11 Sep
|
Aeries Technology
|
Mumbai
11 Sep
Aeries Technology
Mumbai
Position Title: Senior Manager Governance, Risk & Compliance
Type of employment: Full time
Years of experience: 12-15 years
Education: Graduate/Postgraduate (Engineering, Information Technology, Computer Science, or related field)
Location: Prabhadevi, Mumbai (Near Siddhivinayak Temple)
Shifts (if any): Candidate should be flexible to work in different shifts, if required
About Us:
Aeries Technology is a Nasdaq listed global skilled services and consulting partner, headquartered in Mumbai, India, with centers in the USA, Mexico, Singapore, and Dubai. We provide mid-size technology companies with the right mix of deep vertical specialty, functional expertise, and the right systems C solutions to scale, optimize and transform their business operations with unique customized engagement models. Aeries is Great Place to Work certified by GPTW India, reflecting our commitment to fostering a positive and inclusive workplace culture for our employees.
Read about us at https://aeriestechnology.com/careers/
Role Purpose The Senior Manager / AGM - GRC will be responsible for establishing, operating, and continuously improving the organization's Governance, Risk & Compliance framework across Information Technology, Information Security, Data Privacy, Regulatory Compliance, Business Continuity, and Third-Party Risk domains. The role will work closely with executive leadership, business stakeholders, auditors, legal teams, and technology functions to ensure effective risk management and compliance with regulatory and industry requirements.
Key Responsibilities
Governance & Policy Management
- Define and maintain enterprise GRC strategy, roadmap, and operating model.
- Develop, review, and implement governance frameworks, policies, standards, procedures, and controls.
- Establish governance committees, review forums, and compliance reporting mechanisms.
- Ensure periodic policy reviews and approvals.
Enterprise Risk Management (ERM)
- Design and manage enterprise risk management framework.
- Maintain organizational risk register and risk treatment plans.
- Conduct periodic risk assessments across technology, cyber security, operations, vendors, and business functions.
- Present risk posture and mitigation plans to leadership and board committees.
- Facilitate risk acceptance and exception management processes.
Information Security Governance
- Ensure information security controls align with business risks.
- Monitor implementation of ISO 27001, NIST, CIS Controls, and industry best practices.
- Lead security governance reviews and management reporting.
- Coordinate security awareness and compliance initiatives.
Compliance Management
- Ensure compliance with applicable regulations and standards, including:
- DPDPA
- ISO 27001
- SOC 2
- SOX
- ISO 42001
- GDPR (where applicable)
- HIPAA (where applicable)
- Client contractual requirements
- Track regulatory changes and compliance impacts.
- Conduct compliance assessments and readiness reviews.
Internal & External Audit Management
- Lead internal, external, client, and certification audits.
- Coordinate evidence collection and audit responses.
- Track audit findings through closure.
- Develop management action plans.
Third-Party & Vendor Risk Management
- Establish vendor security and risk assessment framework.
- Conduct due diligence assessments for suppliers and partners.
- Monitor third-party risk remediation activities.
- Evaluate contractual compliance requirements.
Data Privacy & Protection
- Support implementation of Data Privacy programs.
- Conduct privacy impact assessments.
- Ensure compliance with data retention and classification requirements.
- Support handling of privacy incidents and regulatory reporting.
Business Continuity & Resilience
- Govern Business Continuity Management (BCM) framework.
- Conduct BCP and DR reviews and testing.
- Ensure remediation of identified gaps.
- Report organizational resilience metrics.
Metrics, Reporting & Board Communication
- Develop executive dashboards and GRC scorecards.
- Present risk and compliance posture to SET, Board, Audit Committee, and leadership teams.
- Provide strategic recommendations for risk reduction.
Leadership Responsibilities
- Build and lead GRC, Compliance, and Risk Management teams.
- Develop team capability and succession plans.
- Drive accountability and performance management.
- Collaborate with IT, Security, Operations, HR, Finance, Legal, and Business Units.
Required Qualifications
Certifications (Preferred)
- CISA
- CISM
- CRISC
- ISO 27001 Lead Auditor/Implementer
- CGEIT
- Certified Risk Manager (CRM)
- DPO/Data Privacy certifications
Experience
- 12-15+ years of overall experience.
- Minimum 7 years in leadership roles managing GRC, Compliance, Risk, and Audit functions.
Required Skills
Functional Skills
- Enterprise Risk Management
- Information Security Governance
- Regulatory Compliance
- Audit Management
- Data Privacy
- Third-Party Risk Management
- Business Continuity
- Policy Management
- Control Framework Design
Technical Skills
- ISO 27001
- NIST CSF
- CIS Controls
- SOC 2
- GRC Platforms
- Risk Register Management
- Security Assessment Methodologies
- Compliance Reporting
Leadership Skills
- Executive Stakeholder Management
- Strategic Thinking
- Team Leadership
- Influencing Skills
- Communication & Presentation
- Change Management
The Job responsibilities of the candidate shall include but not limited to the Job Description & to perform any other tasks/functions as required by the Company.
📌 Senior Manager - Enterprise Risk Management (Mumbai)
🏢 Aeries Technology
📍 Mumbai