Role Purpose: Responsible for ensuring appropriate information security governance within the internal and third party-controlled environments. The role is also responsible for supporting the enterprise control workplace by ensuring compliance to Policies, procedures and other related documents are defined and updated , assuring Risks are identified and managed, applicable Controls are tested as per defined framework, Exceptions are recorded & remediated on-time, Control Data is analyzed and used for continuous improvement and optimization. InfoSec being a governance function for Risk Management, GRC lead is expected to manage First Party, Second Party and Third Party risk management activities & Internal/external audits per defined framework in accordance to regulatory requirement, under direction of CISO & ERM
Role Accountability
• Develop GRC operating model and enterprise-wide security policies and operationalize various GRC capability areas such as enterprise security risk management, compliance management, policy management, security awareness training, third party risk management,
and metrics and reporting
• Develop measures and metrics to evaluate the information security programs / Information Security Exception Management/ standards including ISO 27001, PCI-DSS, NIST CSF, COBIT etc. and modifies strategies as appropriate
• Lead the operationalization of security compliance programs to support various compliance regulations
• Perform risk assessments that address security threats, changes to systems and/or applications, process improvement initiatives, supplier assessments (including downstream outsourcers) and other requests from the business
• Maintain accurate reporting of remediation activities to bring appropriate visibility to stakeholders
• Monitor the security risk profiles of suppliers/ third party vendors to objectively determine high risk suppliers that require additional review
• Respond to customer security/compliance questionnaires
• Ensure