GRC Analyst

Orange Health Labs
India · Bengaluru, India · Karnataka, India · Remote · EgyptPosted Jul 28, 2026
Open JobsEngineeringGRC AnalystGRC Analyst BLR - Head Office, Bangalore, Karnataka, India 1 - 3 YearsConsultantJob Description

Location: Bangalore

Contract Duration: 6 Months

About the company: 

Orange Health is India’s leading on-demand diagnostics lab for urban Indian consumers and is positioned as the fastest diagnostics lab in India. We were recognized as the Diagnostics Startup of the Year 2025.

Launched in January 2021, Orange Health Labs is amongst the most loved brands in the healthcare sector, with over 30,000 reviews and the highest rating on Google for all its facilities across the country, and an NPS close to 90!

Orange Health Labs is among the best places to work, with a team of 1,000+ people across the company. We believe in treating colleagues with respect and investing in their growth for the long term. You can learn more about our work culture on our careers page and LinkedIn page.

Our vision is supported by some of the world’s leading investors like Accel, General Catalyst, Y Combinator, Bertelsmann India, Amazon, and other marquee names. We have been recognised as a Future Unicorn for two consecutive years by Hurun India.

About the role:

Responsible for supporting audits, managing Third-Party Risk Management (TPRM) activities, and ensuring adherence to applicable regulatory and compliance frameworks.

Why join us?

  • Market competitive salary with bi-annual increments.
  • Great stock option policy with rights to exercise 10 years post exit.
  • Well known for a collaborative culture with a top 10% rating on Glassdoor.
  • Fastest-growing health tech company in India with marquee investors.
  • Opportunity to build a product that will have a significant impact on people's health and well-being

 What will you do?

Audit & Compliance

  • Support internal and external audits (ISO 27001, SOC 2, DPDPA and applicable standards)
  • Collect, validate, and maintain audit evidence and documentation
  • Track audit findings, remediation actions, and closure timelines
  • Assist in policy, SOP, and control documentation updates
  • Third-Party Risk Management (TPRM)
  • Conduct security assessments for vendors and partners
  • Review security questionnaires and evaluate responses
  • Follow up with vendors for evidence and gap remediation
  • Maintain vendor risk register and assessment reports

Governance & Risk

  • Assist in risk assessments and risk register maintenance
  • Monitor compliance with internal security policies and standards
  • Support awareness initiatives and security training programs
  • Track compliance metrics and generate reports for stakeholders

Operational Support

  • Coordinate with IT, DevOps, Legal, and business teams for compliance requirements
  • Maintain a documentation repository for audits and certifications
  • Support the implementation of security controls aligned with frameworks

Skills Required  for the Role:

  • Basic understanding of information security principles (CIA triad, risk management)
  • Familiarity with compliance frameworks (ISO 27001, SOC 2 preferred)
  • Understanding of TPRM concepts and vendor risk assessment lifecycle
  • Strong documentation and communication skills
  • Proficiency in Excel, Google Sheets, or similar tools

Tools & Platforms:

  • GRC platforms such as Scrut Automation or CISO Assistant
  • Vendor risk management and questionnaire tools
  • Documentation and collaboration tools (Google Workspace, etc.)
  • Basic familiarity with ticketing systems (Jira preferred)

Preferred Qualifications:

  • Bachelor’s degree in Information Security, Computer Science, or related field
  • Relevant certifications (or pursuing): ISO 27001 Foundation, Security+
  • Exposure to audit processes, compliance tracking, or GRC tooling
  • Basic knowledge of cloud security (AWS preferred)
Job SnapshotUpdated Date28/07/2026Job IDJOB_36Sub-FunctionEngineeringLocationBLR - Head Office, Bangalore, Karnataka, India Experience1 - 3 YearsEmployee TypeConsultantJob Description

Location: Bangalore

Contract Duration: 6 Months

About the company: 

Orange Health is India’s leading on-demand diagnostics lab for urban Indian consumers and is positioned as the fastest diagnostics lab in India. We were recognized as the Diagnostics Startup of the Year 2025.

Launched in January 2021, Orange Health Labs is amongst the most loved brands in the healthcare sector, with over 30,000 reviews and the highest rating on Google for all its facilities across the country, and an NPS close to 90!

Orange Health Labs is among the best places to work, with a team of 1,000+ people across the company. We believe in treating colleagues with respect and investing in their growth for the long term. You can learn more about our work culture on our careers page and LinkedIn page.

Our vision is supported by some of the world’s leading investors like Accel, General Catalyst, Y Combinator, Bertelsmann India, Amazon, and other marquee names. We have been recognised as a Future Unicorn for two consecutive years by Hurun India.

About the role:

Responsible for supporting audits, managing Third-Party Risk Management (TPRM) activities, and ensuring adherence to applicable regulatory and compliance frameworks.

Why join us?

  • Market competitive salary with bi-annual increments.
  • Great stock option policy with rights to exercise 10 years post exit.
  • Well known for a collaborative culture with a top 10% rating on Glassdoor.
  • Fastest-growing health tech company in India with marquee investors.
  • Opportunity to build a product that will have a significant impact on people's health and well-being

 What will you do?

Audit & Compliance

  • Support internal and external audits (ISO 27001, SOC 2, DPDPA and applicable standards)
  • Collect, validate, and maintain audit evidence and documentation
  • Track audit findings, remediation actions, and closure timelines
  • Assist in policy, SOP, and control documentation updates
  • Third-Party Risk Management (TPRM)
  • Conduct security assessments for vendors and partners
  • Review security questionnaires and evaluate responses
  • Follow up with vendors for evidence and gap remediation
  • Maintain vendor risk register and assessment reports

Governance & Risk

  • Assist in risk assessments and risk register maintenance
  • Monitor compliance with internal security policies and standards
  • Support awareness initiatives and security training programs
  • Track compliance metrics and generate reports for stakeholders

Operational Support

  • Coordinate with IT, DevOps, Legal, and business teams for compliance requirements
  • Maintain a documentation repository for audits and certifications
  • Support the implementation of security controls aligned with frameworks

Skills Required  for the Role:

  • Basic understanding of information security principles (CIA triad, risk management)
  • Familiarity with compliance frameworks (ISO 27001, SOC 2 preferred)
  • Understanding of TPRM concepts and vendor risk assessment lifecycle
  • Strong documentation and communication skills
  • Proficiency in Excel, Google Sheets, or similar tools

Tools & Platforms:

  • GRC platforms such as Scrut Automation or CISO Assistant
  • Vendor risk management and questionnaire tools
  • Documentation and collaboration tools (Google Workspace, etc.)
  • Basic familiarity with ticketing systems (Jira preferred)

Preferred Qualifications:

  • Bachelor’s degree in Information Security, Computer Science, or related field
  • Relevant certifications (or pursuing): ISO 27001 Foundation, Security+
  • Exposure to audit processes, compliance tracking, or GRC tooling
  • Basic knowledge of cloud security (AWS preferred)
Share the opportunity





View Similar Jobs Powered by:darwinbox|Privacy Policy

Want jobs like this matched to you?

SimpleCareer scores fresh postings against your résumé so you only see the matches that matter.

Get started free