GRC Assurance Partner

Sandoz India

Telangana

Hybrid

INR 1,800,000 - 3,000,000

Full time

3 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Competitive compensation
Flexible/hybrid working
Health & wellness benefits
Learning & development programs
Global career opportunities
Inclusive culture

Job summary

Sandoz India seeks an experienced Information Security / Risk Compliance leader to steward the ISRC program across regions and product domains. You will guide security requirements with business and technology stakeholders, drive governance frameworks, and oversee remediation of findings and risk exceptions.

An emphasis on executive reporting and cross-functional collaboration is required. The role requires deep knowledge of ISO 27001, NIST, and CIS Controls, with 15+ years in information

Qualifications

  • Bachelor’s degree or equivalent experience in Computer Science, Information Technology, Engineering, or related discipline.
  • Minimum 15 years of experience in information security, technology risk management, or related field.
  • Proven experience partnering with business and technology teams across regional or enterprise portfolios.
  • Strong knowledge of information security frameworks and standards such as ISO 27001, NIST, and CIS Controls.
  • Experience applying security and risk management principles across product development, cloud environments, and third-party ecosystems.
  • Demonstrated ability to manage governance processes, risk assessments, audits, compliance activities, and executive reporting.
  • Strong program and project management capabilities with experience handling multiple priorities and stakeholders.
  • Ability to translate technical security risks into business impact and influence decision-making at multiple organizational levels.
  • Essential Skills: Excellent communication, stakeholder management, consulting, collaboration, and continuous improvement mindset with ability to influence without direct authority.
  • Languages: Fluent written and spoken English.
  • Professional certifications such as CISSP, CISM, CISA, or equivalent information security credentials.
  • Experience with privacy regulations, regulatory compliance requirements, and pharmaceutical industry environments.

Responsibilities

  • Serve as the primary ISRC contact for assigned regions and supported product domains/functions, providing practical guidance on security, compliance, and risk-related matters.
  • Partner with business and technology leadership to define security requirements, support prioritization, and promote risk-based decision-making.
  • Drive the adoption and consistent implementation of ISRC processes, controls, and governance frameworks across supported areas.
  • Manage the security and compliance posture of technology assets and services, ensuring ownership, accountability, and adherence to defined security requirements.
  • Support security control implementation by advising on control design, facilitating evidence collection, and coordinating with control owners and security architects.
  • Manage control deficiencies and security findings through remediation, tracking, validation, and timely closure.
  • Administer the risk exception process, ensuring appropriate approvals, compensating controls, periodic reviews, and remediation activities.
  • Support audits, compliance assessments, asset classification activities, third-party risk reviews, and security awareness initiatives while providing executive-level security reporting and metrics.
  • KPI: Percentage of security findings, control deficiencies, and risk exceptions closed within agreed timelines.

Skills

Information security
Risk management
Governance
Stakeholder management
Communication
Project management
Cloud security
ISO 27001 knowledge
NIST
CIS Controls
English proficiency

Education

Bachelor’s degree in Computer Science / IT / Engineering

Tools

ISO 27001
NIST
CIS Controls
CISSP
CISM
CISA

Job description

Your Key Responsibilities

Your responsibilities include, but not limited to:

  • Serve as the primary ISRC contact for assigned regions and supported product domains/functions, providing practical guidance on security, compliance, and risk-related matters.
  • Partner with business and technology leadership to define security requirements, support prioritization, and promote risk-based decision-making.
  • Drive the adoption and consistent implementation of ISRC processes, controls, and governance frameworks across supported areas.
  • Manage the security and compliance posture of technology assets and services, ensuring ownership, accountability, and adherence to defined security requirements.
  • Support security control implementation by advising on control design, facilitating evidence collection, and coordinating with control owners and security architects.
  • Manage control deficiencies and security findings through remediation, tracking, validation, and timely closure.
  • Administer the risk exception process, ensuring appropriate approvals, compensating controls, periodic reviews, and remediation activities.
  • Support audits, compliance assessments, asset classification activities, third-party risk reviews, and security awareness initiatives while providing executive-level security reporting and metrics.
  • KPI: Percentage of security findings, control deficiencies, and risk exceptions closed within agreed timelines.
Essential Requirements

