Associate Director / Lead - GRC (Gurugram)

Associate Director / Lead - GRC (Gurugram)

30 Aug
|
CyberAssure Services (P
|
Gurugram

30 Aug

CyberAssure Services (P

Gurugram

Company Description CyberAssure Services (P) Ltd. is dedicated to helping organisations protect their systems and sensitive data from evolving cyber threats. Led by seasoned cybersecurity professionals with decades of applied experience, the company delivers robust, practical security solutions that address both internal and external risks.

CyberAssure serves leading global organisations across finance, IT/ITES, healthcare, manufacturing, aviation, retail, and other sectors, building long-term trust through reliable protection.

Key offerings include data discovery and protection, privacy management, GRC, third-party risk management, cloud security, internal audits, certifications, user awareness and phishing simulation, dark web monitoring, and managed security services.

Role/Position : Associate Director / Lead - GRC

Function : Governance, Risk and Compliance (GRC), Third-Party Risk Management (TPRM) Delivery

Experience : 10+ years in TPRM, GRC advisory, or third-party security risk delivery, including pre-sales and OEM-partner engagement

We are looking for a senior, client-facing risk management professional to lead our TPRM & GRC delivery practice end to end — from being an evangelist for the practice in the market, through mapping customer requirements and building winning proposals with OEM partners, to owning delivery and the customer relationship once TPRM assessments and GRC teams are deployed. This is a hybrid presales, delivery leadership, and account management role suited to someone equally comfortable in a client boardroom, a partner enablement session, and a delivery review.

Key Responsibilities

1. Practice Evangelism & Thought Leadership

• Enhance & represent CyberAssure's TPRM & GRC practice at industry forums, client briefings, and partner events, building market visibility and pipeline.

• Track evolving regulatory and market drivers (DPDP Act 2023, RBI/IRDAI/SEBI/CERT-In frameworks, GDPR and translate them into practice positioning and client conversations.

• Contribute to whitepapers, offering decks, and client-facing points of view that position CyberAssure's TPRM approach (including continuous, signal-driven monitoring) as differentiated in the market.

2. Customer Requirement Mapping & Proposal Development

• Lead discovery conversations with prospective and existing clients to understand their vendor risk landscape, regulatory obligations, and GRC maturity.

• Translate customer requirements into scoped solutions — assessment methodology, team sizing, tooling, and delivery model (8x5 & 24x7).





• Own end-to-end proposal development for TPRM and GRC opportunities, including RFP responses, commercial structuring (project, retainer, or outcome-based pricing), and client presentations.

• Coordinate with OEM and technology partners to incorporate the right tooling into proposals — platform selection, licensing, and joint solutioning for ASM, GRC & TPRM components.

3. OEM & Partner Ecosystem Management

• Serve as the primary relationship owner with key OEM/technology partners for TPRM and GRC tooling, keeping CyberAssure current on product roadmaps, SKUs, and joint go-to-market opportunities.

• Build and maintain a working knowledge of the third-party risk platform to advise clients objectively on fit-for-purpose tooling.

• Negotiate partner-supported pricing, co-sell arrangements, and enablement for proposals and delivery.

4. Customer Relationship & Delivery Ownership

• Act as the senior relationship point of contact for clients where TPRM assessments or dedicated GRC delivery teams/pods are deployed, ensuring engagements run to scope, schedule, and quality.

• Oversee delivery leads and assessment teams on active engagements, resolving escalations and ensuring consistent methodology across clients and geographies.

• Drive account growth within existing clients — identifying opportunities to expand scope, extend retainers, or introduce adjacent CyberAssure services.

• Own governance cadences with clients (steering committees, QBRs, SLA/KPI reviews) for ongoing TPRM and GRC managed services engagements.

5. Practice Building & Continuous Improvement

• Contribute to refining CyberAssure's TPRM methodology, assessment templates, and control frameworks based on delivery experience and market feedback.

• Support hiring, onboarding, and capability development for the TPRM/GRC delivery bench.

• Maintain a repeatable proposal and pricing playbook so future opportunities can be scoped and quoted quickly and consistently.

Qualifications & Skills

• 10+ years of overall experience in risk management, TPRM, or GRC advisory/delivery with positive

knowledge of technology,



and demonstrated experience in a client-facing and/or pre-sales

capacity.

- Candidates should possess strong expertise in Governance, Risk, and Compliance frameworks (e.g., ISO 27001/27701, NIST, SOC 2, PCI DSS, HIPAA) and policy development.
- Candidates should possess skills in risk assessment and management, control design and testing, and audit planning and execution.
- Candidates should possess experience with data protection and privacy practices, including data discovery, privacy impact assessments, and regulatory compliance (e.g., GDPR, local data protection laws).
- Candidates should possess familiarity with third-party risk management, vendor due diligence, and ongoing monitoring of external partners.
- Candidates should possess understanding of cloud security principles and controls across major cloud platforms.
- Candidates should possess strong stakeholder management, communication, and presentation skills for engaging executive leadership and client teams.
- Candidates should possess the ability to lead and mentor teams, manage multiple projects, and work in a fast-paced consulting or services environment.
- Beneficial qualifications include a bachelor’s or master’s degree in Information Security, Computer Science, or a related field, and professional certifications such as CISA, CISM, CISSP, ISO 27001 LA/LI, or CRISC.

• Willingness to travel as the engagements require.

- Strong consultative and executive-presence communication — equally effective writing a proposal, presenting to a client CISO, or briefing an OEM partner.
- Commercial acumen: comfortable structuring pricing models (project, retainer, outcome-based) and negotiating scope and commercials.
- Delivery discipline: able to manage multiple concurrent client engagements and delivery teams without losing sight of quality or SLAs.
- Partner management: skilled at building genuine, mutually beneficial relationships with OEMs rather than transactional vendor management.
- Analytical grounding in vendor/third-party risk methodologies (questionnaire-based assessments, continuous monitoring/signal-based scoring, control testing).

How do first 12 months look like:

- A qualified, growing pipeline of TPRM and GRC opportunities with a healthy proposal win rate.
- Strong, reference-able relationships with at least two to three key OEM/technology partners actively contributing to joint opportunities.
- Stable, well-governed delivery across existing client engagements, evidenced by client satisfaction and low escalation volume.

📌 Associate Director / Lead - GRC (Gurugram)
🏢 CyberAssure Services (P
📍 Gurugram

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: associate director / lead - grc (gurugram) / gurugram