25 Aug
|
UST
|
Thiruvananthapuram
25 Aug
UST
Thiruvananthapuram
Role description
Role Overview
Own the end-to-end Security Governance, Risk & Compliance (GRC) tower, encompassing Security Governance, Compliance & Resilience, BCP & DR, and Audit & Compliance. Establish, lead, and continuously mature the organization's GRC program from policy frameworks and compliance certifications through to audit management and operational resilience. Lead a team of GRC analysts, compliance specialists, and resilience engineers; define team strategy, capability roadmap, and performance objectives. Act as the primary Subject-Matter Expert (SME) for GRC disciplines, interfacing with executive leadership, internal audit, legal, risk, engineering, and business unit heads. Deliver executive and board-level risk and compliance reporting, including metrics on control effectiveness, audit findings, certification status, and resilience posture. Drive a unified governance framework that integrates policies, standards, risk management, compliance, audit, and resilience into a cohesive operating model. Champion a risk-based, continuous compliance approach embedding security controls into business processes and technology lifecycle management. Key Responsibilities BCP & DR / Continuity Planning & Management Audit & Compliance Lead Business Impact Analysis (BIA) to identify critical processes, dependencies, RTO and RPO targets across the enterprise. Develop, maintain, and exercise Business Continuity Plans (BCPs) and Disaster Recovery (DR) plans aligned to regulatory and business requirements. Establish DR governance define DR tiers, own DR test scheduling, execution, and post- exercise reporting. Assess IS preparedness against continuity scenarios; identify gaps and drive remediation through structured action plans. Develop and maintain technology-business dependency maps to underpin continuity and DR planning. Own the Security Compliance Certification Lifecycle plan, execute, and manage certifications (ISO 27001, SOC 2, PCI-DSS, HIPAA, DPDP, etc.). Manage the calendar and execution of Internal and External Audits coordinate evidence collection, stakeholder responses, and management actions. Design and operate a Control Validation program continuously test and validate the operating effectiveness of security controls. Conduct formal Gap Assessments against regulatory frameworks and industry standards; produce gap remediation roadmaps with ownership and timelines. Confidential Internal Use Only Page Lead Crisis Management planning establish protocols, communication trees, and executive escalation runbooks. Report BCP/DR posture metrics to senior leadership and integrate findings into the enterprise risk register. Maintain audit-ready documentation, control registers, and evidence repositories at all times. Engage with external auditors, certification bodies, and regulatory authorities as the primary organizational point of contact. Track and close audit findings, non- conformities, and corrective action plans (CAPs) within agreed timelines. Operational Resilience & Governance Recommended Roadmap Items (FY'25-26) Develop, publish, and maintain the enterprise Security Policies and Standards library ensuring alignment to regulatory requirements and business context. Define and track Security Metrics and KPIs/KRIs that measure governance program health and control effectiveness.
Design and execute a Security Awareness & Training program including role-based training curricula, completion tracking, and effectiveness measurement. Run a managed Phishing Simulation program configure scenarios, analyse results, and feed outcomes into targeted training interventions. Build and operate a Unified Governance Framework that aligns GRC processes, tools, and stakeholders under a single operating model. Ensure governance processes support regulatory change management tracking emerging laws, regulations, and standards impacting the organization. Continuity Planning & Management BIA execution, RTO/RPO establishment, and plan documentation. DR Tests & Governance scheduled tabletop and full failover DR exercises with formal governance reporting. Assess IS Preparedness IS readiness assessments against BCP/DR scenarios. Tech-Business Dependency Mapping asset-to-process dependency mapping for all critical systems. Crisis Management crisis response protocols, playbooks, and communication frameworks. Security Compliance Certification Lifecycle roadmap to ISO 27001, SOC 2 Type II, and additional certifications. Internal & External Audits structured audit program with clear ownership and scheduling. Control Validation & Gap Assessment continuous control testing and annual framework gap analysis. Policies & Standards full policy library review/refresh cycle. Security Metrics executive dashboard of GRC KPIs and KRIs. Training & Awareness + Phishing Simulations annual awareness calendar with measurable outcomes. Unified Governance Framework integrated GRC operating model across all pillars. Program Leadership & Governance Confidential Internal Use Only Page Build, mentor, and manage the GRC team analysts, compliance specialists, and resilience practitioners; define career paths and performance goals. Develop and maintain GRC program policies, procedures, playbooks, and runbooks across all pillars (Governance, Compliance, Resilience, Audit). Collaborate with CISO, Legal, Risk, and Executive Leadership to align the GRC program with corporate risk appetite and strategic objectives. Drive quarterly Business Reviews (QBRs) with senior stakeholders and client CISOs on GRC program health, compliance status, and resilience posture. Evaluate, procure, and manage GRC tooling vendors; own the technology roadmap and budget for the GRC tower. Integrate GRC activities with the broader cybersecurity program VM, SOC, AppSec, and IAM to ensure a holistic risk management posture. Act as the domain lead for client-facing advisory engagements involving GRC program maturity assessment and uplift. Support incident response by providing real-time regulatory and compliance guidance during security incidents. Establish a continuous improvement cycle for all GRC processes, leveraging audit findings, control testing results, and industry benchmarks.
