GRC Analyst

  • Karachi, Pakistan
  • Full-Time
  • On-Site

Job Description:

Karachi Based Job!!

We are looking for an experienced GRC Analyst to support our US-based clients. The ideal candidate must have hands-on experience with US compliance and cybersecurity frameworks, and hold relevant industry-recognized certifications.

- Position: GRC Analyst (Certified – Mandatory)

- Experience: 4–5 years

- Employment Type: Full-Time

- Work Model: Onsite (6 PM to 3 AM Pakistan Time)

- Office location: NASTP, Shahrah-e-Faisal, Karachi.

Key Responsibilities:

- Conduct enterprise-level risk assessments and maintain risk registers.

- Develop and implement security policies aligned with US compliance standards.

- Support compliance programs for SOC 2, NIST, CMMC, HIPAA, PCI DSS, and ISO 27001.

- Coordinate internal and external audits.

- Perform third-party/vendor risk assessments.

- Track remediation efforts and ensure timely closure.

- Support clients in certification readiness and audit preparation.

Mandatory Certifications (At Least One Required):

- CISA, CISM, CISSP, CRISC, ISO/IEC 27001 Lead Auditor (LA), ISO/IEC 27001 Lead Implementer (LI), PCI-QSA

Other Requirements:

- Bachelor's degree in Cybersecurity, Information Security, IT, or related field

- Proven experience in Information Security Governance, Risk, Compliance and Security auditing.

- Experience working with US-based regulatory and compliance frameworks preferred.

- Strong documentation, reporting, and client communication skills

- Ability to work independently with US stakeholders.

Benefits

- Hands-on exposure to US-based clients and international cybersecurity operations.

- Opportunity to learn and adapt to advanced US cybersecurity practices, frameworks, and threat landscape.

- Collaboration with experienced cybersecurity professionals and global teams.

- Opportunity to work on GRC and security audit automation and improve operational efficiency.
- Company-sponsored certifications and ongoing professional development opportunities.

- Unlimited lab access for hands-on learning and technical skill enhancement.

Kick off your journey with the best Cybersecurity Firm!!