And because we understand the value of bringing your full and best self to work, we offer a variety of perks to manage a healthy balance, including flexible time off, wellness resources, and company-sponsored team events.
Key Responsibilities
As a GRC Security Analyst at Everpure, you will turn complex security, risk, and compliance requirements into pragmatic, scalable processes that safeguard our business and enable global growth. Partnering cross-functionally across Product Business Units, Digital Technology, Legal, Privacy, Procurement, and Customer Trust, you will own critical risk workstreams end-to-end to drive actionable risk reduction. Operating as an autonomous practitioner, you will balance strong control discipline with business agility to elevate the maturity of our Global Information Security Office (GISO).
Third-Party Risk & Vendor Governance : Lead end-to-end third-party security risk assessments and SaaS vendor reviews—analyzing questionnaires, SOC reports, and architecture gaps—to minimize supply chain vulnerability across global vendor ecosystems.
Security Exception & Risk Register Ownership : Own the enterprise security exception lifecycle and risk register, collaborating with technical owners to evaluate tradeoffs, establish compensating controls, and track remediation to measurable closure.
Security Awareness & Phishing Operations : Direct operational execution of annual security awareness programs and phishing simulation campaigns, leveraging metrics and trend analysis to measurably reduce human-factor risk across global employee populations.
Audit Preparedness & Compliance Alignment : Drive continuous compliance evidence gathering and control assessments supporting ISO 27001 and SOC 2 audits, ensuring Everpure maintains its customer trust and regulatory posture.
GRC Process Scaling & Automation : Maintain and mature GRC platform workflows (Jira, ServiceNow IRM, Graphite Connect), converting manual assessment tasks into streamlined, automated dashboards that give leadership clear visibility into open risk trends.
Requirements
Experience & Background : 8+ years of professional experience in governance, risk, compliance (GRC), information security, IT audit, or third-party risk management within a global technology or cloud environment.
Core GRC & Risk Assessment Expertise : Practical expertise in risk identification, exception lifecycle management, control mapping, and third-party vendor security assessments aligned with frameworks such as ISO 27001, SOC 2, NIST, or CIS Controls.
Business-Oriented Risk Communication : Strong communication skills with a proven ability to translate complex technical risks into clear business terms (likelihood, impact, operational trade-offs) while collaborating effectively with technical and non-technical stakeholders across regions.
Tooling & Process Execution : Proficiency utilizing GRC platforms and workflow tools (ServiceNow IRM, Jira, Graphite Connect) to structure execution plans, maintain risk register integrity, and drive cross-functional follow-through.
Location Requirements : We are primarily an in-office environment and therefore, you will be expected to work from the Bangalore office in compliance with Everpure’s policies, unless you are on PTO, or work travel, or other approved leave.
Ready to Apply?
Join Pure Storage and make an impact in renewable energy