Senior Security Grc Analyst

Rubrik Rubrik · Enterprise · Bangalore, India · Information Security

Senior Security GRC Analyst role focused on maintaining and automating security compliance frameworks (SOC2, ISO 27001, HIPAA), coordinating audits, managing evidence collection, and partnering with engineering teams to close security gaps. Requires expertise in GRC, risk management, and various security standards.

What you'd actually do

  1. Maintain global compliance certifications, including ISO 27001, SOC2, BSI C5, Cyber Essentials, DESC, and evolving data privacy standards.
  2. Serve as the primary liaison for internal and external audits; manage timelines, evidence collection, and communication between process owners and auditing bodies.
  3. Partner with cross-functional teams (risk, governance, sec-ops, etc.) to identify control gaps, prioritise remediation efforts, and implement scalable solutions that reduce organisational risk
  4. Systematise the collection and retention of audit evidence to ensure the organisation is audit-ready at all times without disrupting daily operations..
  5. Experience in conducting a common controls framework, which shall be required to assess control effectiveness and evidence to support in defining security posture and compliance

Skills

Required

  • Information Security Governance, Risk and Compliance (GRC)
  • Compliance roles in the tech industry
  • security and operational risk processes
  • risk quantification principles
  • FAIR-like approaches
  • common security risks, vulnerabilities, and threats
  • ISO 27001/2
  • FedRAMP
  • SOC 2
  • CIS Top 20
  • PCI DSS
  • NIST CSF
  • HIPAA
  • audit and risk management methodologies
  • SOX
  • COBIT
  • NIST RMF
  • data analytics and BI tools (e.g., Power BI)
  • agile project management tools (e.g., Jira)
  • Executive presence
  • build consensus
  • Detail-oriented
  • technical expertise
  • problem-solving abilities
  • prioritise and manage blocking issues
  • ramp up quickly
  • learn new technologies
  • discuss issues at technical and business levels
  • Bachelor's degree in Security, Computer Science, or related field
  • CISA
  • CISM
  • CRISC
  • CGEIT
  • CISSP
  • high-growth SaaS and data management industries
  • Information Technology
  • Information Security
  • Information Security Compliance and/or Auditing
  • ISO 27001
  • SOC2
  • HIPAA
  • HI-TRUST
  • BSI C5
  • Cyber Essentials
  • DESC
  • EU-US Privacy Shield
  • manage multiple projects
  • deliver quality work to deadlines
  • development and management of a comprehensive compliance program
  • interpersonal, verbal, and written communication skills
  • communicate compliance-related concepts
  • working with internal audit
  • external auditors
  • outside consultants

Nice to have

  • Master's degree preferred
  • Experience in high-growth SaaS and data management industries is a plus

What the JD emphasized

  • audit-ready
  • security compliance framework
  • common controls framework
  • security controls