Director, Governance, Risk & Compliance, ITC

Nike Inc

Bengaluru

On-site

INR 3,000,000 - 6,000,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Nike Inc. in Bengaluru hosts a senior GRC leadership role within the India Technology Center. You will lead a large direct-report team, drive GRC programs, and align with Global GRC to advance risk and compliance across enterprise platforms.

You will partner with technology, finance, audit and legal leaders to mature standards, controls, and reporting, while delivering risk-based improvements across regions.

Qualifications

  • 5+ years people management with 15+ direct reports.
  • 12+ years in technology risk, cybersecurity risk, IT audit, or GRC.
  • Proven track record building functional teams across time zones.
  • Strong talent development and cross-functional collaboration.
  • Experience leading in a highly matrixed environment with peers and senior leaders.

Responsibilities

  • Lead a large direct-report GRC team and set operating rhythm.
  • Deliver GRC outcomes for India Technology Center and global priorities.
  • Build strong cross-region partnerships with Global GRC and Tech teams.
  • Extend cybersecurity training and awareness to ITC teams.
  • Support SOX and cybersecurity regulatory obligations with a global lens.
  • Advance Nike's third-party cyber risk model across India and global delivery.
  • Govern cybersecurity risk assessments for high-impact global initiatives.
  • Govern technical recovery alignment for critical services across footprints.
  • Drive end-to-end governance and risk lifecycle management.
  • Strengthen ServiceNow GRC workflows, libraries, attestations, and reporting.
  • Represent India tech leadership in Global GRC and enterprise risk decisions.

Skills

People leadership at scale
Global GRC experience
ServiceNow GRC proficiency
Cybersecurity risk assessments
Matrixed leadership & partnerships

Education

Bachelor's degree
Advanced degree or certifications (CISSP, CISM, CRISC, CISA)

Tools

ServiceNow GRC

Job description

WHO YOU WILL WORK WITH

TheDirector of Governance, Risk and Compliance (GRC)extends Nike’sGlobal GRCteam and is accountable forGRC leadership spanning the India Technology Center and global enterprise priorities. This is a critical leadership role responsible for strengtheningcompliance(with emphasis onSOXand

cybersecurity regulations),risk management(with emphasis onthird-party cyber riskandcybersecurity risk assessments),governance(includingrisk lifecycle managementand therisk register in ServiceNow GRC), andtechnical recovery management—while helping matureglobal standards, tooling, assurance, and reportingin partnership withGlobal GRC,Global Technology, andcross-functional leadersacross finance, audit, legal, procurement, and security/risk forums as applicable.

WHO WE ARE LOOKING FOR

The candidate needs to havelarge-scale, enterprise GRC experienceinhighly matrixed, multinational technology organizationswith sustained impact across the domains above. The candidate needs to be bothdeeply experienced in global GRC practice and platforms(notablyServiceNow GRC) andhighly skilled in people leadership, includingmultiple years managing a large team of direct reports (typically 15+)with a proven record ofbuilding highly functional teams,developing talent, anddriving trust-based teamwork and cross-functional collaborationwith peers and senior leaders.

  • People leadership at scale (direct reports)—5+ years people managementwith accountability for alarge team of direct reports (typically 15+), including hiring, performance management, coaching, and organizational design that scales quality and speed.
  • Leadership & technical depth—12+ yearsin technology risk, cybersecurity risk, IT audit, and/or GRC, with sustained impact on complex, globaltechnology and risk agendas.
  • Building highly functional teams— Proven track recordbuilding highly functional teams: clear roles, operating rhythm, quality bar, and sustainable ways of working across time zones.
  • Talent development & culture— Demonstrated successdeveloping talent(coaching, progression, succession depth) and fostering apositive team culturegrounded intrust,teamwork, andcross-functional collaboration.
  • Matrixed leadership & partnerships— Extensive experience leading and influencing in ahighly matrixed environment; proven ability tobuild strong relationships and partnershipswithpeers and senior leadersacross technology, finance, legal, procurement, audit, and global GRC—while maintaining clarity and accountability fordirect reports.
  • Global + regional operating model— Demonstrated success balancingglobal consistency(policy, platform, metrics) withIndia delivery realitiesand effective partnership across geographies.
  • GRC program execution— Proven experience running components of a global GRC program(policies, standards, exceptions, metrics, governance forums) with accountability for outcomes beyond a single site.
  • Compliance— Strong command ofSOX IT/general controlsand evidence practices; familiarity withcybersecurity regulations and assurance expectationsfor multinational technology organizations.
  • Cybersecurity frameworks & control standards— Deep knowledge of cybersecuritycontrol and compliance frameworks(for example,NIST CSFandISO 27001) and practical experience applying them toenterprise control environments, risk prioritization, and assurance.
  • Third-party cyber risk— Deep experience inglobal third-party cyber riskprograms (tiering, diligence, contractual security requirements, issue management, reporting), including offshore/nearshore delivery contexts.
  • Cybersecurity risk assessments— Experience leading, governing, or quality-reviewingcyber and technology risk assessmentsfor global platforms and initiatives, aligned to enterprise risk appetite.
  • Technical recovery / resilience— Experience governingtechnical recoveryalignment across critical services and regions (DR/BCP expectations, testing governance, RTO/RPO discipline, coordination with incident/resilience teams).
  • Governance & risk lifecycle— Expertise inend-to-end risk lifecyclemanagement andrisk registerquality (ownership, scoring, treatment plans, monitoring, closure) at enterprise scale.
  • ServiceNow GRC— Strong hands‑on experience withServiceNow GRC(or comparable platforms), including workflow improvement, libraries, attestations, dashboards, and adoption across distributed owners globally.
  • Education— Bachelor’s degree required; advanced degree or certifications a plus (e.g., CISSP, CISM, CRISC, CISA, GRCP).
WHAT YOU WILL WORK ON

