GRC Manager (India)

GRC Manager (India)

19 Aug
|
Godrej Infotech
|
India

19 Aug

Godrej Infotech

India

Third Party Cyber Risk ManagementAbout the Business & Position OverviewJob ProfileKey Responsibilities

- End-to-end management of Third Party Cyber Risk lifecycle
- Vendor risk assessment and classification based on risk tiers
- Evaluation of vendor security controls and compliance posture
- Integration of data privacy (DPDP) requirements into TPRM
- Risk tracking, remediation, and closure management
- Alignment with regulatory, compliance, and internal security frameworks
- Stakeholder collaboration across business, legal, procurement, and IT
- Continuous improvement of TPRM processes and methodologies

Third Party Cyber Risk Management Responsibilities

- Implement and manage processes for the complete Third Party Cyber Risk Management lifecycle.
- Conduct cyber security risk assessments of vendors, suppliers, partners, and outsourced service providers.
- Classify third parties into risk tiers (Critical, High, Medium, Low) and define assessment scope accordingly.
- Review vendor security certifications and reports (ISO 27001, SOC 2, PCI-DSS) along with internal questionnaires.
- Identify risks related to data privacy, infrastructure access, cloud services, and managed services.
- Incorporate DPDP requirements to ensure vendors handle personal data securely and support user rights.
- Validate vendor capability to protect data and report breaches as per regulatory expectations.
- Track and drive closure of risks, gaps, and remediation actions with vendors.
- Collaborate with internal stakeholders to evaluate residual risks and recommend mitigation or acceptance.
- Ensure vendor controls comply with security standards (ISO 27001, NIST, RBI/SEBI where applicable).
- Support audits, regulatory reviews, and internal assurance activities.
- Maintain dashboards, risk registers, and reporting metrics for leadership.





Stakeholder & Cross-Functional Collaboration

- Partner with Procurement, Legal, Business, Privacy, and Digital teams to embed cyber risk requirements.
- Review and recommend security clauses, SLAs, and audit rights in vendor contracts.
- Provide advisory support during vendor onboarding, selection, and renewal.

Continuous Improvement

- Enhance TPRM processes using automation and risk-based approaches.
- Monitor emerging third-party cyber threats and trends.
- Support incident response activities involving third-party security incidents.

Qualification Details Essential Qualification: Bachelor's degree in Engineering (Information Security, Computer Science, or related field)

Preferred Qualification: Professional certifications such as: CISM / CISSP / CRISC ISO 27001 Lead Implementer / Auditor

Experience Details Essential Experience:

- 6-8 years of experience in Information Security / Cyber Risk / GRC domains
- 3-4 years of hands-on experience in Third Party / Vendor Cyber Risk Management

Preferred Experience: Experience in large enterprises, conglomerates, or regulated industries

Special Skill Essential:

- Strong understanding of cyber security risk management and vendor risk frameworks
- Hands-on experience with TPRM methodologies and assessments
- Knowledge of:
- ISO 27001 / ISO 27002
- NIST Cyber Security Framework (CSF)
- SOC 2
- Data privacy fundamentals

- Familiarity with cloud security and managed service provider risks
- Understanding of DPDP Act and privacy principles (data protection, consent, cross-border considerations)
- Solid analytical, documentation, and reporting skills
- Effective stakeholder management and communication

Preferred:

- Exposure to automation in TPRM tools and processes
- Experience handling regulatory compliance (RBI, SEBI, etc.)
- Incident response exposure involving third-party security events

Location

- Mumbai

📌 GRC Manager (India)
🏢 Godrej Infotech
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: grc manager (india) / india