GRC Analyst — Information Security GRC
- Full-time
- Work Model: On-Site
Company Description
Established in 2011 and headquartered in Pune, METRO Global Solution Center (GSC) India is a strategic hub driving METRO’s global transformation. With 1,200+ professionals, we deliver specialized integrated expertise across Master Data Management, Information Technology, Cyber Security, Marketing & Design, Strategy, Finance & Accounting, Controlling (FP&A), and People & Culture (HR) solutions that drive operational excellence and digital innovation.
By supporting METRO’s sCore strategy, we enable sustainable growth and strengthen business processes. With a solutions-first mindset, we reduce complexity, accelerate transformation, and create measurable value for METRO businesses scaling up globally. METRO is a leading international food wholesaler operating in over 30 countries with a strong network of wholesale stores, digital marketplaces, and food service distribution. It supports businesses that keep the world running, from hotels, restaurants, and cafés to local retailers - offering quality, reliability, and smart solutions that help small and medium-sized businesses succeed.
Headquartered in Düsseldorf, Germany, METRO AG employs over 85,000 people worldwide and acts as the central management holding company of the group, driving strategic direction, and enabling consistent excellence across all markets. Around the world, METRO has approx. 15 million customers who benefit from the wholesale company’s unique multichannel mix: customers can purchase their goods in one of the large stores in their area as well as by delivery (Food Service Distribution, FSD) – all digitally supported and connected. In parallel, METRO MARKETS is being developed as an international online marketplace for professional customers, which has been growing and expanding continuously since 2019.
Acting sustainably is one of the company principles of METRO, which has been listed in various sustainability indices and rankings, including MSCI, Sustainalytics and CDP.
Job Description
Role purpose
Work as a direct extension of the onshore Information Security GRC team in Düsseldorf. You support strategic GRC workstreams led from headquarters: ISMS development, AI governance, NIS2 readiness, supplier risk, policy work, and ad-hoc projects. Suits someone who wants substantive analyst-level work close to a senior GRC function, not back-office task processing.
Key responsibilities
- Take on analyst-level work assigned directly by onshore GRC colleagues across ISMS, AI governance, NIS2, supplier risk, and policy workstreams.
- Draft first versions of documents — policy excerpts, briefing notes, analyses, risk write-ups, audit responses — for review by onshore owners.
- Conduct desk research on frameworks, regulations, vendor capabilities, and benchmarking to support onshore decision-making.
- Prepare data extracts, summaries, and structured inputs for stakeholder meetings, leadership reviews, and audits.
- Maintain shared workspaces, trackers, and registers; coordinate with business entities and group functions on behalf of onshore colleagues when delegated.
- Pick up ad-hoc tasks across the GRC portfolio as they arise; communicate progress, blockers, and risks transparently.
Qualifications
Must-have qualifications
- 2–4 years in GRC, IT audit, information security, or a closely adjacent function.
- Working knowledge of ISO/IEC 27001 or a comparable framework (NIST CSF, SOC 2); understands risk, controls, and good evidence.
- Strong written English; able to draft clear, well-structured notes and analyses for a senior European audience.
- Self-directed: comfortable receiving a task and producing a structured first version without heavy hand-holding.
- Comfortable with Microsoft 365 and at least one GRC platform (ServiceNow GRC, Archer, OneTrust) — or able to learn quickly.
Nice to have
- Foundational certification: ISO 27001 Foundation, CompTIA Security+, or working toward CISA / ISO 27001 LI.
- Exposure to AI governance (ISO 42001, NIST AI RMF), NIS2, DORA, or supplier risk programs.
- Prior experience embedded in or supporting a European team.
By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply