Skip to main content
Posted 28 August, 2026

Security GRC Analyst II

Diligent Corporation
Bengaluru, Karnataka, India Full Time
Reference: 102_716120_6144535004

Here's a summary of the role:

Every enterprise deal reaches the moment where someone in security says "prove it." You're the person who answers - quickly, accurately, and with the evidence to back it up.

As an Analyst II on our Trust & Assurance team, you'll own a live queue of security questionnaires, third-party due diligence assessments, RFP security sections and customer assurance requests. You'll draft at speed using AI-assisted response tooling, then verify every answer against our approved answer library, current SOC 2 and ISO 27001 certifications and the underlying evidence before it leaves your hands. Accuracy is the whole game here: a wrong answer in a customer questionnaire is a commitment we didn't mean to make.

The best part is that you won't just work the queue - you'll shrink it. Every recurring question you turn into a published answer on our trust site is a ticket that never comes back. If you've spent two to four years in security GRC, compliance, IT audit or customer assurance, you're precise under volume, and you like being measured on turnaround time and first-pass accuracy, you'll do well here.

Here's a breakdown of what you'll do (not all of it, just the important stuff):

  • Own a high-volume queue of security questionnaires, due diligence assessments, RFP security sections and assurance requests, delivering accurate responses within SLA.
  • Use AI-assisted response tooling to draft at speed, then verify every answer against the approved answer library, current certifications and underlying evidence before it goes out.
  • Triage and route incoming requests using established playbooks - resolving the routine independently and escalating anything novel, contractual or architecturally complex.
  • Maintain and expand the answer library by adding approved answers, retiring stale ones and flagging inconsistencies, so the same question never has to be researched twice.
  • Build out trust site and customer-facing content, and show commercial teams how to point customers there - turning recurring questions into self-serve answers.
  • Package evidence for customer security audits and track quality and throughput metrics (turnaround, first-pass accuracy, rework, deflection) to find and fix friction in the process.

These are the essentials you'll need to get an interview:

  • 2-4 years in security GRC, compliance, IT audit, customer assurance or a closely related function.
  • Working knowledge of SOC 2 and ISO 27001, and the ability to read a control and understand what it actually requires.
  • Demonstrable precision under volume - a track record in SLA-driven or queue-based work where accuracy mattered and was measured.
  • Strong written English, with the ability to answer a security question precisely and concisely without padding.
  • Solid organisational habits: you can manage a queue of competing requests without losing track of any of them.
  • Comfort working with AI-assisted tooling, paired with healthy scepticism - you treat generated output as a draft to verify, never an answer to forward.
  • The discipline to escalate rather than guess, and the confidence to say "this is outside what I can answer."

It would be great if you had these to, but we'll support you if you don't:

  • Experience with a trust centre or trust portal platform - for example SafeBase, Whistic, Conveyor or Vanta.
  • Familiarity with questionnaire formats and frameworks such as SIG, CAIQ, HECVAT or VSAQ.
  • Basic working knowledge of AWS, Azure or GCP security concepts - enough to understand the answers you're verifying.
  • Exposure to additional frameworks such as NIST CSF, GDPR, HIPAA or DORA.
  • Early-career certifications or progress toward them - ISO 27001 Foundation or Lead Implementer, CompTIA Security+, or CISA.
  • Experience with Jira, Confluence, Salesforce and Microsoft 365.
  • Additional language skills, particularly for supporting customers across EMEA.

Sign up for Job Alerts