Skip to content

Senior Analyst – GRC & Privacy

Techdefence LabsMumbai, MH, India · Ahmedabad, GJ, IndiaJuly 29, 2026
On-site
Full-time
GRC
Senior · 3–8 yrs

Job Title: Senior Analyst – GRC & Privacy

Company: TechDefence Labs Solutions Ltd.

Location: Mumbai & Ahmedabad

Department: Information Security Compliance (GRC)

Employment Type: Full-Time, Onsite

Position Overview

TechDefence Labs Solutions Ltd. is seeking an experienced and highly skilled Senior Analyst – GRC & Privacy to lead and manage enterprise-wide Governance, Risk, Compliance, and Data Privacy programs. The ideal candidate should have strong hands-on knowledge of cybersecurity governance and compliance frameworks, along with a solid understanding of Vulnerability Assessment and Penetration Testing (VAPT), Security Information and Event Management (SIEM), and Security Operations Center (SOC) processes.

The candidate will independently drive the implementation of security frameworks, regulatory assessments, cybersecurity risk assessments, privacy initiatives, and GRC programs while ensuring alignment with organizational, regulatory, and client requirements.

Key Responsibilities

  • Provide expert consulting on global standards and regulatory frameworks including ISO/IEC 27001, SOC 2, NIST, DPDP Act, PDPL, GDPR, and relevant CERT-In guidelines.
  • Lead end-to-end implementation and compliance initiatives for ISO/IEC 27001, SOC 2, and NIST frameworks for clients.
  • Develop and maintain comprehensive documentation including policies, governance frameworks, SOPs, process flows, risk treatment plans, and compliance reports.
  • Conduct detailed cybersecurity risk assessments for ICT assets, including networks, servers, applications, cloud infrastructure, endpoints, and critical information systems.
  • Demonstrate strong knowledge of VAPT requirements and processes, including vulnerability assessment methodologies, penetration testing requirements, scope definition, rules of engagement, vulnerability classification, risk ratings, technical reports, remediation recommendations, and closure validation.
  • Understand and evaluate VAPT reports, identify security risks and control gaps, track remediation activities, and ensure appropriate closure of identified vulnerabilities.
  • Conduct vendor/third-party risk assessments, due diligence, gap assessments, and continuous monitoring based on ISO/IEC 27001 Annex A, SOC 2 Trust Services Criteria, NIST, and GDPR requirements.
  • Independently execute Business Impact Analysis (BIA) and Privacy Impact Assessments (PIA).
  • Demonstrate working knowledge of SIEM solutions and Security Operations Center (SOC) functions, including security monitoring, log management, alert generation, incident detection, escalation, incident response, threat monitoring, and security event analysis.
  • Understand the integration of SIEM, SOC, EDR/XDR, DLP, vulnerability management, and other security tools within an organization's cybersecurity operations.
  • Collaborate with IT, Engineering, HR, Legal, Finance, Sales, Admin, and other departments for compliance readiness and evidence collection.
  • Perform internal audits, document findings, track corrective actions, and prepare reports for senior leadership and audit committees.
  • Maintain risk registers, compliance dashboards, audit trackers, and executive summaries aligned with regulatory and framework requirements.

Required Experience & Skills

  • 3 - 8 years of relevant experience in Governance, Risk & Compliance, Information Security, Cybersecurity, and Privacy Management.
  • Hands-on experience implementing and auditing frameworks such as ISO/IEC 27001, SOC 2, NIST CSF/800-53/800-171, PCI-DSS, GDPR, DPDPA, and PDPL.
  • Strong understanding of VAPT concepts, requirements, methodologies, vulnerability management, penetration testing processes, VAPT reporting, risk ratings, remediation, and vulnerability closure validation.
  • Ability to understand and interpret VAPT findings and reports and map identified vulnerabilities to cybersecurity risks and compliance requirements.
  • Good knowledge of SIEM platforms, SOC operations, security monitoring, incident detection, alert triaging, log analysis, incident response, and escalation processes.
  • Understanding of Patch Management, Incident Management, Change Management, Configuration Management, Vulnerability Management, and Security Operations.
  • Working knowledge of operating systems, network security, application security lifecycle, cloud security, EDR/XDR, SIEM, SOC, DLP, and cryptographic controls.
  • Strong understanding of cybersecurity controls and their implementation across IT infrastructure, applications, networks, endpoints, and cloud environments.
  • Familiarity with GRC and privacy tools such as ServiceNow, RSA Archer, OneTrust, and MetricStream.
  • Strong analytical, documentation, communication, audit, and technical reporting skills.

Job Details

Experience

Senior · 3–8 yrs

Tools & Tech

ServiceNow