Experience : 7-10 Years Project Location(s) : Trivandrum / Kochi
Work mode: Hybrid/ Remote ( Quarterly 5 days in office for Remote Employees)
Number of Openings: 1
Risk Management
- Lead Information Security and IT risk management activities across the organisation.
- Oversee identification, assessment, treatment and ongoing monitoring of information security risks.
- Provide independent risk advisory to Risk Owners, business and technology stakeholders.
- Monitor residual risk, emerging threats, risk trends and overall organisational risk exposure.
- Report the Information Security risk posture, material risks and key risk indicators to Senior Management.
Compliance & Regulatory Management
- Govern the organisation’s continuous compliance and assurance readiness across ISO 27001, ISO 42001, SOC 2 and PCI DSS.
- Maintain alignment with applicable GDPR, HIPAA, contractual and other regulatory requirements.
- Oversee compliance assessments, control-gap analysis and remediation of identified deficiencies.
- Maintain an integrated control framework and control mappings across GRC platforms including Vanta and Drata.
- Ensure the control environment evolves in line with regulatory developments, emerging AI governance requirements and changes to the organisation’s risk profile.
Audit & Assurance Management
- Lead the organisation’s year-round Information Security audit and assurance programme.
- Conduct internal Information Security audits and coordinate external audits, certification assessments and independent assurance engagements.
- Provide assurance across ISO 27001, ISO 42001, SOC 2 and PCI DSS requirements.
- Oversee periodic security assurance reviews across enterprise and third-party technology environments.
- Maintain governance over the complete audit lifecycle and provide independent advisory on findings, corrective actions and compensating controls.
- Provide assurance over the adequacy and effectiveness of remediation arising from audit and security-review activities.
Security Control Assurance
- Govern the design,
implementation control framework.
- Assess control effectiveness and identify material control deficiencies or areas requiring enhancement.
- Work with Control Owners and relevant stakeholders to drive sustainable remediation of control gaps.
- Define additional, compensating or custom controls where required to address identified risk.
- Maintain oversight of the organisation’s overall control-effectiveness posture. Policy & GRC Governance
- Own the development, maintenance and governance of Information Security policies, standards and supporting frameworks.
- Ensure the policy framework remains aligned with business objectives, security risks and applicable regulatory and assurance requirements.
- Govern policy ownership, periodic review, exceptions and associated risk acceptance.
- Maintain clear security governance, accountability and control ownership across the organisation.
Third-Party Risk Management
- Manage Information Security risk n and ongoing effectiveness of the organisation’s Information Security management across the third-party tools used by the organization.
- Oversee security due diligence, risk assessment and periodic assurance of critical and relevant third parties.
- Assess third-party control environments and residual security risk based on independent assurance and other relevant evidence.
- Provide risk advisory on third-party remediation, compensating controls and risk-treatment decisions.
- Oversee security due diligence, risk assessment and periodic assurance of vendors, service providers and third-party applications. Customer Security Assurance & Trust Centre
- Lead customer-facing Information Security assurance and due-diligence activities.
- Provide governance over the organisation’s security and compliance assurance information provided to customers and external stakeholders.
- Build and maintain the organisation’s Trust Centre as the authoritative source for security, privacy and compliance assurance.
- Ensure customer assurance commitments remain consistent with the organisation’s actual control and compliance posture.
Data Security & Governance
- Provide governance and assurance over enterprise data-security and data-protection controls.
- Oversee data classification, information protection, Data Loss Prevention and related data-security requirements.
- Govern the use of Microsoft Purview and associated data-protection capabilities as part of the broader Information Security control setting.
- Assess data-security risks and provide assurance over the effectiveness of associated controls.
- Ensure data-security governance remains aligned with applicable security, privacy and regulatory requirements.
Reporting & Senior Management Assurance
- Provide independent reporting to Senior Management on the organisation’s Information Security risk, compliance, audit and control-assurance posture.
- Establish meaningful KPIs, KRIs, metrics and assurance scorecards to measure the effectiveness of the GRC programme.
- Highlight material risks, control weaknesses, compliance exposures and significant remediation concerns requiring management attention.
- Provide consolidated assurance and recommendations to support risk-based Senior Management decision-making.
Preferred Skills
- Experience with GRC and compliance platforms such as Vanta and Drata.
- Understanding of AI governance and evolving AI regulatory requirements.
- Knowledge of enterprise data-security governance, Microsoft Purview and Data Loss Prevention.
- Strong stakeholder management, risk advisory and Senior Management reporting capabilities.
📌 Lead InfoSec Audit and GRC (Kochi)
🏢 InApp
📍 Kochi