368,611open jobs
9,439companies
50,719added this week
Browse all
Salary
$33k – $82k per year (Estimated)
Location
In office (Bengaluru)
Seniority
Principal · 12+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Altera is a American semiconductor company that specializes in manufacturing programmable logic devices, primary field-programmable gate arrays (FPGAs), System-on-a-Chip (SoC) FPGAs, and related design software. Originally founded in 1983, the company pioneered reconfigurable hardware before being acquired by Intel in 2015 and later re-established as an independent, standalone enterprise. Its high-performance hardware and intellectual property cores are widely used across data centers, telecommunications, automotive systems, defense, and edge AI applications.

Job Details:

Job Description:

Role Summary

The Senior / Principal GRC Analyst is a senior individual contributor responsible for architecting, leading, and scaling enterprise governance, risk, and compliance programs across highly regulated, technology-driven environments. This role owns implementation and continuous improvement of ISO/IEC 27001, ISO/IEC 42001 (AI Management Systems), GDPR, CCPA/CPRA, and CMMC, and acts as a trusted advisor to security leadership, engineering, legal, and executive stakeholders.

This role requires strong hands-on cybersecurity knowledge, deep regulatory expertise, and the ability to translate technical security architectures into audit-ready, business-aligned compliance outcomes.

Core Responsibilities (All Environments)

  • Define and maintain a risk-based GRC architecture aligned to ISO, NIST, privacy, and regulatory requirements.
  • Lead end-to-end implementations of:
    • ISO/IEC 27001 (ISMS ownership, risk methodology, SoA, internal audits)
    • ISO/IEC 42001 (AI governance, AI risk and control design)
    • GDPR and CCPA/CPRA privacy programs
    • CMMC / NIST SP 800-171
  • Translate security architectures and technical controls into compliant policies, standards, and evidence.
  • Lead enterprise, third-party, cloud, and AI-specific risk assessments.
  • Serve as primary interface for auditors, assessors, regulators, customers, and partners.
  • Drive efficiency using GRC platforms, security telemetry, and AI-assisted compliance tooling.
  • Mentor junior GRC professionals and influence cross-functional teams without direct authority.

Technical Cybersecurity Skills & Expectations

Security Architecture & Controls

  • Strong understanding of defense-in-depth architectures, including:
    • Network segmentation, firewalls, IDS/IPS
    • Endpoint Detection & Response (EDR/XDR)
    • Identity and Access Management (IAM), SSO, MFA, RBAC
  • Ability to assess and validate technical control effectiveness, not just paper compliance.

Cloud & SaaS Security

  • Hands-on familiarity with cloud security models (AWS, Azure, GCP concepts):
    • Shared responsibility
    • Logging and monitoring
    • Encryption at rest and in transit
    • Secure CI/CD and infrastructure-as-code risks
  • Ability to map cloud security controls to ISO 27001, NIST, and CMMC requirements.

Data Protection & Privacy Engineering

  • Understanding of:
    • Data classification and labeling
    • DLP, encryption, key management
    • Data residency and cross-border data transfer controls
  • Ability to work with engineering teams on privacy-by-design implementations.

Vulnerability & Risk Management

  • Familiarity with:
    • Vulnerability management lifecycle
    • Secure configuration baselines
    • Risk acceptance, compensating controls, and technical debt
  • Ability to assess real-world risk rather than checklist compliance.

Incident Response & Monitoring

  • Knowledge of incident response processes, including:
    • Detection, containment, and post-incident reviews
    • Regulatory and contractual notification requirements
  • Ability to validate IR plans against ISO and regulatory expectations.

AI & Emerging Technology Risk

  • Understanding of AI-related security and governance risks:
    • Training data integrity
    • Model lifecycle and access control
    • Bias, explainability, and accountability considerations
  • Exposure to AI-enabled security and compliance tools preferred.

Industry-Specific Skills

Defense / Government Contractors

  • CMMC L1-L3 and NIST SP 800-171 technical control interpretation
  • CUI protection, enclave design, boundary controls
  • Vendor and subcontractor security assurance
  • DFARS-aligned audit and evidence readiness

Semiconductor / Hardware & Manufacturing

  • Protection of design IP, fabrication data, and production systems
  • Supplier and foundry security risk assessments
  • Alignment of cyber, physical, and operational security controls
  • Global compliance and data localization considerations

SaaS / Cloud-Native

  • Cloud-native ISMS design
  • Secure SDLC and CI/CD risk governance
  • Customer audits, security questionnaires, trust signals
  • AI feature governance and responsible data usage

Qualifications:

Required Qualifications

  • 7-12+ years of experience in GRC, security, privacy, or risk management.
  • Proven ownership of ISO 27001, GDPR/CCPA, and CMMC or NIST 800-171 programs.
  • Strong technical and regulatory interpretation skills.
  • Ability to operate independently at senior or principal IC level.

