Job Description
Post Name- Senior Manager/AVP - GRC
n
Job Type- Permanent
n
Location- Mumbai
n
Budget- For Senior Manager-45 LPA (fixed + variable)
n
For AVP- 65 LPA (fixed + variable)
n
Educational Qualification/ Certifications:
n
Mandatory- Graduate / Postgraduate / BE / BTech.
n
Certifications- At least one of the CIPM/CIPP/ISACA-CDPSE/CDPO/GDPR-CDPO/ISO 27701 LA/LI and/or PMP/CISM/CISSP/CISA/ISO 27001 certifications is mandatory.
n
Work Experience:
n
Mandatory-Min 10 years (For General Manager) and 14 years (For AVP) of experience preferred in Security Advisory, Cyber Security and privacy implementation and operations
n
Responsibilities:
n
n
- Develop and execute the GRC strategy and framework to ensure compliance with applicable regulatory requirements and industry standards.
n
- Lead the assessment and management of security risks across the organization, ensuring effective mitigation strategies are in place
n
- Establish strong governance processes and policies to promote a culture of compliance and risk awareness among employees.
n
- Oversee the development, implementation, and maintenance of information security policies, standards, and procedures.
n
- Collaborate with executive management to provide regular updates on GRC matters, including risk assessment outcomes and compliance status.
n
- Manage cross-functional teams to integrate GRC practices across relevant business functions and projects.
n
- Lead internal and external audit processes, ensuring timely completion and resolution of any findings.
n
- Develop and oversee training and awareness programs related to GRC and information security for staff at all levels.
n
- Stay abreast of emerging regulatory requirements, security threats, and industry trends to proactively adjust the GRC program as necessary.
n
n
Skills Required:
n
n
- Should have relevant experience in Security & Privacy engineering and tools implementation.
n
- Project Management experience with leading a technical team.
n
- Knowledge on cyber security, data security, SOC operations and incident management
n
- Experience with large BFSI, trading industry in security and privacy domain will be added advantage.
n
- Good understanding of SEBI, RBI, MEITY, NCIIPC, CERT-IN and MoF guidelines and advisories in data security, cyber security and data privacy.
n
- Knowledge of information security and privacy principles and practices, understanding of security protocols, principles, standards and defence in depth.
n
- Ability to communicate effectively through writing, speaking, and presenting to peers and top management.
n
- Must be a team player capable of contributing to MCX mission through collaboration with fellow teammates and other stakeholders in a agile environment.
n
n
For more details contact Sonali at
[email protected]/ +91 (phone hidden).
📌 Senior Manager/ AVP- GRC (Mumbai)
🏢 T&M Services Consulting
📍 Mumbai