Resume sample

GRC Analyst Resume Example

Credibility for a GRC Analyst comes from clear evidence of governance, risk, and compliance programs for technology organizations. GRC Analyst with 6+ years implementing and managing governance, risk, and compliance programs for technology companies and BFSI clients.

The resume sample below keeps ISO 27001, SOC 2 Type II, NIST CSF, RBI IT Framework, PCI-DSS attached to real duties; keep the same discipline in your version.

GRC Analyst Resume Sample

Preethi Raghavan

GRC Analyst

Chennai, Tamil Nadu · preethi.ragh@email.com · +91-9840556677 · linkedin.com/in/preethiragh-grc

Professional Summary

GRC Analyst with 6+ years implementing and managing governance, risk, and compliance programs for technology companies and BFSI clients. Expert in ISO 27001, SOC 2 Type II, NIST CSF, RBI IT frameworks, and enterprise risk management. Led 3 ISO 27001 certifications and 5 SOC 2 Type II audits with zero major findings.

GRC Analyst Technical Skills

Core Skills: ISO 27001 · SOC 2 Type II · NIST CSF · RBI IT Framework · PCI-DSS · GDPR · Risk Register · Control Mapping · Vendor Risk Management · Business Continuity · Vanta · Drata · OneTrust · Archer · Python · Excel · JIRA · Confluence · Third-Party Risk

Professional Experience

Senior GRC AnalystRazorpay Software Pvt Ltd · Apr 2020 – Present
  • Led ISO 27001:2022 certification program — scoped 120 controls, conducted gap assessment, remediated 80 findings, and achieved certification in 9 months with zero major non-conformities.
  • Managed annual SOC 2 Type II audit across 5 Trust Service Criteria — authored 150+ control narratives, coordinated evidence from 12 engineering teams, zero exceptions in 3 consecutive years.
  • Built enterprise risk register covering 200+ risks across 8 domains — quarterly risk scoring review with CISO and VP Engineering driving remediation prioritization.
  • Implemented Vanta continuous compliance platform automating 60% of evidence collection — reducing audit prep effort from 400 engineer-hours to 90 hours annually.
  • Conducted 50+ vendor risk assessments using standardized questionnaire and scoring model — flagging 12 high-risk vendors for compensating controls or contract renegotiation.
  • Designed and delivered GDPR compliance program covering data inventory, consent management, DPO appointment, and cross-border transfer mechanisms.
GRC AnalystErnst & Young India (Cybersecurity Advisory) · Jun 2018 – Mar 2020
  • Conducted NIST CSF maturity assessments for 5 banking clients — produced board-level heat maps and 18-month remediation roadmaps.
  • Assisted 3 clients through PCI-DSS v3.2 assessments — scoped cardholder data environments, mapped controls, and remediated gaps.
  • Built policy template library (40+ security policies) standardized across EY's India GRC practice.

GRC Analyst Projects

grc-control-mapper

Python tool mapping controls across ISO 27001, SOC 2, NIST CSF, and PCI-DSS to identify overlaps and reduce duplicate evidence collection — used across 5 client audits.

Education

B.Tech Computer Science — SSN College of Engineering, Chennai, 2018 | CGPA: 8.1/10

Certifications

  • Certified Information Systems Auditor (CISA)
  • ISO 27001 Lead Implementer — PECB
  • Certified in Risk and Information Systems Control (CRISC)

All details in this resume example are illustrative and should be replaced with your actual experience, achievements, education, and certifications.

Practical GRC Analyst resume guidance focused on governance, risk, and compliance programs for technology organizations, using only claims you can verify from your own history.

How to Write a GRC Analyst Resume

Interviewers need proof of governance, risk, and compliance programs for technology organizations, not an undifferentiated cloud of neighboring tools.

Ground depth in ISO 27001, SOC 2 Type II, NIST CSF, RBI IT Framework, PCI-DSS by linking each skill to a responsibility from your summary, experience, or grc-control-mapper.

Resumes stumble when they security engineer technical controls language without GRC program evidence. Keep every technology claim tied to something you personally owned.

Prefer decision language—what you modeled, operated, secured, led, or shipped—over tool inventories that could fit any adjacent title.

Close the loop by showing how ISO/SOC2/NIST/PCI/GDPR control mapping and risk registers appears in your bullets, projects, and summary without inventing employers, percentages, or scale.

Instead of

Experienced professional skilled in many modern tools related to grc analyst.

Use

Managed annual SOC 2 Type II audit across 5 Trust Service Criteria — authored 150+ control narratives, coordinated evidence from 12 engineering teams, zero exceptions in 3 consecutive years.

What to Include in a GRC Analyst Resume

Cover ISO 27001, SOC 2 Type II, NIST CSF, RBI IT Framework, PCI-DSS, GDPR, Risk Register, Control Mapping when truthful, grouped the way you actually practiced the work rather than as a buzzword dump.

Add Certified Information Systems Auditor (CISA), ISO 27001 Lead Implementer — PECB, or Certified in Risk and Information Systems Control (CRISC) only if completed, preserving official credential names.

