Xceedance
Website:
xceedance.com
Job details:
Experience Required: 5–8 Years
Location: Gurgaon/ Noida
Role: GRC Consultant
Security Questionnaire Manageme
nt· Serve as the single point of coordination for client-issued IT security/compliance questionnaires — cyclic and bi-annual in natur
e.· Log incoming requests from the shared distribution mailbox, loop in the account manager, and set/manage the standard ~60-day turnaround commitment to client
s.· Route each questionnaire to the corporate Security Compliance team, who own roughly 90% of standard responses, and independently coordinate with business subject-matter experts to complete the remaining client- or business-specific question
s.· Maintain the Received / Working / Sent folder structure and the historical SharePoint response repository; reuse and adapt previously validated answers to maintain consistency and speed of turnaroun
d.· Cross-check current-cycle responses against prior submissions for the same client, flag inconsistencies or outdated answers, and escalate ambiguous or sensitive items for review before final submissio
n.Access Recertification Manageme
nt· Coordinate the semi-annual access recertification cycle (for H1 typically starting January/February and completing through June, aligned with SOX audit timing) covering in-scope applications and shared-data security object
s.· Confirm application inventory and scope with application owners; submit and track data-pull requests to the Security Administration team via the internal ticketing syste
m.· Consolidate and clean raw access-extract data (application ownership details, AD extracts, user profiles) into a standardized Excel workbook, using macros, formulas, and pivot tables to de-duplicate entries and merge rows where necessary (with multi-group access details
).· Load the consolidated dataset into SharePoint, distribute recertification requests to business and IT reviewers, and track review decisions through to completio
n.· Compile audit-ready evidence packages (timestamps, reviewer decisions, access-removal confirmations) to support internal IT audit and SOX audit requirement
s.· Coordinate with Legal, HR, or other business stakeholders as needed for non-standard questionnaire items and escalate unique/new/non-standard client audit requests to senior team member
s.Additional Activiti
es· Coordinate mandatory bi-annual security/privacy awareness training for employees and consultants with access to personal information — working with HR and the employee talent portal and managing SharePoint acknowledgment surveys or vendor points of contact for consultant population
s.· Support the annual BCP/DR test cycle: confirm test dates with application owners, ensure business tester availability, track communications, and document test outcomes and remediation ownershi
p.REQUIRED SKILLS & QUALIFICATIO
NS· Bachelor's degree in either Comp Science, Information Systems, Information Security, Privacy, Risk Management, IT/Information Systems Business Administration or a related fiel
d.· Overall 5+ years of experience with 3–5 years of experience in GRC coordination, compliance operations, IT audit/vendor-risk support, client assurance, and with project coordination roles; deep technical security background is not require
d.· Advanced Excel skills, including documentation, pivot tables, macros, formula-based reconciliation, and large-dataset consolidation/cleanu
p.· Strong working knowledge of MS Word, SharePoint, and shared-drive documentation management practice
s.· Excellent written and verbal English communication skills, with confidence handling client-facing as well as internal leadership correspondenc
e.· Demonstrated ability to coordinate across cross-functional stakeholders — IT, Security, Legal, HR, Business, and third-party vendors etc. and drive follow-ups to closur
e.· High attention to detail and consistency when validating recurring or comparative data set
s.· Ability to handle sensitive, PII-adjacent information responsibly and maintain confidentiality (the role does not require direct access to client applications or systems
).· Availability to overlap with US Eastern Time hours (through at least 12:00 PM ET) for real-time collaboration with the client teams/stakeholder
s
.
PREFERRED ATTRIBUT
ES· Familiarity with vendor/third-party risk concepts (e.g., SIG questionnaires) is an advantage; formal GRC or security certifications are good to have but not mandatory for this rol
e.· Prior experience supporting insurance, reinsurance, or financial services client
s.· Experience with GRC tools, security questionnaire platforms, audit evidence repositories, or workflow tracking tools is an advantag
e.· Good understanding of information security, privacy, risk, access management, business continuity, and compliance concepts; familiarity with ISO 27001, ISO 27701, SOC/SOC 2, NIST, GDPR, HIPAA etc. or client audit requirements is preferre
d.· Certifications such as ISO 27001 Foundation/Internal Auditor, ISO 27701, ISO/IEC 27001:2022 LI or LA, CISA, CRISC, or equivalent are good to hav
e.· Self-driven with strong ownership; comfortable ramping up through an apprenticeship/knowledge-transfer period alongside the client team before working semi-independentl
y.· Comfortable in a coordination-heavy role with cyclical rather than constant workload peaks, and able to flex into ad hoc requests as they aris
e.ROLE FOC
- USThis role is focused on client security assurance, questionnaire and access-recertification coordination, security awareness and training facilitation, BCP/DR facilitation and management, documentation management, and cross-functional stakeholder follow-up — however not on hands-on technical security wor
k.
Click on Apply to know more.