12 Aug
|
Incedo
|
Gurugram
Job Title: Senior Manager / Lead – Governance, Risk & Compliance (GRC)
Location: Gurgaon / Gurugram
Experience: 8–16 Years
Employment Type: Full-Time
Job Function: Governance, Risk & Compliance / Cybersecurity / Information Security
Job Summary
We are looking for an experienced Governance, Risk & Compliance (GRC) professional with 8–16 years of experience in enterprise risk management, cybersecurity governance, privacy, regulatory compliance, and information security frameworks.
The ideal candidate will have strong hands-on experience in implementing, managing, and auditing ISMS, PIMS, SOC 2, NIST CSF, and other global cybersecurity, privacy, risk, and regulatory frameworks. The role will involve partnering with senior leadership and cross-functional stakeholders to strengthen the organization's risk posture, compliance maturity, security governance, and regulatory readiness.
Experience across BFSI, Technology, Healthcare, or Manufacturing sectors will be highly valued.
Key Responsibilities
Lead and manage enterprise-wide Governance, Risk & Compliance (GRC) programs and initiatives.
Develop, implement, and continuously improve information security, privacy, risk, and compliance frameworks.
Drive implementation and audit readiness for ISO 27001 (ISMS) and ISO 27701 (PIMS).
Manage SOC 2 Type 2 compliance, control frameworks, evidence collection, audit coordination, and remediation activities.
Implement and assess cybersecurity controls aligned with NIST CSF 2.0.
Support regulatory and industry compliance requirements including DORA, NIS 2, FedRAMP, HIPAA, and NESA.
Establish and maintain enterprise risk management practices aligned with ISO 31000 and ISO 27005.
Support emerging technology governance initiatives, including ISO 42001 / AI Governance.
Conduct risk assessments, control assessments, compliance assessments, gap assessments, and internal audits.
Identify security and compliance gaps and drive risk remediation and corrective action plans.
Partner with Information Security, IT, Privacy, Legal, Internal Audit, Cloud, Engineering, and Business teams.
Provide regular risk and compliance reporting to senior management and leadership.
Develop and maintain policies, standards, procedures, risk registers, control matrices, and compliance documentation.
Support internal and external audits, regulatory assessments, customer security assessments, and certification activities.
Drive third-party/vendor risk management, including due diligence, assessments, monitoring, and remediation.
Provide governance and risk oversight for cloud security and technology environments.
Leverage GRC platforms to automate risk, compliance, audit, control, and evidence-management processes.
Stay current with evolving cybersecurity regulations, privacy requirements, emerging risks, and industry best practices.
Required Skills & Expertise
Governance, Risk & Compliance
Enterprise Risk Management
Information Security Governance
Cybersecurity Risk Management
Compliance Management
IT Risk & Controls
Internal/External Audits
Regulatory Compliance
Third-Party Risk Management
Control Testing & Assurance
Risk Assessment & Remediation
Frameworks & Standards
Must Have
ISO 27001 / ISMS
ISO 27701 / PIMS
SOC 2 Type 2
NIST CSF 2.0
Preferred Experience
Experience working with BFSI, Technology, Healthcare, or Manufacturing organizations.
Experience managing enterprise-level GRC programs and multiple compliance frameworks.
Strong exposure to cloud security governance and risk management.
Experience interacting with senior leadership, auditors, regulators, customers, and external stakeholders.
Experience in building or improving GRC processes, controls, and automation.
Solid understanding of cybersecurity, privacy, technology risk, and regulatory requirements.
📌 Technical Manager (Gurugram)
🏢 Incedo
📍 Gurugram