AI Jobs Map

Accordion India · Hyderabad, Telangana, India

Accordion India - Associate - IT Risk and Compliance

mid_levelfull timePosted yesterday
Apply on LinkedInLinkedInOpens the original posting. AI Jobs Map never asks for your details.

Stack mentioned

cybersecuritygdprhipaasoc2exceliso-27001google-sheets

Job description

Company Overview (Accordion | The Leader in Private Equity Consulting | Office of the CFO)

There’s a better way to work in finance—and more specifically, a better way to unlock value potential in private equity-backed portfolio companies. Working at the intersection of sponsors and management teams across every stage of the investment lifecycle, our team provideshands-on, execution-oriented supportto elevate the office of the CFO.

So, what does it mean to work at Accordion? It means joining1,000+ finance & technology experts in a high-growth, agile, and entrepreneurial environment while changing the way portfolio companies drive value. It also means making your mark on Accordion’s future—by embracing a culturerooted in collaboration and a firm-wide commitment to building something great, together.

Accordion is headquartered in New York City with 10 offices worldwide, including the India office based out of Hyderabad. Join us and make your mark on our company.

Location: Hyderabad

Role Overview

The Associate is responsible for supporting the Governance, Risk, and Compliance (GRC) function in implementing and maintaining information security, regulatory compliance, risk management, and internal audit programs. The role will support the organization’s compliance with ISO27001:2022 and other applicable regulatory and industry requirements, assist with risk assessments and internal audits, maintain compliance documentation and evidence, and coordinate with business and technology teams to ensure timely completion of GRC activities.

The role requires strong attention to detail, analytical ability, effective communication, and a willingness to learn and work across multiple GRC and information security frameworks.

Key Responsibilities

ISO 27001:2022Compliance

- Support the implementation, maintenance, and continual improvement of the ISO 27001:2022 Information Security Management System (ISMS).

- Support the collection, review, organization, and maintenance of evidence required for ISO 27001 certification and surveillance audits.

- Coordinate with control owners to obtain required compliance evidence within defined timelines.

- Assist in monitoring the implementation and effectiveness of ISO 27001 controls.

- Assist with preparation for internal and external ISO 27001 audits.

- Track audit observations, non-conformities, corrective actions, and improvement opportunities.

- Support information security awareness and compliance training activities.

Risk Management

- Support the GRC team in identifying, assessing, documenting, and monitoring information security, operational, compliance, and third-party risks.

- Assist in conducting periodic risk assessments across business functions, projects, applications, vendors, and other organizational areas.

- Maintain risk registers and ensure identified risks are appropriately documented, assigned, and tracked through remediation.

- Coordinate with risk owners to obtain updates on risk treatment plans and mitigation activities.

Regulatory and Compliance Management

- Support the GRC team in monitoring applicable regulatory, contractual, and industry requirements.

- Assist in maintaining regulatory and compliance obligation registers.

- Conduct basic research on applicable requirements under frameworks and regulations such as GDPR, HIPAA, CCPA/CPRA, DPDPA, and other relevant requirements.

- Support assessments to determine the organization’s compliance with applicable regulatory and contractual requirements.

- Assist in identifying compliance gaps and documenting recommended remediation actions.

- Support the development, review, and maintenance of policies, procedures, standards, and guidelines.

- Assist in tracking policy acknowledgements, compliance activities, and periodic reviews.

- Support investigations and documentation of compliance exceptions or breaches, as directed by the GRC Manager.

- Maintain accurate and organized compliance records and documentation.

Internal Audit and Assessment Support

- Support planning and execution of internal audits and compliance assessments.

- Assist in developing audit checklists, questionnaires, evidence requests, and testing documentation.

- Document audit observations, findings, exceptions, and supporting evidence.

- Coordinate with processand control ownersto obtain responses and remediation plans.

- Maintain the audit findingsand corrective actiontracker.

- Follow up with responsible owners on overdue remediation activities.

- Assist the GRC Manager duringexternal audits, certification audits, customer audits, and regulatory assessments.

- Maintain organized audit evidence repositories to ensure audit readiness.

SOC 2 and Compliance Support

- Support the GRC team in maintaining SOC 2 readiness and compliance activities.

- Assist with collection and validation of SOC 2 control evidence from control owners.

