Senior Manager (Bengaluru)

Senior Manager (Bengaluru)

17 Aug
|
Calpion Software Technologies
|
Bengaluru

17 Aug

Calpion Software Technologies

Bengaluru

– Security Governance & Risk Leader

Position Title

Security Governance, Risk & Compliance (GRC) Leader

Department

Information Security / Technology

Reports To

Chief Information Security Officer (CISO) / Chief Information Officer (CIO)/VP IT infrastructure and Information security

Position Summary The Security Governance, Risk & Compliance (GRC) Leader is responsible for establishing and maintaining a robust security governance framework that aligns cybersecurity initiatives with organizational objectives, regulatory requirements, and industry best practices. This role provides strategic leadership for information security governance, risk management, compliance, policy administration, audit readiness, and security oversight across the enterprise.

The incumbent will work closely with executive leadership, business stakeholders, IT teams, auditors, regulators, and third-party partners to ensure that security risks are effectively managed, compliance obligations are met, and security controls support business growth while protecting organizational assets.

Key Responsibilities

1. Security Governance & Strategy

- Develop and implement enterprise-wide cybersecurity governance frameworks aligned with business objectives and regulatory requirements.

- Define, maintain, and enforce information security policies, standards, procedures, and guidelines.

- Establish governance structures, security committees, and reporting mechanisms to support security oversight.

- Partner with executive leadership to align security strategy with organizational goals and risk appetite.

- Develop security roadmaps and maturity improvement programs based on industry frameworks and emerging threats.

- Present security governance updates, risk posture, and compliance status to executive management and board committees.

2. Security Risk Management & Compliance

- Establish and maintain an enterprise information security risk management framework.

- Identify, assess, monitor, and mitigate cybersecurity risks affecting business operations and technology environments.

- Maintain security risk registers and track remediation activities to closure.

- Ensure compliance with applicable regulatory, legal, and contractual requirements, including:

- ISO 27001

- NIST Cybersecurity Framework

- GDPR

- HIPAA

- PCI-DSS

- SOX

- RBI and other regional regulatory requirements

- Conduct compliance assessments and readiness reviews for certifications and audits.

- Collaborate with business units to implement risk treatment and control improvement plans.

3. Security Controls & Policy Management

- Design, implement, and monitor security control frameworks across infrastructure, applications, cloud platforms, and business processes.

- Oversee periodic review and enhancement of security policies and procedures.

- Ensure organization-wide awareness and adherence to security standards.

- Lead control testing, effectiveness evaluations, and compliance validation activities.

- Monitor key security controls including:

- Identity and Access Management (IAM)





- Privileged Access Management (PAM)

- Change Management

- Data Protection

- Endpoint Security

- Cloud Security Controls

- Business Continuity and Disaster Recovery

4. Information Security Governance & Security Oversight

- Collaborate with the CISO and security operations teams to drive cybersecurity governance initiatives.

- Monitor compliance with internal security standards and industry best practices.

- Oversee security assessment programs including:

- Vulnerability Assessments

- Penetration Testing

- Security Architecture Reviews

- Cybersecurity Maturity Assessments

- Support security incident management and crisis response governance processes.

- Review threat intelligence, emerging risks, and cybersecurity trends to strengthen organizational resilience.

- Ensure periodic reporting of security metrics, risks, incidents, and remediation activities.

5. Security Program & Operational Governance

- Establish governance frameworks for security initiatives, projects, and transformation programs.

- Oversee security budgeting, planning, and resource prioritization.

- Monitor vendor security performance and third-party risk management programs.

- Ensure security requirements are integrated into technology projects and procurement processes.

- Track security KPIs, KRIs, and service-level metrics to drive continuous improvement.

- Evaluate effectiveness of security investments and governance programs.

6. Audit Management & Regulatory Coordination

- Act as the primary liaison for internal and external security audits.

- Coordinate audit planning, evidence collection, and stakeholder engagement activities.

- Review audit findings and develop remediation plans.

- Ensure timely closure of audit observations and compliance gaps.

- Support regulatory examinations and customer security assessments.

- Maintain documentation required for compliance certifications and governance reviews.

7. Stakeholder Management & Leadership

- Serve as the key liaison between Information Security, IT, Risk, Legal, Compliance, Audit, and Business Units.

- Build robust relationships with executive leadership and business stakeholders.

- Promote a culture of security awareness, accountability, and compliance throughout the organization.

- Lead and mentor governance, risk, and compliance teams.

- Drive security training, awareness, and communication initiatives across the enterprise.

- Provide strategic recommendations to leadership regarding security investments, risk mitigation, and governance improvements.

Requirements

Qualifications & Experience

Education

- Bachelor's Degree in Computer Science,



Information Technology, Cybersecurity, Information Systems, or a related discipline.

- Master's Degree (MBA, MS Information Security, or equivalent) preferred.

Experience

- 12+ years of experience in Information Security, IT Governance, Risk Management, Audit, or Compliance.

- Minimum 5+ years in a leadership or management role within Security Governance, Risk, and Compliance.

- Proven experience implementing and managing enterprise security governance frameworks.

- Hands-on experience managing security audits, risk assessments, compliance programs, and security control frameworks.

- Robust understanding of enterprise technology environments, cloud security, cybersecurity operations, and regulatory requirements.

Preferred Certifications

- Certified Information Security Manager (CISM)

- Certified Information Systems Auditor (CISA)

- Certified in Risk and Information Systems Control (CRISC)

- Certified Information Systems Security Professional (CISSP)

- COBIT Foundation / Design & Implementation

- ISO 27001 Lead Auditor or Lead Implementer

- ITIL Foundation or Expert

- Certified Cloud Security Professional (CCSP) – Preferred

Key Competencies

Leadership & Strategy

- Strategic thinking and business alignment

- Executive presence and influencing skills

- Decision-making and governance leadership

Risk & Compliance

- Security risk assessment and mitigation

- Regulatory compliance management

- Control design and validation

Technical Knowledge

- Information security frameworks and standards

- Cybersecurity governance and operations

- Cloud security and data protection

Communication & Collaboration

- Stakeholder management

- Board and executive reporting

- Negotiation and conflict resolution

- Presentation and communication excellence

Operational Excellence

- Program and project governance

- Process improvement and optimization

- Performance measurement and reporting

Key Performance Indicators (KPIs)

Governance & Compliance

- Audit compliance score

- Number of repeat audit findings

- Timely closure of audit observations

- Regulatory compliance adherence rate

Risk Management

- Reduction in high-risk findings

- Risk remediation closure percentage

- Security control effectiveness scores

- Risk assessment completion rates

Security Program Effectiveness

- Security maturity assessment improvement

- Security policy compliance rate

- Third-party risk assessment completion rate

- Vulnerability remediation performance

Operational Metrics

- SLA adherence for security governance activities

- Budget utilization and optimization

- Security project delivery success rate

- Service delivery performance metrics

Stakeholder Satisfaction

- Business stakeholder satisfaction score

- Executive reporting effectiveness

- Security awareness adoption metrics

- Alignment of security initiatives with business objectives

Job Level: Senior Manager / Director / Head of Information Security Governance & Risk Management

📌 Senior Manager (Bengaluru)
🏢 Calpion Software Technologies
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior manager (bengaluru) / bengaluru