Preferred Certifications & Experience

  • ISO 27001 Lead Implementer / Lead Auditor
  • CISSP, CISA, CRISC
  • CIPM, CIPP/US, CIPP/E
  • Experience with Microsoft security and compliance platforms (Purview, Defender, Entra ID) or equivalent
  • Exposure to AI governance frameworks, tools, or regulations

Role Leveling Expectations

Senior GRC Analyst

  • Leads major compliance initiatives
  • Acts as SME for key frameworks
  • Partners closely with security and engineering
  • Defines enterprise GRC strategy and architecture
  • Advises executives on material cyber and regulatory risk
  • Shapes AI governance and future compliance roadmaps
  • Mentors and raises overall GRC maturity

Job Type:

Regular

Shift:

Primary Location:

Bengaluru, Karnataka, India

Additional Locations:

Posting Statement:

All qualified applicants will receive consideration for employment without regard to race, color, religion, religious creed, sex, national origin, ancestry, age, physical or mental disability, medical condition, genetic information, military and veteran status, marital status, pregnancy, gender, gender expression, gender identity, sexual orientation, or any other characteristic protected by local law, regulation, or ordinance.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,611 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Bengaluru
$169k – $253k per year • Equity • In office • Full-Time • 8+ years exp • Bachelor's Degree • Boulder
JavaScript
TypeScript
AI/ML
AI Agents
Frontend
GraphQL
React.js
DevOps
AWS
Azure
GCP
Google GKE
Helm
Kubernetes
Apply
Network Manager 2 hours ago
$128k – $173k per year • In office • Full-Time • 5+ years exp • United States
DevOps
AWS
Azure
GCP
Apply
$60k – $108k per year • Remote/Hybrid • Full-Time • Bachelor's Degree • United States
PowerShell
Python
DevOps
AWS
Azure
IAM
Splunk
Cybersecurity
Crowdstrike
ISO 27001
Microsoft Defender
Microsoft Entra ID
Microsoft Sentinel
NIST CSF
Qualys Cloud Platform
Apply
$99k – $135k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • Washington
JavaScript
TypeScript
DevOps
Azure
Azure DevOps
CI/CD
Management
Power Apps
Power Automate
QA
Playwright
Apply
$128k – $173k per year • In office • Full-Time • 7+ years exp • Bachelor's Degree • United States
JavaScript
Node JS
TypeScript
Frontend
React.js
DevOps
Amazon EC2
AWS
AWS CDK
AWS Lambda
CI/CD
GitHub Actions
Jenkins
Terraform
Amazon CloudWatch
Amazon S3
API Gateway
GitHub
GitLab
IAM
Apply
$96k – $139k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • United States
Java
Python
SystemVerilog
Verilog
Apply
$44k – $90k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Bengaluru
C++
MATLAB
Python
Apply
CISO 4 days ago
$300k – $370k per year • In office • Full-Time • 15+ years exp • Bachelor's Degree • San Jose
Apply
$187k – $270k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • San Jose
Python
Apply
$30k – $72k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Bengaluru
C++
Perl
Python
Verilog
VHDL
Apply
$31k – $82k per year (Estimated) • In office • Full-Time • 3+ years exp • Hyderabad • Bengaluru
Apply
$31k – $73k per year (Estimated) • In office • Full-Time • 5+ years exp • Bengaluru
Apply
$16k – $34k per year (Estimated) • Remote/Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • Mumbai • Bengaluru
JavaScript
PowerShell
SQL
C#
C#
.NET
Databases
Azure SQL Database
MS SQL
DevOps
Azure
Rest API
Cybersecurity
Microsoft Entra ID
QA
Postman
Swagger
Apply
$41k – $89k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bengaluru
C#
TypeScript
JavaScript
C#
.NET
Databases
Apache Kafka
AI/ML
Copilot
LLM
OpenAI
Frontend
Angular
GraphQL
DevOps
Azure
Azure AKS
Azure DevOps
CI/CD
Docker
GitHub
GitHub Actions
Grafana
Kubernetes
Prometheus
Rest API
Apply
$38k – $83k per year (Estimated) • In office • Full-Time • 12+ years exp • Bachelor's Degree • Bengaluru
Databases
Oracle
DevOps
AWS
Platform Engineering
Apply
See all jobs
This is one of many
368,611 more open roles from verified company boards, updated every day.