Lead InfoSec Audit and GRC (Kochi)

Lead InfoSec Audit and GRC (Kochi)

12 Sep
|
InApp
|
Kochi

12 Sep

InApp

Kochi

Experience : 7-10 Years Project Location(s) : Trivandrum / Kochi

Work mode: Hybrid/ Remote ( Quarterly 5 days in office for Remote Employees)

Number of Openings: 1

Risk Management

- Lead Information Security and IT risk management activities across the organisation.
- Oversee identification, assessment, treatment and ongoing monitoring of information security risks.
- Provide independent risk advisory to Risk Owners, business and technology stakeholders.
- Monitor residual risk, emerging threats, risk trends and overall organisational risk exposure.
- Report the Information Security risk posture, material risks and key risk indicators to Senior Management.

Compliance & Regulatory Management

- Govern the organisation’s continuous compliance and assurance readiness across ISO 27001, ISO 42001, SOC 2 and PCI DSS.
- Maintain alignment with applicable GDPR, HIPAA, contractual and other regulatory requirements.
- Oversee compliance assessments, control-gap analysis and remediation of identified deficiencies.
- Maintain an integrated control framework and control mappings across GRC platforms including Vanta and Drata.
- Ensure the control environment evolves in line with regulatory developments, emerging AI governance requirements and changes to the organisation’s risk profile.

Audit & Assurance Management

- Lead the organisation’s year-round Information Security audit and assurance programme.
- Conduct internal Information Security audits and coordinate external audits, certification assessments and independent assurance engagements.
- Provide assurance across ISO 27001, ISO 42001, SOC 2 and PCI DSS requirements.
- Oversee periodic security assurance reviews across enterprise and third-party technology environments.
- Maintain governance over the complete audit lifecycle and provide independent advisory on findings, corrective actions and compensating controls.
- Provide assurance over the adequacy and effectiveness of remediation arising from audit and security-review activities.

Security Control Assurance

- Govern the design,



implementation control framework.
- Assess control effectiveness and identify material control deficiencies or areas requiring enhancement.
- Work with Control Owners and relevant stakeholders to drive sustainable remediation of control gaps.
- Define additional, compensating or custom controls where required to address identified risk.
- Maintain oversight of the organisation’s overall control-effectiveness posture. Policy & GRC Governance
- Own the development, maintenance and governance of Information Security policies, standards and supporting frameworks.
- Ensure the policy framework remains aligned with business objectives, security risks and applicable regulatory and assurance requirements.
- Govern policy ownership, periodic review, exceptions and associated risk acceptance.
- Maintain clear security governance, accountability and control ownership across the organisation.

Third-Party Risk Management

- Manage Information Security risk n and ongoing effectiveness of the organisation’s Information Security management across the third-party tools used by the organization.
- Oversee security due diligence, risk assessment and periodic assurance of critical and relevant third parties.
- Assess third-party control environments and residual security risk based on independent assurance and other relevant evidence.
- Provide risk advisory on third-party remediation, compensating controls and risk-treatment decisions.
- Oversee security due diligence, risk assessment and periodic assurance of vendors, service providers and third-party applications. Customer Security Assurance & Trust Centre




- Lead customer-facing Information Security assurance and due-diligence activities.
- Provide governance over the organisation’s security and compliance assurance information provided to customers and external stakeholders.
- Build and maintain the organisation’s Trust Centre as the authoritative source for security, privacy and compliance assurance.
- Ensure customer assurance commitments remain consistent with the organisation’s actual control and compliance posture.

Data Security & Governance

- Provide governance and assurance over enterprise data-security and data-protection controls.
- Oversee data classification, information protection, Data Loss Prevention and related data-security requirements.
- Govern the use of Microsoft Purview and associated data-protection capabilities as part of the broader Information Security control setting.
- Assess data-security risks and provide assurance over the effectiveness of associated controls.
- Ensure data-security governance remains aligned with applicable security, privacy and regulatory requirements.

Reporting & Senior Management Assurance

- Provide independent reporting to Senior Management on the organisation’s Information Security risk, compliance, audit and control-assurance posture.
- Establish meaningful KPIs, KRIs, metrics and assurance scorecards to measure the effectiveness of the GRC programme.
- Highlight material risks, control weaknesses, compliance exposures and significant remediation concerns requiring management attention.
- Provide consolidated assurance and recommendations to support risk-based Senior Management decision-making.

Preferred Skills

- Experience with GRC and compliance platforms such as Vanta and Drata.
- Understanding of AI governance and evolving AI regulatory requirements.
- Knowledge of enterprise data-security governance, Microsoft Purview and Data Loss Prevention.
- Strong stakeholder management, risk advisory and Senior Management reporting capabilities.

📌 Lead InfoSec Audit and GRC (Kochi)
🏢 InApp
📍 Kochi

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: lead infosec audit and grc (kochi) / kochi