IT GRC Analyst

Albemarle CorporationIndiaHybridFull-timeSenior, 5–8 yearsListed 3 hours ago

Apply now

About this role

Be an essential element to a brighter future.

We work together to transform essential resources into critical ingredients for mobility, energy, connectivity and health. Join our values-led organization committed to building a more resilient world with people and planet in mind. Our core values are the foundation that make us successful for ourselves, our customers and the planet.

Job Description

Job Description

We work together to transform essential resources into critical ingredients for mobility, energy, connectivity and health. Join our values-led organization committed to building a more resilient world with people and planet in mind. Our core values are the foundation that make us successful for ourselves, our customers and the planet.

Albemarle is hiring for an IT GRC Analyst. This position is hybrid (3 days per week in office) and located in Bangalore, India

What You Will Do

- Support the development, implementation, and ongoing management of the IT risk and compliance program, including IT General Controls (ITGC), SOX 404, and alignment to NIST CSF, ISO 27001, and COBIT, as well as the regional and customer-driven obligations that drive the compliance calendar, including NIS2 and SACS-210.
- Facilitate cybersecurity risk assessments, maintain the cyber risk register, track remediation to closure, and report on risk and controls maturity to IT and executive leadership, identifying trends and opportunities for improvement.
- Lead SOX IT compliance activities as one of several compliance programs, including audit evidence collection, control testing, gap analysis, deficiency remediation, and reporting to IT management and Internal Audit.
- Coordinate with control owners across IT to ensure timely completion of control testing, documentation, and remediation activities.
- Coordinate third-party cybersecurity risk assessments, including supplier security reviews, SOC 2 report evaluation, vendor security questionnaires, and remediation tracking, applying a documented intake and vendor tiering model.
- Maintain and continuously improve IT GRC documentation, including control narratives, risk-and-control matrices, and policy repositories.
- Coordinate the lifecycle of cybersecurity policies, standards, and procedures, including review cadence, exception intake and tracking, and governance documentation.
- Partner with Internal Audit, external auditors, and IT leadership to support audit cycles and ensure consistent, audit-ready evidence.
- Support customer security questionnaires, compliance attestations, cyber insurance applications, and other external assurance requests, and prepare materials for regulatory and customer assessments including NIS2 and SACS-210 recertification.
- Coordinate security participation in DPIAs, privacy reviews, and DPA reviews in partnership with Legal and Privacy.
- Assess and review change management controls as part of audit, compliance, and control effectiveness activities; CAB/CMB operational ownership and AI governance program ownership remain outside this role.

What You Bring

Required:

- Bachelor’s degree in Computer Science, Information Systems, or a related discipline; or equivalent combination of education and work experience.
- 5–8+ years of experience in IT compliance, GRC, or audit roles.
- Demonstrated SOX 404 compliance experience, including ITGC testing, documentation, and audit coordination.
- Experience evaluating third-party assurance artifacts, including SOC 2 Type II reports and ISO 27001 certification documentation.
- Working knowledge of GRC frameworks: COBIT, COSO, NIST CSF, ISO 27001; exposure to EU cybersecurity regulation (NIS2) and customer or industry security assessment schemes.
- Familiarity with data privacy regulations such as GDPR, CCPA, and India's DPDP Act.

It’d be great if you also have:

- Professional certifications: CISA, CRISC, CGEIT, or equivalent (or actively pursuing).
- Experience with GRC tooling or audit-management platforms.
- Ability to communicate control gaps and remediation plans clearly to both technical and non-technical stakeholders.
- Comfortable working with cross-functional teams to drive control remediation to closure.

Benefits of joining Albemarle

- Competitive compensation
- Comprehensive benefits package
- A diverse array of resources to support you professionally and personally.

We are partners to one another in pioneering new ways to be better for ourselves, our teams, and our communities. When you join Albemarle, you become our most essential element and you can anticipate competitive compensation, a comprehensive package, and resources that foster your well-being and fuel your personal growth. Help us shape the future, build with purpose and grow together. #LI-JH3

Be an essential element to a brighter future.

Benefits of Joining Albemarle

- Competitive compensation
- Comprehensive benefits package
- A diverse array of resources to support you professionally and personally.

We are partners to one another in pioneering new ways to be better for ourselves, our teams, and our communities. When you join Albemarle, you become our most essential element and you can anticipate competitive compensation, a comprehensive benefits package, and resources that foster your well-being and fuel your personal growth. Help us shape the future, build with purpose and grow together.