14 Aug
|
Incedo
|
Gurugram
Job Title: Senior Manager / Lead – Governance, Risk & Compliance (GRC)
Location: Gurgaon / Gurugram
Experience: 8–16 Years
Employment Type: Full-Time
Job Function: Governance, Risk & Compliance / Cybersecurity / Information Security
Job Summary
We are looking for an experienced Governance, Risk & Compliance (GRC) professional with 8–16 years of experience in enterprise risk management, cybersecurity governance, privacy, regulatory compliance, and information security frameworks.
The ideal candidate will have strong hands-on experience in implementing, managing, and auditing ISMS, PIMS, SOC 2, NIST CSF , and other global cybersecurity, privacy, risk, and regulatory frameworks. The role will involve partnering with senior leadership and cross-functional stakeholders to strengthen the organization's risk posture, compliance maturity, security governance, and regulatory readiness.
Experience across BFSI, Technology, Healthcare, or Manufacturing sectors will be highly valued.
Key Responsibilities
- Lead and manage enterprise-wide Governance, Risk & Compliance (GRC) programs and initiatives.
- Develop, implement, and continuously improve information security, privacy, risk, and compliance frameworks .
- Drive implementation and audit readiness for ISO 27001 (ISMS) and ISO 27701 (PIMS) .
- Manage SOC 2 Type 2 compliance, control frameworks, evidence collection, audit coordination, and remediation activities.
- Implement and assess cybersecurity controls aligned with NIST CSF 2.0 .
- Support regulatory and industry compliance requirements including DORA, NIS 2, FedRAMP, HIPAA, and NESA .
- Establish and maintain enterprise risk management practices aligned with ISO 31000 and ISO 27005 .
- Support emerging technology governance initiatives, including ISO 42001 / AI Governance .
- Conduct risk assessments, control assessments, compliance assessments, gap assessments, and internal audits .
- Identify security and compliance gaps and drive risk remediation and corrective action plans .
- Partner with Information Security, IT, Privacy, Legal, Internal Audit, Cloud, Engineering, and Business teams.
- Provide regular risk and compliance reporting to senior management and leadership .
- Develop and maintain policies, standards, procedures, risk registers, control matrices, and compliance documentation.
- Support internal and external audits, regulatory assessments, customer security assessments, and certification activities.
- Drive third-party/vendor risk management , including due diligence, assessments, monitoring, and remediation.
- Provide governance and risk oversight for cloud security and technology environments .
- Leverage GRC platforms to automate risk, compliance, audit, control, and evidence-management processes.
- Stay current with evolving cybersecurity regulations, privacy requirements, emerging risks, and industry best practices.
Required Skills & Expertise Governance, Risk & Compliance
- Enterprise Risk Management
- Information Security Governance
- Cybersecurity Risk Management
- Compliance Management
- IT Risk & Controls
- Internal/External Audits
- Regulatory Compliance
- Third-Party Risk Management
- Control Testing & Assurance
- Risk Assessment & Remediation
Frameworks & Standards
Must Have:
- ISO 27001 / ISMS
- ISO 27701 / PIMS
- SOC 2 Type 2
- NIST CSF 2.0
Preferred Experience
- Experience working with BFSI, Technology, Healthcare, or Manufacturing organizations.
- Experience managing enterprise-level GRC programs and multiple compliance frameworks.
- Solid exposure to cloud security governance and risk management .
- Experience interacting with senior leadership, auditors, regulators, customers, and external stakeholders.
- Experience in building or improving GRC processes, controls, and automation.
- Strong understanding of cybersecurity, privacy, technology risk, and regulatory requirements.
📌 Technical Manager (Gurugram)
🏢 Incedo
📍 Gurugram