Talent.com
Senior Governance, Risk and Compliance Analyst (12-month contract)

Senior Governance, Risk and Compliance Analyst (12-month contract)

ConfidentialBengaluru / Bangalore, India
1 day ago
Job description

Company Description

Carousell Group is the leading multi-category platform for secondhand in Greater Southeast Asia on a mission to inspire the world to start selling, and to make secondhand the first choice. Founded in August 2012 in Singapore, the Group has a leading presence in seven markets under the brands Carousell, Cho Tot, Laku6, Mudah.my, OneShift, Ox Luxe, Ox Street, and Refash, serving tens of millions of monthly active users. Carousell is backed by leading investors including Telenor Group, Rakuten Ventures, Naver, STIC Investments and Sequoia Capital India.

As a team of passionate individuals working together to solve meaningful problems, there is so much more for you to discover in a career with Carousell. Our culture is made up of hiring, developing, and promoting people who embody our values of HEART, which is an acronym for Humility, Empathy, Accountability, Relentlessly resourceful and Teamwork. Together as an organisation, we make magic happen.

Job Description

We are seeking a seasoned Senior GRC Analyst to build, lead, and mature our IT Governance, Risk, and Compliance program. This is a pivotal role where you will be the primary architect of our new Sarbanes-Oxley (SOX) IT controls framework and will be responsible for establishing and leading the company's annual internal IT audit program.

This is a technical, hands-on role. You will not only design the control framework but also be expected to dive directly into our diverse systems (from SaaS platforms like Oracle Netsuite and Salesforce to CI / CD tools like Jenkins and Github) to verify configurations, analyze access controls, and retrieve audit evidence.

You will be responsible for designing and implementing a unified control framework that is both compliant and practical, bridging the gap between high-level financial reporting principles (COSO) and granular IT governance practices (COBIT) . This position is critical for establishing a resilient, transparent, and scalable control environment to support our growth and mature our IT governance function.

This role works closely with key stakeholders, including SaaS owners, Legal, Finance, CorpIT, Security Engineering, as well as external auditors. This is a high-impact position with a clear path for growth into team leadership for the right candidate.

Responsibilities :

  • Program Leadership & Strategy : Lead the development, documentation, and implementation of the SOX IT RACM Program. Proactively drive the IT control maturity milestones, advancing the program from an ad-hoc (Level 1) to a defined (Level 2) and implemented (Level 3) state .
  • Framework & Control Harmonization : Architect a unified control framework for both internally built and SaaS-based systems , ensuring all controls are mapped to both COSO principles and COBIT processes.
  • Framework Analysis : Lead control harmonization efforts by analyzing multiple frameworks (including ISO 27001, Cyber Trust Mark, and CCF) to identify common controls and streamline our compliance ambitions.
  • Internal Audit Leadership : Establish and lead the company's annual internal IT audit program. This includes developing the annual risk-based audit plan, performing and managing internal audits and assessments to evaluate the effectiveness of controls , and ensuring that all internal audit results are documented and re-usable for external audits. You will be the primary driver for reporting on control effectiveness to the Steering Committee and senior leadership.
  • Technical Control Validation & Audit : Act as a hands-on technical GRC expert. This includes :
  • Independently navigating in-scope systems (with temporary admin rights as needed) to find configuration settings, review access (roles, permissions, groups), and validate controls directly.
  • Analyzing authentication and access management (SSO, SAML, OAuth, IAM) to ensure they are implemented according to policy.
  • Understanding and auditing CI / CD pipelines, batch jobs , and incident management processes , using tools like Jira tickets and system audit trails as artifact evidence.
  • Stakeholder Remediation & Strategy : Lead GRC advisory and remediation sessions with SaaS and in-house system owners. You will be responsible for using ITGC evaluations (like the Controls Evidence Templates) to establish a control baseline, clearly communicate surfaced deficiencies, and collaboratively develop mid-term and long-term roadmaps to mitigate all identified risks.
  • Risk & Control Management : Establish and lead risk identification workshops to define and document the IT RACM for all SaaS and all in-scope systems. Collaborate with the Legal and Security teams to contribute to the wider Enterprise Risk Matrix (ERM) and ensure PII / data privacy risks are appropriately identified and controlled.
  • Audit & Stakeholder Management : Serve as the primary GRC liaison for all external and internal audits , ensuring audit readiness and effectively communicating the hybrid COSO / COBIT control approach.
  • Tooling & Governance : Lead the 'Tool Enablement' objective, including the selection and implementation of a GRC tool. Establish program governance, including a Steering Committee , and provide quarterly PMO updates.
  • Culture & Training : Develop and deliver training programs to build and foster a culture of trust, control, and accountability across all business systems.

