Quick Summary
Be an essential element to a brighter future. We work together to transform essential resources into critical ingredients for mobility, energy, connectivity and health.
Be an essential element to a brighter future.
We work together to transform essential resources into critical ingredients for mobility, energy, connectivity and health. Join our values-led organization committed to building a more resilient world with people and planet in mind. Our core values are the foundation that make us successful for ourselves, our customers and the planet.
Job Description
We work together to transform essential resources into critical ingredients for mobility, energy, connectivity and health. Join our values-led organization committed to building a more resilient world with people and planet in mind. Our core values are the foundation that make us successful for ourselves, our customers and the planet.
Albemarle is hiring for an IT GRC Analyst. This position is hybrid (3 days per week in office) and located in Bangalore, India
Responsibilities
~2 min read- →Support the development, implementation, and ongoing management of the IT risk and compliance program, including IT General Controls (ITGC), SOX 404, and alignment to NIST CSF, ISO 27001, and COBIT, as well as the regional and customer-driven obligations that drive the compliance calendar, including NIS2 and SACS-210.
- →Facilitate cybersecurity risk assessments, maintain the cyber risk register, track remediation to closure, and report on risk and controls maturity to IT and executive leadership, identifying trends and opportunities for improvement.
- →Lead SOX IT compliance activities as one of several compliance programs, including audit evidence collection, control testing, gap analysis, deficiency remediation, and reporting to IT management and Internal Audit.
- →Coordinate with control owners across IT to ensure timely completion of control testing, documentation, and remediation activities.
- →Coordinate third-party cybersecurity risk assessments, including supplier security reviews, SOC 2 report evaluation, vendor security questionnaires, and remediation tracking, applying a documented intake and vendor tiering model.
- →Maintain and continuously improve IT GRC documentation, including control narratives, risk-and-control matrices, and policy repositories.
- →Coordinate the lifecycle of cybersecurity policies, standards, and procedures, including review cadence, exception intake and tracking, and governance documentation.
- →Partner with Internal Audit, external auditors, and IT leadership to support audit cycles and ensure consistent, audit-ready evidence.
- →Support customer security questionnaires, compliance attestations, cyber insurance applications, and other external assurance requests, and prepare materials for regulatory and customer assessments including NIS2 and SACS-210 recertification.
- →Coordinate security participation in DPIAs, privacy reviews, and DPA reviews in partnership with Legal and Privacy.
- →Assess and review change management controls as part of audit, compliance, and control effectiveness activities; CAB/CMB operational ownership and AI governance program ownership remain outside this role.
- Bachelor’s degree in Computer Science, Information Systems, or a related discipline; or equivalent combination of education and work experience.
- 5–8+ years of experience in IT compliance, GRC, or audit roles.
- Demonstrated SOX 404 compliance experience, including ITGC testing, documentation, and audit coordination.
- Experience evaluating third-party assurance artifacts, including SOC 2 Type II reports and ISO 27001 certification documentation.
- Working knowledge of GRC frameworks: COBIT, COSO, NIST CSF, ISO 27001; exposure to EU cybersecurity regulation (NIS2) and customer or industry security assessment schemes.
- Familiarity with data privacy regulations such as GDPR, CCPA, and India's DPDP Act.
- Professional certifications: CISA, CRISC, CGEIT, or equivalent (or actively pursuing).
- Experience with GRC tooling or audit-management platforms.
- Ability to communicate control gaps and remediation plans clearly to both technical and non-technical stakeholders.
- Comfortable working with cross-functional teams to drive control remediation to closure.
What We Offer
~1 min readLocation & Eligibility
Listing Details
- Posted
- September 28, 2026
- First seen
- September 28, 2026
- Last seen
- September 28, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 56%
- Scored at
- September 28, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.