- Maintain evidence trackers and monitor evidence submission timelines.

- Support control applicability assessments and gap assessments.

- Assist in responding to customer security and compliance questionnaires.

- Support preparation of documentation and evidence for customer audits, due diligence assessments, and security reviews.

- Coordinate with relevant teams to obtain accurate and timely responses to compliance requests.

GRC Reporting and Administration

- Maintain GRC trackers, registers, dashboards, and compliance calendars.

- Prepare periodic status reports covering risks, audits, compliance activities, findings, remediation actions, and evidence collection.

- Maintain accurate records of GRC activities and supporting documentation.

- Monitor deadlines and proactively follow up with stakeholders.

- Assist in preparing presentations and management reports for GRC-related activities.

- Ensure GRC documentation is properly organized, version-controlled, and readily available for audits and assessments.

Ideally, you have

- Bachelor’s degree in business administration, Information Security, Computer Science, Law, Risk Management, Audit, or a related field.

- 1–3 years of experience in Governance, Risk & Compliance, information security, IT audit, internal audit, risk management, or a related area.

- Fresh graduates with relevant academic qualifications, internships, certifications, or demonstrated interest in GRC may also be considered.

- ISO 27001 Foundation, Internal Auditor, Lead Auditor/Lead Implementer, Security+, CISA,CRISC, or other relevant certifications are desirable.

- Basic to intermediate knowledge of ISO 27001:2022 and information security principles.

- Familiarity with frameworks and regulations such as SOC 2, GDPR, HIPAA, CCPA/CPRA, DPDPA, or similar requirements is desirable.

- Knowledge of risk assessment, internal audit, control testing, or compliance assessment processes is desirable.

- Strong proficiency in Microsoft Excel/Google Sheets and Microsoft Office/PowerPoint.

- Ability to review evidence, documentation, and control requirements accurately.

- Ability to analyse information, identify gaps and support practical recommendations.

- Understanding of basic audit methodology and control assessment.

- Ability to maintain clear, accurate, and well-organized compliance documentation.

- Clear written and verbal communication with the abilityto follow up professionally with stakeholders.

- Takes responsibility for assigned activities and follows tasks through to completion.

- Ability to manage multiple assignments, deadlines, and competing priorities.

Why Explore a Career at Accordion:

A Culture of Impact &Excellence

- A culture of merit & recognition: Thrive in a meritocratic, high-growth environment with semi-annual performance and promotion cycles.

- Multi - dimensional exposure: Navigate complex,high stakes workstreams across diverse industries and domains. At Accordion, you will engage with varied intellectual challenges that keep your perspective sharp, and your curiosity fuelled.

- Entrepreneurial environment: Exercise the intellectual freedom to make definitive decisions and the autonomyto own their outcomes. We reward initiative, encouraging you to expand your influence and assume larger responsibilities.

- Collaborative vitality: Experience a non-bureaucratic, high-energy culture alongside high-calibre peers. Our environment is designed to challenge your thinking and accelerate your growth through shared expertise and collective ambition.

Our Commitment to Your Well-being

We believe that our collective success is rooted in the personal well-being and growth of our people. We have curated a suite of benefits designed to support you and your family’s health, celebrate your milestones, and empower your professional journey.

- Comprehensive health & security: We provide fully covered Health and Group Term Life Insurance for you, with health insurance coverage extending to your immediate family.

- Care on your terms: Access expert medical guidance through on-site health camps or our integrated tele-health services. This ecosystem includes free professional consultations alongside discounted healthcare services including dental and vision care.

- Integrated family support: We supportworking parents with a fully sponsored, premium on-site Day Care facility.

- Empowering leave Structures: Our robust leave policy is an intentional commitment to work-life integration, featuring dedicated maternity and parental support designed to help new parents through life’s major transitions.

- A culture of recognition: We believe everybreakthrough deserves an audience. Through our dedicated rewards platform, we pause to celebrate both your professional triumphs and your most meaningful personal milestones.

- Architecting your growth: Thrive in a positive & transparent environment designed for the continuous evolution of your craft. We provide the infrastructure through learning programs and engagement initiatives - to bridge the gap between your personal aspirations and professional mastery.

More jobs at Accordion India

Accordion India - Associate - IT Risk and Compliance at Accordion India (Hyderabad, Telangana, India) | AI Jobs Map