Lead a large direct-report GRC team for Nike’s India Technology Center in support of global priorities in a highly matrixed model. Drive compliance, third-party cyber risk, assessments, technical recovery, ServiceNow GRC governance, global partnership, and KPIs across the enterprise.

  • Direct-report leadership (scale + culture)— Lead, organize, and develop alarge team of direct reports (15+), including operating rhythm, quality expectations, and career growth; role-modeltrust,collaboration, andinclusive teamworkwhile investing intalent developmentand a healthy team culture.
  • Dual-scope leadership— Deliver GRC outcomes for theIndia Technology Centerwhile contributing materially toglobal GRC priorities(standards, governance cadence, escalations, cross-region coordination).
  • Matrix partnership— Operate effectively across ahighly matrixed modelby aligning priorities, clarifying decision paths, and sustainingstrong partnershipswith peers and senior leaders globally.
  • Cybersecurity training & awareness (ITC)— Extendglobal cybersecurity training and awarenesscapabilities, programs, and stakeholderengagementsto theIndia Technology Center (ITC), driving adoption, relevance for local audiences, and sustained participation while staying aligned toenterprise standards, campaigns, and reporting expectations.
  • Compliance (SOX & cybersecurity regulations)— SupportSOXand applicablecybersecurity regulatoryobligations with a global lens: sustainable control operation, testing readiness, issue remediation, and coordination with Finance, Internal Audit, Legal, and Global GRC.
  • Third-party cyber risk— Advance Nike’sthird-party cyber riskmodel across engagements relevant to India and global technology delivery, with consistent global rigor and clear remediation ownership.
  • Cybersecurity risk assessments— Govern and/or sponsorcybersecurity risk assessmentsfor high-impact global initiatives and platforms; ensure outputs are prioritized, actionable, and aligned toglobal risk appetite.
  • Technical recovery management— Governtechnical recoveryalignment for critical services acrossglobal and India-supported footprints: standards adherence, testing governance, evidence expectations, and remediation of resilience gaps.
  • Governance & risk lifecycle— Ensure disciplinedrisk lifecycle managementand credibleenterprise risk registerposture for priorities owned or heavily supported from India; drive accountability withglobal and regionalrisk and control owners.
  • ServiceNow GRC— Partner across Global GRC and technology teams to strengthenServiceNow GRCusage: workflows, libraries, attestations, reporting, anddata qualityin support of risk lifecycle, assurance, and audit readiness.
  • Global partnership & representation— Serve as a trusted bridge between India technology leadership and Global GRC—surfacing themes early, aligning priorities, and enabling timely enterprise risk decisions.
  • Metrics— Define and socializeglobal-relevant GRC KPIs/KRIsfocused on risk reduction, control effectiveness, and remediation closure where India contributes materially; reinforce pragmatic controls and early risk engagement in engineering and vendor workflows worldwide.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Information Security Analyst, ITC
Lead Information Security Analyst, ITC

Nike • Karnataka

On-site
INR 3,500,000 - 4,500,000
Director of Cyber Defense Operations , ITC
Director of Cyber Defense Operations , ITC

Nike Inc • India

On-site
INR 4,500,000 - 7,500,000
GRC Lead
GRC Lead

Baldor Technologies • Mumbai

On-site
INR 300,000 - 600,000
GRC - Security Analyst
GRC - Security Analyst

Jobgether • India

On-site
INR 1,200,000 - 1,800,000
Fully remote in India
Full-time employment
Exposure to multiple security framesk—
+2
Senior Role - GRC & Infosec
Senior Role - GRC & Infosec

NPCI Bharat BillPay Limited • Mumbai

On-site
INR 2,000,000 - 3,000,000
Senior GRC Consultant - Contract
Senior GRC Consultant - Contract

Jobgether SRL • India

Remote
INR 1,674,000 - 2,344,000
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

844 Altera Semiconductor Technology India Pvt. Ltd. • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Governance, Risk & Compliance (GRC) Specialist
Governance, Risk & Compliance (GRC) Specialist

Guideline Inc • Pune District

On-site
INR 2,250,000 - 2,750,000
Travel up to 10%
US shift
GRC Lead / Security Compliance Lead
GRC Lead / Security Compliance Lead

Gnani Innovations Private Limited. • India

On-site
INR 350,000 - 600,000
GRC Consultant @ Mumbai
GRC Consultant @ Mumbai

Quess IT Solutions • Mumbai

On-site
INR 1,800,000 - 2,400,000