Verified today
Senior / Principal GRC Analyst
About the role
GRC team at Altera builds enterprise governance, risk, and compliance programs for highly regulated, technology‑driven environments. The analyst architects, leads, and scales ISO/IEC 27001, ISO/IEC 42001, GDPR, CCPA/CPRA, and CMMC initiatives, translating technical security architectures into audit‑ready, business‑aligned compliance outcomes. Based in Bengaluru, India, the role is on‑site with a focus on cross‑functional collaboration and AI‑enabled compliance tooling.
What you’ll do
- Define and maintain risk‑based GRC architecture aligned to ISO, NIST, privacy, and regulatory requirements
- Lead end‑to‑end implementations of ISO/IEC 27001, ISO/IEC 42001, GDPR, CCPA/CPRA, and CMMC/NIST SP 800‑171
- Translate security architectures and technical controls into compliant policies, standards, and evidence
- Lead enterprise, third‑party, cloud, and AI‑specific risk assessments
- Serve as primary interface for auditors, assessors, regulators, customers, and partners
- Drive efficiency using GRC platforms, security telemetry, and AI‑assisted compliance tooling
- Mentor junior GRC professionals and influence cross‑functional teams without direct authority
What you’ll bring
- 7–12+ years GRC, security, privacy, or risk management
- ISO 27001 Lead Implementer / Lead Auditor
- CISSP, CISA, CRISC
- Experience with Microsoft security and compliance platforms
Nice to have
- ISO 27001 Lead Implementer / Lead Auditor
- CISSP
- CISA
- CRISC
- CIPM
- CIPP/US
- CIPP/E
- Microsoft Purview, Defender, Entra ID