Qualifications

  • Education : Bachelor's Degree (or equivalent) in Information Technology, Computer Science, IT Audit, or a related field.
  • Experience : 3-5+ years of progressive experience in IT Audit, IT Risk Management, or IT GRC.
  • SOX Expertise : Demonstrable, hands-on experience in building, implementing, and / or managing a SOX 404 IT controls program is essential.
  • Governance Frameworks : Expert-level knowledge and practical implementation experience with COSO (for ICFR) and COBIT (for ITGCs). Strong understanding of other frameworks like ISO 27001, Cyber Trust Mark, CCF, NIST, and PCI-DSS is also required.
  • Audit Experience : Deep experience in managing and responding to external audits, particularly SOC1.
  • Deep Technical Acumen (Mandatory) : The ideal candidate must be able to :
  • Demonstrate a strong understanding of modern authentication and authorization protocols (e.g., SSO, OAuth, SAML).
  • Understand Identity and Access Management (IAM) concepts, including roles, privileges, permissions, and the difference between default / built-in vs. custom accounts / groups .
  • Be technically proficient enough to navigate the configuration settings of diverse systems to find evidence.
  • Understand IT operations concepts, including batch jobs , incident management , and the use of ticketing systems (like Jira) and audit trails as evidence .
  • Automation & Learning Mindset (Highly Desired) : An aptitude for and keen interest in learning new technologies. We are a heavy user of GenAI and automation tools like n8n; a candidate who is comfortable and willing to build their own GRC automation workflows (e.g., for evidence collection) to bridge gaps pending a formal GRC tool, would be at a significant advantage.
  • Certifications : Professional certifications such as CISA, CRISC, CISM, or CGEIT are highly preferred.
  • Leadership & Program Management : Proven ability to manage complex projects, drive milestones, and lead cross-functional initiatives.
  • Communication Skills : Exceptional communication and presentation skills. Must have the ability to translate complex technical control requirements (the 'how') into business-friendly language (the 'what' and 'why') for stakeholders and leadership.
  • Independence : Ability to operate independently, think strategically, and effectively represent the GRC program across the organization.
  • Additional Information

    By proceeding with your application , you are adhering to our PDPA policies. In case you are interested to know more, read about our Candidates Personal Data Privacy Statement.

    Skills Required

    Iso 27001, Saml, Jira, COSO, Oauth, Cobit, Iam, nist, Sso

    Create a job alert for this search

    Risk And Compliance Analyst • Bengaluru / Bangalore, India

    Related jobs
    • Promoted
    Governance, Risk & Compliance Analyst

    Governance, Risk & Compliance Analyst

    SmarshBengaluru, Karnataka, India
    Smarsh empowers its customers to manage risk and unleash intelligence in their digital communications.Our growing community of over 6500 organizations in regulated industries counts on Smarsh every...Show moreLast updated: 2 days ago
    • Promoted
    Analyst - GRC (Governance, Risk & Compliance)

    Analyst - GRC (Governance, Risk & Compliance)

    AmagiBangalore Urban, Karnataka, India
    This role has been established to support the business in building sustainable governance andcompliance practices at Amagi. The basic factor required to be successful in this role warrants a good un...Show moreLast updated: 11 days ago
    • Promoted
    Senior Governance, Risk, and Compliance Analyst

    Senior Governance, Risk, and Compliance Analyst

    ConfidentialBengaluru / Bangalore, India
    Senior Governance, Risk and Compliance Analyst.At Arctic Wolf, we're not just navigating the cybersecurity landscape - we're redefining it. Our global team of dedicated Pack members is driving innov...Show moreLast updated: 6 days ago
    • Promoted
    Version 1 - Audit & Compliance Analyst

    Version 1 - Audit & Compliance Analyst

    Version 1 Services Private LimitedBangalore, India
    Version 1 has celebrated over 28 years in Technology Services and continues to be trusted by global brands to deliver solutions that drive customer success. Version 1 has several strategic technolog...Show moreLast updated: 30+ days ago
    • Promoted
    SAP Governance Risk and Compliance

    SAP Governance Risk and Compliance

    Randstad DigitalBengaluru, Karnataka, India
    Job Role : SAP Governance Risk and Compliance GRC.As an Application Developer, you will design, build, and configure applications to meet business process and application requirements.A typical day ...Show moreLast updated: 21 days ago
    • Promoted
    Senior Analyst Governance, Risk & Compliance

    Senior Analyst Governance, Risk & Compliance

    ConfidentialBengaluru / Bangalore
    Risk Management : Identify, assess, and mitigate risks related to compliance, security, and other relevant areas.Compliance Programs : Develop and implement compliance programs to ensure adherence to...Show moreLast updated: 30+ days ago
    • Promoted
    Amagi - Analyst - Governance / Risk & Compliance

