
Job description
The GRC Analyst/Lead supports the organization’s governance, risk management, and compliance (GRC) programs by assisting with control design and testing, risk assessments, policy management, third party risk management and vendor assessment, and regulatory compliance activities. This role works closely with global stakeholders across IT, Security, Legal, Privacy, and Internal Audit to ensure adherence to internal policies, industry frameworks, and regulatory requirements.
This role should be able to work independently and should be used to Global collaboration; the Staples GRC function is lead out of Staples US Corporate and this role will serve as an extension of such team to provide coverage to the India office. Governance & Policy Management Support the lifecycle management of information security, privacy, and risk management policies (drafting, review, approvals, communication, and periodic refresh).
Maintain policy repositories and ensure alignment with applicable frameworks and regulatory requirements. Assist with governance reporting, metrics, and committee materials. Risk Management Participate in enterprise and IT risk assessments, including risk identification, scoring, documentation, and tracking of mitigation plans.
Support risk workshops and coordination with business and technology teams. Maintain risk registers and follow up on remediation activities. Compliance & Assurance Support compliance programs aligned to frameworks such as: SOC 1 / SOC 2 ISO/IEC 27001 PCI DSS NIST CSF / NIST 80053 (as applicable) Assist with internal and external audits, including evidence collection, walkthroughs, control testing, and issue tracking.
Support customer, vendor, and regulatory inquiries related to security and compliance. Regulatory & Privacy Support Assist with compliance activities related to applicable laws and regulations (e.g., India Digital Personal Data Protection Act (DPDP), GDPR, or other regional privacy requirements as applicable). Support privacy risk assessments, data inventories, and control documentation.
Third. Party Risk Management Support third party/vendor risk assessments, including questionnaire review, evidence validation, and risk issue tracking. Coordinate with procurement, legal, and security teams on vendor compliance matters. Reporting & Continuous Improvement Prepare dashboards, metrics, and reports for management and audit committees.
Identify opportunities to improve GRC processes, tooling, and documentation. Support implementation and maintenance of GRC tools (e.g., Archer, Service. Now GRC, Metric. Stream, or similar).
Requirements
Basic Qualifications Working knowledge of at least one major framework (SOC, ISO 27001, PCI DSS, NIST). Understanding of risk and control concepts, including control design and effectiveness. Strong documentation, analytical, and organizational skills. Ability to work with global teams across multiple time zones. Strong written and verbal communication skills in English.
Preferred Qualifications
Experience supporting global or US based compliance programs. Familiarity with privacy regulations (DPDP, GDPR, CCPA concepts). Experience with GRC platforms (e.g., Logic. Gate). Professional certifications (or progress toward): CISA, CRISC, CISM ISO 27001 Lead Implementer / Auditor </