opportunity to work on enterprise-wide Information Security, Compliance, and Risk Management initiatives.
  • Hands-on exposure to NIST CSF 2.0, ISO 27001:2022, GDPR, DPDP Act, and Third-Party Risk Management programs.
  • Collaboration with Security, Product, Engineering, and Compliance leadership teams.
  • High-impact role with visibility across audit, governance, and risk functions.
  • Flexible and fast-paced work environment.
  • Potential for contract extension based on performance and business requirements.


  • Similar Jobs

    7 Hours Ago
    Hybrid
    Bengaluru, Bengaluru Urban, Karnataka, IND
    Senior level
    Senior level
    Fintech • Financial Services
    Supports commercial loan closing by reviewing and uploading loan data, completing complex legal documentation, ensuring compliance with bank policies and regulatory requirements, and coordinating with Credit, Sales, Legal, and internal teams. Provides subject matter expertise, supports less experienced staff, interprets procedures, and recommends process and tool improvements.
    7 Hours Ago
    Hybrid
    Bengaluru, Bengaluru Urban, Karnataka, IND
    Entry level
    Entry level
    Fintech • Financial Services
    Provides commercial loan servicing support across commercial, real estate, and problem-loan portfolios. Resolves customer and operational issues, maintains and validates loan data in Loan IQ, performs regulatory and documentation diligence, manages portfolio records, and escalates matters as needed. The role requires sound risk judgment, compliance with bank policies, stakeholder coordination, process improvement, and the ability to guide peers in a high-volume environment.
    Top Skills: Loan Iq
    7 Hours Ago
    Hybrid
    Bengaluru, Bengaluru Urban, Karnataka, IND
    Junior
    Junior
    Fintech • Financial Services
    Support securities operations across client onboarding, cash payments, funding, custody, settlement, structured loans, and ledger reconciliation. Review transactions, resolve operational issues, monitor daily production, assess risks, recommend process improvements, and help implement new procedures. Collaborate with internal and external stakeholders while ensuring compliance with trade workflow controls and timely handling of sensitive documents and transaction requests.

    What you need to know about the Bengaluru Tech Scene

    Dubbed the "Silicon Valley of India," Bengaluru has emerged as the nation's leading hub for information technology and a go-to destination for startups. Home to tech giants like ISRO, Infosys, Wipro and HAL, the city attracts and cultivates a rich pool of tech talent, supported by numerous educational and research institutions including the Indian Institute of Science, Bangalore Institute of Technology, and the International Institute of Information Technology.

    Sign up now Access later

    Create Free Account

    Please log in or sign up to report this job.

    Create Free Account