Associate Director - Information Security & GRC

Talent Hired-the Job Store

Gurugram District, Delhi

On-site

INR 600,000 - 900,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Taggd is seeking an Associate Director - Information Security & GRC to own information security, cybersecurity, and governance, risk & compliance for Taggd and group companies. You are the primary contact for enterprise customers on diligence for TARA, Taggd's AI recruitment engine.

You will define security policies, establish standards (identity, endpoint, network, cloud, logging, incident response), work with the DPO on privacy, and coordinate with Product and Engineering for data residency

Qualifications

  • 10+ years in information security and GRC, including hands-on cybersecurity, not paper GRC only.
  • Practical depth in at least two: incident response, identity and access, vulnerability management, cloud security.
  • ISO 27001 program ownership: you have built an ISMS, not only audited one.
  • SOC 2 Type II program or evidence work.
  • Audit lifecycle management: internal and external, including evidence collection and control testing.
  • Hands-on enterprise customer due diligence: security questionnaires, RFPs, and security reviews.
  • DPDP (or equivalent privacy law) in a real operating context.
  • SaaS / multi-tenant product experience.
  • Comfort speaking with enterprise CISOs and security reviewers.
  • Based in Gurgaon / NCR, or willing to work from Taggd HQ.

Responsibilities

  • Write and run information security policy across Taggd and group companies.
  • Extend ISO 27001, SOC 2 Type II, and ISO 42001 across Taggd and group companies as needed.
  • Own DPDP readiness with the DPO.
  • Lead TARA customer security questionnaires and RFP security responses: data residency, model-training claims, DPDP, and related due diligence.
  • Build third-party risk management (TPRM) for vendors that touch Taggd and group companies data.
  • Run risk assessments. Keep a live risk register, track remediation, and report to stakeholders.
  • Own the audit lifecycle for internal, customer, and certification audits: evidence collection, control testing, and response.
  • Set cybersecurity controls: identity and access, endpoint, network, and cloud. IT implements. You do not run that team.
  • Own identity and access: access reviews, privileged access, joiners / movers / leavers.
  • Own vulnerability and patch posture: the standard, the tracking, the exceptions. IT executes.
  • Own incident response: playbook, severity, who is called, post-incident review.

Skills

InfoSec
GRC
Incident response
Identity & access
Vulnerability management
Cloud security

Job description

Associate Director - Information Security & GRC

Company: Taggd

Location: Gurgaon (M3M Broadway, Sector 71)

Work mode: Office, based at Taggd HQ

About Taggd

Taggd is a digital recruitment platform that provides Ready-to-Hire talent to India Inc. Combining the power of human knowledge and data, Taggd has successfully fulfilled talent mandates of more than 100+ clients and ensured hiring managers' success for half a million jobs from 14+ sectors. With a vision to fulfil 1 million jobs through our talent platform by 2030, we strive to connect people with people, people with companies, and people with opportunities.

The role

You own information security, cybersecurity, and GRC for Taggd and group companies, and you are the person enterprise customers talk to when they diligence TARA, Taggd's agentic AI recruitment engine.

You will define the Information Security policies and set the cybersecurity standard (identity, endpoint, network, cloud, logging, incident response). IT runs the estate to the policies & standards. You work with the DPO on privacy, and with Product and Engineering when a customer or auditor asks how TARA handles data, residency, and model use.

More on TARA: https://taggd.in/recruitment-model/tara-ai/

What you will do
  • Write and run information security policy across Taggd and group companies.
  • Extend ISO 27001, SOC 2 Type II, and ISO 42001 across Taggd and group companies as needed.
  • Own DPDP readiness with the DPO.
  • Lead TARA customer security questionnaires and RFP security responses: data residency, model-training claims, DPDP, and related due diligence.
  • Build third-party risk management (TPRM) for vendors that touch Taggd and group companies data.
  • Run risk assessments. Keep a live risk register, track remediation, and report to stakeholders.
  • Own the audit lifecycle for internal, customer, and certification audits: evidence collection, control testing, and response.
  • Set cybersecurity controls: identity and access, endpoint, network, and cloud. IT implements. You do not run that team.
  • Own identity and access: access reviews, privileged access, joiners / movers / leavers.
  • Own vulnerability and patch posture: the standard, the tracking, the exceptions. IT executes.
  • Own incident response: playbook, severity, who is called, post-incident review.
What you need
  • 10+ years in information security and GRC, including hands-on cybersecurity, not paper GRC only.
  • Practical depth in at least two of: incident response, identity and access, vulnerability management, cloud security.
  • ISO 27001 program ownership: you have built an ISMS, not only audited one.
  • SOC 2 Type II program or evidence work.
  • Audit lifecycle management: internal and external, including evidence collection and control testing.
  • Hands-on enterprise customer due diligence: security questionnaires, RFPs, and security reviews.
  • DPDP (or equivalent privacy law) in a real operating context.
  • SaaS / multi-tenant product experience.
  • Comfort speaking with enterprise CISOs and security reviewers.
  • Based in Gurgaon / NCR, or willing to work from Taggd HQ.
Nice to have
  • CISA, CISM, CISSP, or CIPP.
  • Hands-on cloud security (AWS or equivalent).
  • ISO 42001.
  • Security review of GenAI or agentic systems.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Lead / Security Compliance Lead
GRC Lead / Security Compliance Lead

Gnani Innovations Private Limited. • India

On-site
INR 350,000 - 600,000
Technical Manager
Technical Manager

Incedo Inc. • Gurugram District

On-site
INR 2,500,000 - 5,000,000
Senior Security & Compliance Lead – Certifications & GRC
Senior Security & Compliance Lead – Certifications & GRC

PETADATA • Hyderabad

On-site
INR 400,000 - 700,000
Lead -Governance, Risk and Compliance (GRC)
Lead -Governance, Risk and Compliance (GRC)

ARCON • Mumbai

On-site
INR 1,500,000 - 2,500,000
Senior Manager – Digital, Cyber Security (GRC)
Senior Manager – Digital, Cyber Security (GRC)

Tata Consumer Products • Bengaluru

On-site
INR 1,500,000 - 1,900,000
Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

Power Bridge • Arishinakunte

On-site
INR 1,200,000 - 2,400,000
Health insurance
Long-term savings plan with employer’匹
Professional development opportunities
GRC Lead
GRC Lead

Baldor Technologies • Mumbai

On-site
INR 300,000 - 600,000
Assistant Vice President- GRC
Assistant Vice President- GRC

Nykaa • Gurugram District

On-site
INR 2,200,000 - 2,800,000
Senior Security GRC & ISO 27001 Manager
Senior Security GRC & ISO 27001 Manager

UST • Thiruvananthapuram

On-site
INR 1,500,000 - 2,100,000
Infosec Analyst
Infosec Analyst

super.money • Bengaluru

On-site
INR 900,000 - 1,500,000
Competitive compensation
Shape GRC for a top UPI company in I