Lead the design and delivery of a Metrics & Reporting framework providing CISO-ready dashboards and board-level visualizations of compliance posture and resilience health. Required Qualifications 8+ years of experience in cybersecurity and/or IT risk, with at least 4 years focused on GRC, compliance management, or operational resilience. Proven experience designing and leading enterprise GRC programs covering governance, compliance, audit, and business continuity / DR. Deep knowledge of security policy and standards frameworks ISO 27001, NIST CSF, NIST SP 800-53, CIS Controls, and equivalent. Hands-on experience managing compliance certification lifecycles ISO 27001,ISO 22301,ISO 27701,HITRUST, SOC 2, PCI-DSS, HIPAA, or DPDP. Solid background in BCP/DR program management BIA, RTO/RPO setting, DR governance, and crisis management. Experience conducting and managing internal and external audit engagements; familiarity with audit evidence collection and finding remediation. Proficiency with GRC platforms such as ServiceNow GRC, Archer, MetricStream, OneTrust, or equivalent. Experience designing and executing security awareness programs including phishing simulations. Excellent communication and stakeholder management skills ability to translate GRC findings into risk narratives for C-suite and board audiences. Familiarity with regulatory and data protection requirements: GDPR, DPDP Act, RBI guidelines, SEBI CSCRF, or sector-specific mandates. Confidential Internal Use Only Page Preferred Qualifications Experience in a consulting or managed security services environment, advising multiple enterprise clients on GRC strategy and maturity uplift. Familiarity with integrated risk management (IRM) methodologies and enterprise risk management (ERM) frameworks. Exposure to OT/ICS compliance and resilience requirements in industrial or critical infrastructure environments. Experience with third-party and supply chain risk management (TPRM/SCRM) programs. Background in security architecture or technical security assessments to complement governance expertise. Knowledge of AI governance and emerging regulatory requirements related to AI/ML risk management. Experience building and operating a Phishing Simulation program using platforms such as KnowBe4, Proofpoint Security Awareness, or Cofense. Certifications Required / Strongly Preferred ISO 27001 Lead Auditor or Lead Implementer ISO 22301 Lead Auditor or Lead Implementer CISA Certified Information Systems Auditor Nice to Have CISSP Certified Information Systems Security Professional CISM Certified Information Security Manager CRISC Certified in Risk and Information Systems Control CCSP Certified Cloud Security Professional
Skills
Compliance, Cybersecurity, GRC, Quality Metrics
About UST
UST is a global digital transformation solutions provider. For more than 20 years, UST has worked side by side with the world’s best companies to make a real impact through transformation. Powered by technology, inspired by people and led by purpose, UST partners with their clients from design to operation. With deep domain expertise and a future-proof philosophy, UST embeds innovation and agility into their clients’ organizations. With over 30,000 employees in 30 countries, UST builds for boundless impact—touching billions of lives in the process.
📌 Senior Security GRC & ISO 27001 Manager (Thiruvananthapuram)
🏢 UST
📍 Thiruvananthapuram