GRC Specialist

Bengaluru | Full-time

Apply

About the Role

GRC Specialist to execute the day-to-day work that keeps our compliance and risk programs running — from responding to customer security questionnaires to supporting audits and assessing vendor risk. You'll work closely with Engineering, IT, Sales and Customer Success to turn security and compliance requirements into clear, evidenced answers, while the GRC Lead sets overall program strategy and priorities.

Key Responsibilities

  • Customer RFP & Security Questionnaire Response — Own end-to-end responses to inbound customer RFPs, RFIs, and CAIQs, coordinating with internal teams to gather accurate, evidence-backed answers that support sales and customer success deal cycles.
  • Risk Assessment & Management — Conduct risk assessments and control validation testing against frameworks such as SOC 2, ISO 27001, and NIST; maintain the risk register, score identified risks, and track treatment items through to closure.
  • Audit & Compliance Support — Support the full lifecycle of SOC 2 and ISO 27001 audits, including evidence collection, control walkthroughs, and remediation tracking, in coordination with internal stakeholders and external auditors.
  • Third-Party & Vendor Risk Management — Conduct vendor security assessments and review vendor questionnaire responses to evaluate third-party risk posture.
  • Trust Centre Maintenance — Keep customer-facing certifications, policies, and security documentation current and accurate.
  • Cross-Functional Coordination — Partner with Engineering, IT, Legal, and Privacy teams to resolve findings and validate control implementations.
  • Metrics & Reporting — Track and report on risk, incident, vulnerability, and control metrics, clearly explaining changes and next steps to stakeholders.

Required Qualifications

  • 4–5 years of experience in a GRC, IT audit, information security, or compliance-related role.
  • Working knowledge of security and compliance frameworks (SOC 2, ISO 27001, GDPR, PCI DSS, or similar).
  • Experience with GRC tooling (e.g., Scrut/Vanta/Drata) 
  • Strong written communication skills — able to translate technical controls into clear answers for customers and auditors.
  • Comfort managing multiple concurrent requests under deal-cycle timelines.

Preferred Qualifications

  • Certifications such as ISO 27001 Lead Implementer/Auditor.
  • Prior experience responding to customer security questionnaires in a SaaS environment.
  • Familiarity with IT/cloud infrastructure (AWS/Azure/GCP) and vendor risk assessment methodologies.