Come work at a place where innovation and teamwork come together to support the most exciting missions in the world
Job Description: GRC Lead
Role Title: Governance, Risk & Compliance (GRC) Lead
Department: Security Operations- Governance, Risk and Compliance (GRC)
Reporting To: Manager – GRC
Location: Pune (Hybrid)
Experience: 8–10 years
Role Type: Full‑time
Role Overview
The GRC Lead is responsible for establishing, leading, and continuously improving the organization’s Governance, Risk, and Compliance framework across technology, information security, and business operations. This role ensures alignment with regulatory requirements, industry standards, and organizational risk appetite while enabling business growth and resilience.
The GRC Lead partners closely with technology, security, legal, compliance, internal audit, procurement, and business stakeholders to proactively identify, assess, mitigate, and monitor risks, including third‑party, cyber, regulatory, and operational risks.
Key Responsibilities
Governance & Policy Management
- Define and maintain enterprise‑level GRC frameworks, policies, standards, and procedures
- Establish governance structures for risk ownership, escalation, and decision‑making
- Ensure alignment between business objectives, risk appetite, and control frameworks
- Drive security and risk awareness across the organization
Risk Management
- Lead the enterprise and technology risk assessment lifecycle (identification, assessment, treatment, monitoring)
- Own risk registers and ensure risks are tracked, reviewed, and mitigated effectively
- Support risk quantification and scenario analysis where applicable
- Report risk posture to senior leadership and governance committees
- Integrate risk management into SDLC, cloud adoption, and digital initiatives
Compliance & Assurance
- Ensure compliance with applicable laws, regulations, and standards, such as:
- ISO 27001 / ISO 27701
- NIST CSF / NIST 800‑53
- SOC 1 / SOC 2
- GDPR, DPDP Act
📌 Senior GRC Analyst (Pune)
🏢 Qualys
📍 Pune