Assistant Vice President- GRC

Nykaa

Gurugram District

On-site

INR 2,200,000 - 2,800,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

A leading consumer-tech company in India is seeking an experienced Information Security Manager. In this role, you will maintain the GRC and Data Protection program, ensuring compliance with laws and implementing policies. The ideal candidate has over 9 years of experience in Information Security, including 5 years specifically in Governance, Risk, and Compliance (GRC). You will lead security initiatives and engage with stakeholders to promote effective information security practices.

Qualifications

  • 9+ years in Information Security with a minimum of 5 years in GRC.
  • Strong understanding of information security principles and compliance.
  • Demonstrated ability to lead change within an organization.

Responsibilities

  • Maintain a robust GRC & Data Protection program.
  • Implement InfoSec policies, procedures, and standards.
  • Ensure compliance with laws and standards related to information security.

Skills

Information Security Management
Risk Management
Communication Skills
Analytical Skills
Vendor Risk Management

Education

Graduate in Computer Science or Information Security
Relevant certifications (CISSP, CISM, CISA)

Tools

ISO 27001
NIST Cyber Security Framework

Job description

Location- Gurgaon

Work Model- 5 days from Office

Company Description

Nykaa is a digitally native, consumer-tech company that offers a wide range of beauty, personal care and fashion products. Since its inception in 2012, Nykaa has disrupted the beauty retail market in India and captured the hearts of millions of customers. Besides offering engaging and educational content, we have diversified our offerings through other online platforms like Nykaa Fashion, Nykaa Man, and Superstore.

Key Responsibilities
  • Maintain a robust GRC & Data Protection program that aligns with organizational goals and objectives.
  • Developing and implementing InfoSec policies, procedures, and standards
  • To assess the security posture of the organization by using Cyber‑Security Framework such as NIST
  • Ensuring that information security risks are identified, assessed, and managed appropriately, and that appropriate controls are in place to mitigate these risks.
  • Establishing and maintaining relationships with stakeholders across the organization, including senior leadership, business units, and other key stakeholders, to promote information security best practices and awareness.
  • Leading the information security awareness and training programs for employees to ensure that they understand their roles and responsibilities in maintaining the security of information assets.
  • Ensuring that the organization is compliant with relevant laws, regulations, and standards related to information security, such as IT Act, Cert‑In, PCI, etc.
  • Lead the implementation of ISO 27001 Information Security Management System.
  • Govern the third‑party risk management program, ensuring comprehensive assessment, monitoring, and mitigation strategies to safeguard the organization.
  • Set governance rigor including regular updates for management, publishing dashboards including metrics for monitoring effectiveness of the organization’s information security program.
Qualification/Skill
  • Graduate in Computer Science, Information Security
  • Relevant certifications (e.g., CISSP, CISM, CISA) are a plus.
  • 9+ years in Information Security with minimum 5 years of experience in GRC
  • Experience in managing vendor risk management program
  • Strong understanding of information security principles, risk management, and compliance requirements
  • Experience with industry frameworks and standards (ISO 27001, NIST, etc.).
  • Excellent communication and interpersonal skills, with the ability to collaborate with cross‑functional teams.
  • Demonstrated ability to lead and drive change within an organization.
  • Strong analytical and problem‑solving skills.
  • Ability to handle confidential information
  • Ethical, with the ability to remain impartial and report all noncompliance
  • Organizational skills with attention to detail
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Manager/ AVP- GRC
Senior Manager/ AVP- GRC

T&m • Mumbai

On-site
INR 4,500,000 - 6,500,000
Information Security GRC Consultant
Information Security GRC Consultant

Aarcalev Technology Solutions • India

Remote
INR 900,000 - 1,500,000
Fully remote role
Exposure to global compliance frameworks
Professional growth opportunities
Associate Director - Information Security & GRC
Associate Director - Information Security & GRC

Talent Hired-the Job Store • Gurugram District, Delhi

On-site
INR 600,000 - 900,000
GRC Lead
GRC Lead

Baldor Technologies • Mumbai

On-site
INR 300,000 - 600,000
Senior Manager/ AVP- GRC
Senior Manager/ AVP- GRC

T&M Services Consulting Pvt Ltd • Mumbai

On-site
INR 4,500,000 - 6,500,000
Technical Manager
Technical Manager

Incedo Inc. • Gurugram District

On-site
INR 2,500,000 - 5,000,000
Cybersecurity Lead - GRC
Cybersecurity Lead - GRC

Medusind • Mumbai

On-site
INR 2,500,000 - 4,500,000
Lead -Governance, Risk and Compliance (GRC)
Lead -Governance, Risk and Compliance (GRC)

ARCON • Mumbai

On-site
INR 1,500,000 - 2,500,000
Senior Role - GRC & Infosec
Senior Role - GRC & Infosec

NPCI Bharat BillPay Limited • Mumbai

On-site
INR 2,000,000 - 3,000,000
GRC Solution Consultant
GRC Solution Consultant

LTM • Sector 10

Hybrid
INR 4,000,000 - 6,500,000