Include grc-control-mapper with technologies such as ISO 27001, SOC 2 Type II, NIST CSF, RBI IT Framework when you need compact proof alongside employment bullets. Add a certifications subsection because this source includes Certified Information Systems Auditor (CISA); ISO 27001 Lead Implementer — PECB; Certified in Risk and Information Systems Control (CRISC); on your resume, list only credentials you actually hold and preserve their official names.

GRC Analyst Resume Summary Example

Begin with 6 years centered on governance, risk, and compliance programs for technology organizations, then reinforce the strongest theme already present in the professional summary.

GRC Analyst with 6+ years implementing and managing governance, risk, and compliance programs for technology companies and BFSI clients. Expert in ISO 27001, SOC 2 Type II, NIST CSF, RBI IT frameworks, and enterprise risk management. Led 3 ISO 27001 certifications and 5 SOC 2 Type II audits with zero major findings.

Important GRC Analyst Skills for a Resume

Core Skills

ISO 27001 · SOC 2 Type II · NIST CSF · RBI IT Framework · PCI-DSS · GDPR · Risk Register · Control Mapping · Vendor Risk Management · Business Continuity · Vanta · Drata · OneTrust · Archer · Python · Excel · JIRA · Confluence · Third-Party Risk

Retain GRC Analyst skills you can defend with a delivery story, design choice, incident, test, leadership example, or project walkthrough.

GRC Analyst Resume Experience Examples

Senior GRC Analyst

Managed annual SOC 2 Type II audit across 5 Trust Service Criteria — authored 150+ control narratives, coordinated evidence from 12 engineering teams, zero exceptions in 3 consecutive years.

Senior GRC Analyst

Led ISO 27001:2022 certification program — scoped 120 controls, conducted gap assessment, remediated 80 findings, and achieved certification in 9 months with zero major non-conformities.

Senior GRC Analyst

Built enterprise risk register covering 200+ risks across 8 domains — quarterly risk scoring review with CISO and VP Engineering driving remediation prioritization.

Senior GRC Analyst

Implemented Vanta continuous compliance platform automating 60% of evidence collection — reducing audit prep effort from 400 engineer-hours to 90 hours annually.

Use real numbers when you can verify them. Do not invent metrics simply to make the resume sound stronger.

GRC Analyst ATS Keywords

ISO 27001SOC 2 Type IINIST CSFRBI IT FrameworkPCI-DSSGDPRRisk RegisterControl MappingVendor Risk ManagementBusiness ContinuityVantaDrataOneTrustArcherPythonExcelJIRAConfluenceThird-Party RiskGRC analyst resumegovernance risk compliance resume IndiaISO 27001 analyst resumeSOC 2 audit resumeCISA CRISC GRC resume

Choose keywords that match both the GRC Analyst job description and work you can substantiate. Spell out important concepts naturally in summary and experience instead of pasting this list.

GRC Analyst Resume Tips

Lead with GRC programs

Open with frameworks or audits you supported.

Show frameworks carefully

Mention ISO 27001, SOC 2, NIST, PCI-DSS, GDPR, or RBI IT only when applied.

Place risk registers

Describe control mapping work you performed.

Never invent certifications

Do not claim audit opinions you did not earn/support.

Differentiate from Security Engineer

Emphasize governance and compliance evidence over exploitation testing.

Interview-test every line

Keep only statements you can expand into a concrete GRC Analyst story without guessing.

Frequently Asked Questions

How do I prove ownership of governance, risk, and compliance programs for technology organizations on a GRC Analyst resume?

Cover governance, risk, and compliance programs for technology organizations with source-backed skills such as ISO 27001, SOC 2 Type II, NIST CSF, RBI IT Framework, PCI-DSS, plus experience or projects that show what you personally owned.

Which GRC Analyst skills belong in the skills section?

Prioritize ISO 27001, SOC 2 Type II, NIST CSF, RBI IT Framework, PCI-DSS and other category skills only when you can explain them with a project, production example, or troubleshooting story.

What should the GRC Analyst summary emphasize?

State about 6 years of GRC Analyst work and the ISO/SOC2/NIST/PCI/GDPR control mapping and risk registers focus that matches the job description—only if that tenure is true for you.

Can grc-control-mapper support a thin experience section?

Yes—grc-control-mapper can support claims involving ISO 27001, SOC 2 Type II, NIST CSF, RBI IT Framework when you need concise, technology-specific project evidence.

Should I list credentials such as Certified Information Systems Auditor (CISA), ISO 27001 Lead Implementer — PECB, on a GRC Analyst resume?

Certified Information Systems Auditor (CISA), ISO 27001 Lead Implementer — PECB, or Certified in Risk and Information Systems Control (CRISC) belongs on the resume only when earned; otherwise rely on skills and delivery evidence.

Build Your GRC Analyst Resume with AI

Showcase your audit outcomes, control coverage, and compliance automation with an AI-crafted GRC Analyst resume.

Free to start · No credit card required