    Amagi - Analyst - Governance / Risk & Compliance

    Amagi Media LabsBangalore, India
    This role has been established to support the business in building sustainable governance andcompliance practices at Amagi. The basic factor required to be successful in this role warrants a good un...Show moreLast updated: 14 days ago
    • Promoted
    Senior Process Analyst – Sox Audit

    Senior Process Analyst – Sox Audit

    Selections HR Services Private LimitedBengaluru, Republic Of India, IN
    Hiring : Senior Process Analyst – SOX Audit.Hybrid (1 week WFO, 3 weeks WFH).None (Occasional travel to US HQ may occur;. We are looking for a detail-oriented and driven.The ideal candidate will work...Show moreLast updated: 2 days ago
    • Promoted
    Senior Process Analyst – SOX Audit

    Senior Process Analyst – SOX Audit

    Selections HR Services Private LimitedBengaluru, Karnataka, India
    Hiring : Senior Process Analyst – SOX Audit.Hybrid (1 week WFO, 3 weeks WFH).None (Occasional travel to US HQ may occur; valid US visa preferred). We are looking for a detail-oriented and driven.The ...Show moreLast updated: 2 days ago
    • Promoted
    Senior Staff Security Governance & Compliance Analyst

    Senior Staff Security Governance & Compliance Analyst

    ConfidentialBengaluru / Bangalore, India
    Diligent is the AI leader in governance, risk and compliance (GRC) SaaS solutions, helping more than 1 million users and 700,000 board members to clarify risk and elevate governance.The Diligent On...Show moreLast updated: 6 days ago
    • Promoted
    Senior Analyst, Risk Mangement

    Senior Analyst, Risk Mangement

    RazorpayBengaluru, Karnataka, India
    This role requires strong knowledge and experience in Sanctions, AML (Anti-Money Laundering), and Financial Crimes.The position will focus on Customer Due Diligence (CDD), website assessment, risk ...Show moreLast updated: 2 days ago
    • Promoted
    Sap Governance Risk And Compliance

    Sap Governance Risk And Compliance

    Randstad DigitalBengaluru, Republic Of India, IN
    Job Role : SAP Governance Risk and Compliance GRC.As an Application Developer, you will design, build, and configure applications to meet business process and application requirements.A typical day ...Show moreLast updated: 21 days ago
    • Promoted
    • New!
    Governance, Risk & Compliance Manager

    Governance, Risk & Compliance Manager

    DIGILE TECHNOLOGIES PRIVATE LIMITEDBangalore
    About the Role : We are seeking a highly experienced Governance, Risk, and Compliance (GRC) Manager to lead our enterprise risk management and compliance initiatives...Show moreLast updated: 19 hours ago
    • Promoted
    Senior Compliance Analyst

    Senior Compliance Analyst

    ConfidentialBengaluru / Bangalore, India
    Signzy is a digital trust system.We provide identification, background checks, forgery detection.Our biometric user authentication system and blockchain-based digital trail.This increases complianc...Show moreLast updated: 6 days ago
    • Promoted
    Governance, Risk, and Compliance (GRC) Manager

    Governance, Risk, and Compliance (GRC) Manager

    DigileBengaluru, Karnataka, India
    We are seeking a highly experienced.Governance, Risk, and Compliance (GRC) Manager.The ideal candidate will have deep expertise in. HITRUST CSF, ISO 27001 : 2022, SOC 2 Type II, NIST 800-53.Financial ...Show moreLast updated: 2 days ago
    • Promoted
    Senior Analyst, Governance Risk and Compliance

    Senior Analyst, Governance Risk and Compliance

    ConfidentialBengaluru / Bangalore, India
    Saks Global is the largest multi-brand luxury retailer in the world, comprising Saks Fifth Avenue, Neiman Marcus, Bergdorf Goodman, Saks OFF 5TH, Last Call and Horchow. Its retail portfolio includes...Show moreLast updated: 5 days ago
    • Promoted
    Governance, Risk, And Compliance (Grc) Manager

    Governance, Risk, And Compliance (Grc) Manager

    DigileBengaluru, Republic Of India, IN
    We are seeking a highly experienced.Governance, Risk, and Compliance (GRC) Manager.The ideal candidate will have deep expertise in. HITRUST CSF, ISO 27001 : 2022, SOC 2 Type II, NIST 800-53.Financial ...Show moreLast updated: 2 days ago
    • Promoted
    Business Continuity Analyst (Operational Resilience, Governance, Key Risk Indicators)

    Business Continuity Analyst (Operational Resilience, Governance, Key Risk Indicators)

    ConfidentialBengaluru / Bangalore, India
    Visa is a world leader in payments and technology, with over 259 billion payments transactions flowing safely between consumers, merchants, financial institutions, and government entities in more t...Show moreLast updated: 6 days ago