CareerPlanSign in

GRC Lead - India

India💼 Full-time🗓 2026-08-26 → 2026-09-25

Core

Lead and mature Governance, Risk, and Compliance capabilities, overseeing the Information Security Management System (ISMS), regulatory compliance, and risk governance.

Role type

Senior IC GRC Lead (Information Security)

Builds

Enterprise security governance programs, ISO 27001 certified ISMS, risk management frameworks, and client assurance responses.

Domain

Financial services / Cybersecurity / Regulatory Compliance

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

ISO 27001 Lead Implementer/Auditor experience, enterprise risk management framework design, information security policy lifecycle management, client security questionnaire response, third-party risk assessment, stakeholder management for executive leadership

Preferred skills

Experience with ISO 31000, ISO 22301, ISO 42001, NIST Cybersecurity Framework, SOC 1/2, GDPR, DORA, NIS2

Technologies

ISO 27001, ISO 27002, ISO 31000, ISO 27005, ISO 22301, ISO 42001, NIST Cybersecurity Framework, SOC 1, SOC 2, GDPR, DORA, NIS2

Responsibilities

Own the lifecycle management of Information Security policies, standards, and frameworks; Lead ISO 27001 certification and recertification activities; Maintain and oversee the Group Security Risk Register; Lead responses to client security questionnaires and Right-to-Audit engagements; Conduct security assessments for vendors and suppliers; Partner with Security Operations, Engineering, Legal, and business stakeholders to address risks.

Seniority

Senior, hands-on IC

Sourced via lever · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.