Job Title: Assistant Manager | GRC | Pune | Cyber Strategy & Transformation
About the role
As a Cybersecurity GRC Consultant / Assistant Manager, this position plays an vital role to support the implementation and management of governance, risk, and compliance initiatives that safeguard the organization's information assets. This role involves assisting in the execution of cybersecurity policies, conducting risk assessments, participating in audits, and evaluating third-party risk. You will contribute to aligning business objectives with security best practices and regulatory standards such as ISO 27001, NIST, and ITGC. The position requires a foundational understanding of security frameworks and a collaborative approach to strengthening the organization’s cyber risk posture.
Key Responsibilities
· Assist in the design, implementation, and maintenance of cybersecurity GRC frameworks (ISO 27001, NIST, COBIT, etc.)
· Support the implementation of GRC frameworks (ISO 27001, NIST, COBIT) across various functions.
· Assist in drafting and updating cybersecurity policies, procedures, and control documentation.
· Conduct and document basic IT/cybersecurity risk assessments and internal control reviews.
· Maintain portions of the risk register and support the tracking of mitigation plans and KRIs.
· Assist in internal/external audit activities, including control testing and evidence collection.
· Perform initial third-party risk reviews and support due diligence documentation.
· Track audit findings and help monitor remediation efforts to closure.
· Contribute to compliance with global cybersecurity regulations (SOX, GDPR, DPDP, PCI-DSS).
· Help prepare GRC dashboards and reports for internal stakeholders.
· Collaborate with IT, legal, privacy, and compliance teams to support GRC initiatives.
· Stay current on regulatory changes and industry standards impacting cybersecurity.
· Support security awareness campaigns and participate in user training initiatives.
· Work with GRC tools (e.g., Archer, ServiceNow GRC, or Excel-based trackers) to manage workflows and data.
Qualifications
· Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or a related field
· 1–5 years of experience in GRC, IT audit, risk management, cybersecurity, or compliance roles.
· Foundational knowledge of IT control and compliance frameworks (ISO 27001, NIST, SOC 2, COBIT).
· Understanding of regulatory environments and compliance needs (e.g., GDPR, SOX, PCI-DSS, DPDP).
· Strong analytical, documentation, and communication skills.
· Willingness to learn and adapt in a fast-paced cybersecurity environment.
Certifications like ISO 27001 Foundation, CISA (beginner level), or CompTIA Security+ are a plus.