Manager GRC
*Technical Audit & Assurance •* *AI Risk Governance • Project Risk*
About the GRC Function
Governance, Risk & Compliance (GRC) is ZS's enterprise-wide second-line governance function — governing the integrity of the firm's control setting, managing the certification and assurance portfolio, and providing the independent risk signal that enables leadership to make informed decisions with confidence.
The function operates alongside ERM and Legal/Compliance within ZS's governance structure and works closely with the ZS's Delivery Excellence (DEX) organization for delivery governance and audit. GRC's four accountability areas span control environment integrity, regulatory and certification compliance, risk intelligence and oversight, and delivery and operational assurance. The function is midway through a deliberate expansion of its assurance capabilities, and this role is central to that growth.
The Role
The Manager – GRC (Technical Audit & Assurance)
is a senior individual contributor and program leader responsible for GRC's technical audit and assurance capabilities. The role leads client security audits, owns GRC's AI risk governance workstream, and strengthens the Project Risk Assessment (PRA) program through technical depth and independent oversight.
The Manager works closely with three peer leads — Certifications & Compliance, Risk Operations, and Third-Party Risk & Data Compliance — and is a key partner to the Delivery Excellence organization and ZS's Technology, Platform Services and Client Service organizations. The role reports to the Head of GRC.
Key Responsibilities
Client & Delivery Security Audit Program
Lead GRC's client and delivery security audit program — independent, evidence-based reviews of security and governance controls in live client engagements and across ZS's delivery organization.
- Manage end-to-end audit execution: scoping, walkthroughs, evidence review, observation validation, management response, remediation tra
📌 Manager - GRC (Pune)
🏢 ZS
📍 Pune