23 Aug
|
Zee Entertainment Enterprises
|
India
23 Aug
Zee Entertainment Enterprises
India
Job Description
Manager / Senior Manager – Governance, Risk & Compliance (GRC)
Location
Bangalore
Experience
8–10 years of experience in Governance, Risk, Compliance, and Information Security.
Role Overview
The GRC Manager / Senior Manager is responsible for leading cybersecurity governance, risk management, compliance, and awareness programs in ZEE. This role ensures enterprise-wide risk visibility, audit readiness, regulatory compliance, and continuous improvement of the cybersecurity maturity posture.
Key Responsibilities
Risk Management & Governance
- Maintain an up-to-date enterprise risk register including risk assessment, mitigation, and acceptance inputs with status.
- Conduct weekly reviews of enterprise and engineering risks and policy exceptions and track closure.
- Perform proactive risk identification through process reviews, audits and control testing.
- Publish fortnightly cybersecurity and privacy risk summary reports to leadership.
- Track KPIs and publish dashboards indicating control maturity.
Security Awareness & Training
- Plan and execute weekly cybersecurity awareness campaigns via email.
- Conduct monthly cybersecurity and privacy training for contractors.
- Lead quarterly ethical phishing simulations, reduce phishing failure rates and improve reporting rate.
- Execute industry-event-based awareness programs and annual gamified security carnival.
Policies,
ISMS & Process Reviews
- Lead annual Information Security Policy and Procedure reviews with cross-functional stakeholders.
- Plan and execute ISMS risk assessments, internal and external ISO 27001 audits.
- Review cybersecurity processes and recommend enhancement to process and control measures for improvement.
Leadership Reporting & Governance Committees
- Prepare quarterly cybersecurity and monthly business review reports for CIO and leadership.
- Convene and manage Information Security & Privacy Steering Committee (ISPSC) meetings and track actions/decision out of the meetings for closure.
Audit, Compliance & Contracts
- Assist the team during internal, corporate, and statutory audits.
- Review MSAs, NDAs, and project engagements for security obligations.
- Support in security and privacy compliance portal submissions.
Financial & Corporate Governance
- Track cybersecurity budget consumption and renewals.
- Provide cybersecurity inputs for ESG, BRSR and Annual reporting.
Qualifications & Certifications
- Bachelor’s degree in Engineering, Computer Science, or related field.
- Preferred certifications: CISM, CISSP, CRISC, ISO 27001 Lead Auditor/Implementer.
Job Requirement
- GRC & Risk Management
- ISO 27001 / ISMS
- Audit & Compliance
- Security Governance
- Risk Reporting & Dashboards
📌 Manager - GRC (India)
🏢 Zee Entertainment Enterprises
📍 India