Professional, Cyber Risk & GRC (Bengaluru)

Professional, Cyber Risk & GRC (Bengaluru)

14 Sep
|
Zinnov Management Consulting
|
Bengaluru

14 Sep

Zinnov Management Consulting

Bengaluru

Zinnov is hiring for the role of Professional, Cyber Risk & GRC on behalf of our Global MNC MedTech client company - a company where technology sits at the center of everything: powering how the core business operates day to day and shaping the products and digital solutions that will define the future of patient care. This role is part of the companys establishment of their recent India Global Capability Centre (GCC) in Bengaluru which will drive enterprise technology, digital transformation and innovation for its global operations and contributing to technology that ultimately helps millions of people around the world.

What you'll do

As a Professional, Cyber Risk & GRC, you will support DePuy Synthes' cybersecurity GRC function with a primary focus on third-party risk management, cyber control assessments, enterprise risk tracking, and cyber risk support for acquired-company integrations.

How you'll make an impact

- Execute the full TPRM lifecycle, including vendor intake and classification, due diligence, risk assessment, remediation, ongoing monitoring, reassessment, and offboarding.
- Conduct internal and external cybersecurity risk assessments across systems, services, and vendors.
- Assess IAM, data protection, vulnerability management, incident response, logging, cloud security, and resilience controls.
- Identify control gaps, determine inherent and residual risk, evaluate compensating controls, and support risk acceptance decisions.
- Maintain the enterprise cyber risk register and track risks through remediation, acceptance, or closure.
- Review vendor evidence, challenge gaps or unsupported claims, and coordinate timely remediation with vendors and internal owners.
- Partner with Procurement, Legal, Privacy, Audit, Compliance, business owners, and vendors throughout assessments and remediation.
- Support cybersecurity due diligence and risk tracking for acquired-company integrations in partnership with Legal and IT Integrations teams.




- Maintain audit-ready evidence and support internal audits, external audits, and regulatory inquiries related to vendor and enterprise risk.
- Develop concise findings, KPIs, KRIs, dashboards, and executive-ready updates that translate technical issues into business risk.
- Manage assessment priorities, vendor portfolios, deadlines, and process improvements to strengthen execution and scalability.

What you'll bring

Experience

- 5 years of experience in GRC, vendor or third-party risk management, cyber risk assessment, IT audit, risk register management, or cybersecurity risk support for acquired company integrations.
- Hands-on knowledge of the TPRM lifecycle: intake and classification, due diligence, risk assessment, remediation, ongoing monitoring, reassessment, and offboarding.
- Ability to assess cybersecurity controls across IAM, data protection, vulnerability management, incident response, logging, cloud security, and operational resilience.
- Strong risk analysis and judgment, including identifying control gaps, assessing inherent and residual risk, evaluating compensating controls, and supporting risk acceptance decisions.
- Working knowledge of NIST CSF, ISO 27001, NIST SP 800-53, NIST SP 800-161, SOC reports, privacy requirements, and relevant regulatory obligations.
- Experience collaborating with cross-functional teams such as Legal, IT, or compliance

Skills:

- Working knowledge of vendor/third-party risk management (TPRM) processes and tools such as ServiceNow TPRM/GRC, OneTrust, Archer, CyberGRX, AuditBoard, or a comparable workflow and risk platform.
- Familiarity with GRC frameworks and standards (NIST, ISO 27001, or similar)
- Strong analytical and reporting skills, with the ability to translate risk findings into clear, actionable recommendations
- Experience supporting IT integrations or cybersecurity due diligence for mergers and acquisitions is a plus.

If you're excited about this opportunity and passionate about solving meaningful challenges, collaborating with global teams and contributing to innovation in healthcare, please apply!

📌 Professional, Cyber Risk & GRC (Bengaluru)
🏢 Zinnov Management Consulting
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: professional, cyber risk & grc (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: professional, cyber risk & grc (bengaluru) / bengaluru