GRC Consultant
Help regulated organisations turn obligations into controls that operate, owners who answer for them and evidence that is ready before the auditor asks.
- Location
- Hyderabad
- Practice
- Governance, Risk and Compliance
- Type
- Full time
- Experience
- 3 to 7 years
- Posted
- September 2026
Compliance that is a state our clients are in, not a season they prepare for.
Our Governance, Risk and Compliance practice works with organisations that answer to the DPDP Act, to RBI, SEBI and IRDAI directions, to CERT-In directions and to their own boards. Too often their compliance is assembled under deadline: a risk register that lists incidents instead of assets, controls that exist only on paper, and a war room before every audit. We replace that with a system that runs every day.
You will lead that work with the client: agree the scope, identify what matters and who owns it, map every obligation to a control and every control to evidence, and report risk in terms a board can act on. We prepare organisations for certification and for audits by empanelled auditors; we never claim to certify them.
What you will do
- Run ISO/IEC 27001:2022 readiness and maintenance: scope, risk assessment, statement of applicability, control operation, internal audit and management review.
- Map regulatory obligations, including the DPDP Act, RBI, SEBI and IRDAI directions and CERT-In directions, to the controls a client actually runs, each with an owner and a source of evidence.
- Build asset inventories and classification schemes with named business, technical, data, control and risk owners.
- Maintain risk registers tied to assets and business consequence, and prepare board reporting that shows exposure, ownership and progress.
- Test whether controls operate, not only whether policies exist, and track every exception to closure.
- Design continuous evidence collection with client teams, automated where their systems allow.
- Prepare clients for external audits and help them remediate what those audits find.
- Where AI use creates obligations, map them to policy and to the signed evidence Rhinexa Niyantran produces.
What you bring
- Hands-on experience implementing or maintaining an ISO/IEC 27001 management system, including risk assessment and internal audit.
- Working knowledge of Indian information and cyber security regulation (the DPDP Act, RBI, SEBI and IRDAI directions, CERT-In directions) and the ability to read a new direction and map it to controls.
- Enough grounding in security controls (identity and access, logging and monitoring, vulnerability management, backup and recovery, third-party risk) to challenge evidence, not just file it.
- The confidence to run workshops with business, technology and risk owners, and to turn what you hear into a register, a plan and a date.
- Clear written English: policies people follow and summaries a board reads.
Useful, not essential
- ISO/IEC 27001 Lead Implementer or Lead Auditor, CISA, CISM, CRISC or CDPSE.
- Experience with SOC 2, PCI DSS, ISO/IEC 27701, ISO/IEC 42001 or the NIST Cybersecurity Framework 2.0.
- Sector experience in financial services, healthcare or a global capability centre.
- Scripting or GRC tooling used to automate evidence collection.
What happens after you apply.
Rhinexa never asks candidates for payment at any stage. Report any such request to us.
Application
We review every application and reply either way.
Conversation
A call with the hiring lead about the role and your experience.
Practical
A practical exercise relevant to the work, discussed with the team.
Offer
References, offer and a planned first month.