+ Post Job +
Home Cybersecurity

Senior GRC Analyst

📍 mohali 🏷️ Cybersecurity 💰 ₹126,000 / month
An IT City, Sector 82 employer in Mohali is hiring a Senior GRC Analyst, full-time and on-site, with pay up to ₹1,26,000 a month. The hiring team is working from a baseline of 66 months of relevant governance, risk, and compliance experience. The seat opened up after the previous analyst moved into a broader risk management role internally, so this isn't a brand-new position but one with an established set of ongoing audits already attached to it.

Requirements

A bachelor's degree is expected, typically in cybersecurity, information technology, or a related field. Alongside the degree, candidates need a recognized security certification; either CEH or CompTIA Security+ satisfies this requirement. Sixty-six months of hands-on experience in a GRC or broader security compliance function is standard for this level, most of it spent working directly with audits, risk registers, or control frameworks rather than adjacent IT work. The certification and years of experience stand in for a working knowledge of how compliance actually gets done inside a company, beyond reading a policy document and understanding it. Someone at this level should be able to walk an auditor through a control gap and explain, without notes, why it happened and what's being done about it. A recent example from a comparable team: a vendor's data retention practice didn't match what was documented in the contract, and closing that gap took three weeks of back-and-forth between legal, procurement, and the vendor itself. That kind of cross-team coordination is routine, not an exception.

What the role covers day-to-day

  • Maintain and update risk registers, tracking new and existing risks against agreed tolerance levels
  • Support internal and external audits, including gathering evidence and coordinating responses across departments
  • Map existing controls against frameworks such as ISO 27001, SOC 2, or similar, and flag where gaps exist
  • Contribute to incident response from a compliance and reporting angle, documenting what happened and what controls were affected
  • Draft and revise internal policies so they reflect current practice rather than outdated procedure
Vendor risk reviews come up often enough to mention separately. New vendors get assessed before onboarding, and existing ones cycle through reassessment on a rolling schedule, so a meaningful slice of the role involves reading contracts and flagging clauses that don't line up with how the vendor actually operates. Much of this work involves translation. Engineers describe a system change in technical terms, and part of the job is figuring out what that means for a control that an auditor will ask about six months later. It's not glamorous, and a good chunk of any given week goes into documentation that nobody reads until something goes wrong and someone needs proof it was handled correctly. Turnaround on that documentation matters more than people expect, since an incomplete record during an active audit can hold up a certification renewal by weeks.

Core and nice-to-have skills

Governance, risk, and compliance frameworks are the backbone of the role, alongside solid risk assessment skills and the discipline to keep documentation accurate as things change. Beyond that baseline, a few things will strengthen an application without being mandatory. None of these are dealbreakers on their own, but a candidate with two or three tends to need less ramp-up time on the audit calendar this team is already running against.
  • Familiarity with a GRC platform such as ServiceNow GRC or Archer
  • An additional certification like CISA, CRISC, or ISO 27001 Lead Auditor
  • Exposure to vulnerability assessment tools, even if that wasn't the core part of a previous role
  • Experience working directly with external auditors rather than only preparing materials for someone else to present

Team and working style

The compliance function sits close to security operations, and the two teams meet weekly to review open findings. One of the senior analysts already on the team was hired through Naukri Mitra for a nearly identical role a couple of years back, and she usually sits in on the second interview round for this seat. Expect a fair amount of independent work punctuated by meetings that run longer than scheduled, since audit conversations rarely wrap up on time.

Compensation and benefits

  • Salary up to ₹1,26,000 per month
  • Health insurance
  • Paid time off
  • Performance-linked bonuses
  • Relocation assistance and accommodation support for candidates moving to Mohali
Candidates comparing GRC analyst salary in Mohali per month figures across the IT City corridor will find this one sits comfortably at the senior end, in line with the certification and experience bar attached to it. Bonuses are reviewed annually rather than quarterly, tied to audit outcomes and how cleanly a given certification cycle closed out.

Location and how to apply

This is an on-site role based in IT City, Sector 82, so daily presence is expected rather than a hybrid arrangement. Anyone reviewing GRC analyst jobs for experienced professionals in Mohali will find the seniority and pay band reflect genuine leadership expectations within the compliance function, not just a title bump. The role reports to the head of compliance, who splits time between this office and a smaller satellite location, so a portion of the week will involve running things independently without a manager physically present. Apply with a resume that details specific audit cycles or frameworks you've worked with, rather than a general list of compliance duties. If you've led a remediation effort from finding to closure, mention it directly, since that kind of ownership is exactly what this role is built around. Shortlisted candidates should expect two rounds: one technical conversation covering frameworks and past audit work, and one with the security operations lead to see how the two teams would work together day to day. Together, both rounds usually take a little over a week from the initial screen, and offers tend to go out within a few days of the final conversation rather than sitting in a longer approval queue.
Apply Now