Open Positions: 2
Location: Mumbai
Employment Type: Full-Time
Job Description
We are hiring GRC (Governance, Risk & Compliance) Analysts with 4-5 years of experience. The ideal candidate should have a basic understanding of information security, risk management, compliance frameworks, and cybersecurity policies.
Responsibilities
- Serve as the primary administrator and subject matter expert for Tenable Security Center, Nessus Manager, and Nessus Agents.
- Taking care of all patching and upgrades for Tenable.SC as and when needed after testing.
- Lead upgrades, migrations, plugin management, scanner deployment, and high-availability planning.
- Troubleshooting any issues that arise within the Tenable SC.
- Ensures that regular backups along with test restores are in place to ensure high availability.
- Familiarity with CVE, CVSS scoring, exploitability concepts, and vulnerability classification.
- Build and optimize the scan policies based on regulatory, compliance, and organizational security requirements and support on challenges while running those on required assets.
- Work closely with scanning teams (Windows, Linux, Network, DB, MW, Security Devices and Firewall) to address their new scan policy requirements.
- Build and manage custom scripts for generating reports in the required regulatory format, primarily using Python.
- Support for integration of the Tenable SC with various tools such as ServiceNow, CyberArk , Ansible , Active Directory etc.
- Automate vulnerability workflows using APIs, scripting (Python/PowerShell), and orchestration tools.
- Provide technical guidance to scanning teams for complex or high-risk vulnerabilities along with suggestions and recommendations for fixes wherever needed.
- Availability of support during weekends as needed.
Requirements
- 4-6 years of experience in GRC, Information Security, Risk, or Compliance.
- Basic understanding of ISO 27001, SOC 2, PCI-DSS, or similar frameworks.
- Good documentation and communication skills.
- Strong analytical and organizational abilities.
- Bachelor's degree in IT, Cybersecurity, or a related field.
Preferred
- Relevant certifications or training in cybersecurity, risk, or compliance.
Pay: ₹15,000.00 - ₹20,000.00 per week
Benefits:
- Leave encashment
- Paid sick time
Work Location: In person