GRC Lead - India
Core
Lead and mature Governance, Risk, and Compliance capabilities, overseeing the Information Security Management System (ISMS), regulatory compliance, and risk governance.
Role type
Senior IC GRC Lead (Information Security)
Builds
Enterprise security governance programs, ISO 27001 certified ISMS, risk management frameworks, and client assurance responses.
Domain
Financial services / Cybersecurity / Regulatory Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
ISO 27001 Lead Implementer/Auditor experience, enterprise risk management framework design, information security policy lifecycle management, client security questionnaire response, third-party risk assessment, stakeholder management for executive leadership
Preferred skills
Experience with ISO 31000, ISO 22301, ISO 42001, NIST Cybersecurity Framework, SOC 1/2, GDPR, DORA, NIS2
Technologies
ISO 27001, ISO 27002, ISO 31000, ISO 27005, ISO 22301, ISO 42001, NIST Cybersecurity Framework, SOC 1, SOC 2, GDPR, DORA, NIS2
Responsibilities
Own the lifecycle management of Information Security policies, standards, and frameworks; Lead ISO 27001 certification and recertification activities; Maintain and oversee the Group Security Risk Register; Lead responses to client security questionnaires and Right-to-Audit engagements; Conduct security assessments for vendors and suppliers; Partner with Security Operations, Engineering, Legal, and business stakeholders to address risks.
Seniority
Senior, hands-on IC
