03 Sep
|
Happiest Resume
|
Bengaluru
03 Sep
Happiest Resume
Bengaluru
Role: GRC Lead – Cybersecurity & Compliance
We are seeking experienced Governance, Risk, and Compliance (GRC) professionals to join our cybersecurity function in a strategic role. This position will be instrumental in driving enterprise-wide risk management, strengthening security governance frameworks, and ensuring regulatory and industry compliance across the organization.
The ideal candidate brings a strong foundation in information security, risk management, and compliance, along with the ability to collaborate across business and technology teams to enhance the organization’s overall security posture.
Key Responsibilities
Lead and manage enterprise-level cybersecurity risk assessments and risk management initiatives.
Drive the design, implementation, and continuous improvement of governance frameworks, policies, and control environments.
Oversee and ensure alignment with global compliance frameworks such as ISO 27001, SOC 2, PCI-DSS, GDPR, and NIST.
Act as a key liaison for internal and external audits, ensuring audit readiness and effective closure of observations.
Provide strategic oversight on remediation programs, risk treatment plans, and compliance tracking.
Establish and manage third-party risk management processes, including vendor security assessments.
Partner with cross-functional stakeholders (Technology, Legal, Business, and Security teams)
to embed compliance and risk-aware culture.
Monitor evolving regulatory landscapes and recommend proactive control enhancements.
Present risk insights, compliance posture, and governance updates to leadership through dashboards and reports.
Support organization-wide security awareness and governance initiatives.
Required Experience & Skills
5-7 years of experience in Technology GRC, Information Security, or Risk & Compliance roles.
Strong understanding of global security standards and frameworks (ISO 27001, SOC 2, PCI-DSS, GDPR, NIST).
Proven experience managing audits, risk assessments, and compliance programs.
Solid understanding of risk management methodologies and internal control frameworks.
Robust stakeholder management and communication skills with the ability to influence outcomes.
Ability to operate independently while managing multiple priorities in a dynamic environment.
Preferred Qualifications
Industry certifications such as ISO 27001 LA/LI, CISA, CRISC, or CISSP.
Experience with GRC platforms/tools and automation of compliance processes.
Core Competencies
Strategic thinking and analytical mindset
Strong ownership and accountability
Attention to detail with a governance-first approach
Effective collaboration and stakeholder engagement
📌 GRC Lead – Cybersecurity & Compliance (Bengaluru)
🏢 Happiest Resume
📍 Bengaluru