ApplySarthi

IT Risk and Compliance Analyst

Jobgether

Tailor my CV for this job, freeView job and applyYour CV rewritten for this role, from your real experience. Sign in with Google, nothing to install.

Got this interview? Our apps help you get the job.

Skills named in this job

Read from the description itself, not inferred.

This role on the market

996 open compliance roles across 198 companies are on ApplySarthi right now, most of them in Bengaluru (74), Hyderabad (31), Mumbai (13).

What compliance roles keep asking for: Stakeholder management (15%) — counted across their open postings here.

SaaS jobs

Jobgether has 4,435 open roles listed here.

Counted across 14 company job boards, updated as roles open and close.

Preparing for this interview

Interviews for compliance roles keep coming back to Stakeholder management. Practise those questions before you sit with Jobgether.

Questions you are likely to be asked

  1. Why do you want to join Jobgether?
  2. What is your experience with SaaS? Tell me one thing you learned the hard way.
  3. How do you check that your numbers are right before you share them?
  4. Walk me through a dashboard or report you built. Who used it, and for what?
  5. Explain a join or a window function you have used, and why you needed it.

Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.

Practise the IT Risk and Compliance Analyst at Jobgether interview free →

Accountabilities:: Review client MSAs, SOWs, DPAs, security addenda, and related agreements using contract analysis tools, identifying provisions requiring attention from Legal, IT, Delivery, or other stakeholders and coordinating redlines through completion. Translate contractual security, privacy, data handling, audit, breach notification, and sub-processor requirements into trackable operational commitments and verify that obligations are being met. Respond to client security questionnaires, due diligence requests, and audit inquiries while maintaining and improving a reusable knowledge base to make future responses faster and more consistent. Collect, organize, maintain, and manage control evidence within the GRC platform, tracking remediation activities against frameworks such as SOC 2, ISO 27001, NIST CSF, and other applicable standards. Support vendor risk management activities for SaaS and AI providers by reviewing security documentation, DPAs, sub-processor information, and findings, while maintaining accurate vendor risk records. Operationalize data retention and disposal requirements by tracking departmental retention schedules, documenting exceptions and legal holds, and working with IT to verify retention settings across relevant platforms. Support privacy program activities including data mapping, data subject request processes, and monitoring obligations associated with GDPR, CCPA, and other applicable privacy requirements. Draft, maintain, publish, and improve compliance policies, standard operating procedures, and process documentation, ensuring that requirements remain current and are effectively implemented. Prepare risk and compliance reporting for leadership, highlighting program status, emerging risks, remediation progress, and areas requiring attention. Maintain and monitor the risk register, support annual risk assessments, and contribute to the identification, evaluation, and treatment of organizational risks. Participate in business continuity and disaster recovery planning, tabletop exercises, security incident response, internal audits, access reviews, and periodic control testing. Administer security awareness training programs and monitor completion and compliance across the organization. Requirements Bachelor’s degree or equivalent practical experience, with 3–5 years of professional experience in compliance, GRC, contract management, privacy, risk, or a related field. Hands-on experience reviewing commercial agreements, ideally including MSAs, DPAs, security addenda, or similar documents, with the ability to collaborate effectively with legal counsel on contractual redlines. Experience responding to client security questionnaires, vendor due diligence requests, audit inquiries, or comparable compliance information requests. Working knowledge of at least one major security or compliance framework, such as SOC 2, ISO 27001, or NIST CSF, including a practical understanding of the evidence required to demonstrate control effectiveness. Foundational understanding of data privacy regulations such as GDPR and CCPA, particularly how privacy requirements translate into contracts, operational processes, and compliance obligations. Exceptional organizational and follow-through skills, with the ability to manage numerous parallel workstreams, deadlines, stakeholders, and remediation activities without losing attention to detail. Clear, concise, and confident written communication skills, including the ability to interpret complex technical or legal information and distill it into practical priorities and recommendations. Strong analytical, problem-solving, and judgment skills, with the ability to identify gaps, assess risks, coordinate solutions, and follow issues through to resolution. Comfortable working with SaaS platforms, GRC systems, contract analysis tools, and other technology, with a demonstrated ability to learn new systems quickly and use technology to improve processes. Self-directed and accountable, with the ability to own outcomes end to end while working effectively within a small, collaborative team. Comfortable working across technical, legal, operational, and business functions and translating requirements between different stakeholder groups. Benefits Salary range of $80,000–$90,000 USD . Remote working arrangement within the United States. Opportunity to help build and shape an IT risk and compliance program from the ground up. Broad exposure to IT risk, compliance, privacy, vendor management, contracts, security operations, and governance. Collaborative and inclusive work environment that values diverse perspectives and authentic contributions. Opportunities to work closely with cross-functional teams across legal, technology, delivery, security, and leadership functions. Meaningful ownership and autonomy within a growing compliance program. Opportunity to contribute to process improvement and the development of scalable compliance practices.

Match this job to your CV

ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.

Check my match →

Similar open roles

Need answers during your interview? Try Live Sarthi.

Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.

Try Live Sarthi free →

A Windows app, from the same team as ApplySarthi.

Listed on lever · posted 2026-10-05. ApplySarthi collects openings and links to application pages; the role is advertised by Jobgether, not by us.