What you'll bring to the role:

  • Bachelor’s degree, or equivalent experience, in Computer Science, Information Technology, Engineering, or a related discipline.
  • Minimum 15 years of experience in information security, technology risk management, or a related field.
  • Proven experience partnering with business and technology teams across regional or enterprise portfolios.
  • Strong knowledge of information security frameworks and standards such as ISO 27001, NIST, and CIS Controls.
  • Experience applying security and risk management principles across product development, cloud environments, and third-party ecosystems.
  • Demonstrated ability to manage governance processes, risk assessments, audits, compliance activities, and executive reporting.
  • Strong program and project management capabilities with experience handling multiple priorities and stakeholders.
  • Ability to translate technical security risks into business impact and influence decision-making at multiple organizational levels.
  • Essential Skills: Excellent communication, stakeholder management, consulting, collaboration, and continuous improvement mindset with the ability to influence without direct authority.
  • Languages: Fluent written and spoken English.
  • Professional certifications such as CISSP, CISM, CISA, or equivalent information security credentials.
  • Experience with privacy regulations, regulatory compliance requirements, and pharmaceutical industry environments.
Your Key Responsibilities

Your responsibilities include, but not limited to:

  • Serve as the primary ISRC contact for assigned regions and supported product domains/functions, providing practical guidance on security, compliance, and risk-related matters.
  • Partner with business and technology leadership to define security requirements, support prioritization, and promote risk-based decision-making.
  • Drive the adoption and consistent implementation of ISRC processes, controls, and governance frameworks across supported areas.
  • Manage the security and compliance posture of technology assets and services, ensuring ownership, accountability, and adherence to defined security requirements.
  • Support security control implementation by advising on control design, facilitating evidence collection, and coordinating with control owners and security architects.
  • Manage control deficiencies and security findings through remediation, tracking, validation, and timely closure.
  • Administer the risk exception process, ensuring appropriate approvals, compensating controls, periodic reviews, and remediation activities.
  • Support audits, compliance assessments, asset classification activities, third-party risk reviews, and security awareness initiatives while providing executive-level security reporting and metrics.
  • KPI: Percentage of security findings, control deficiencies, and risk exceptions closed within agreed timelines.
Essential Requirements

What you'll bring to the role:

  • Bachelor’s degree, or equivalent experience, in Computer Science, Information Technology, Engineering, or a related discipline.
  • Minimum 15 years of experience in information security, technology risk management, or a related field.
  • Proven experience partnering with business and technology teams across regional or enterprise portfolios.
  • Strong knowledge of information security frameworks and standards such as ISO 27001, NIST, and CIS Controls.
  • Experience applying security and risk management principles across product development, cloud environments, and third-party ecosystems.
  • Demonstrated ability to manage governance processes, risk assessments, audits, compliance activities, and executive reporting.
  • Strong program and project management capabilities with experience handling multiple priorities and stakeholders.
  • Ability to translate technical security risks into business impact and influence decision-making at multiple organizational levels.
  • Essential Skills: Excellent communication, stakeholder management, consulting, collaboration, and continuous improvement mindset with the ability to influence without direct authority.
  • Languages: Fluent written and spoken English.
  • Professional certifications such as CISSP, CISM, CISA, or equivalent information security credentials.
  • Experience with privacy regulations, regulatory compliance requirements, and pharmaceutical industry environments.
Desirable Requirements
  • Professional certifications such as CISSP, CISM, CISA, or equivalent information security credentials.
  • Experience with privacy regulations, regulatory compliance requirements, and pharmaceutical industry environments.
You’ll Receive
  • Competitive compensation and performance-related rewards.
  • Flexible and hybrid working opportunities.
  • Comprehensive health and wellness benefits.
  • Learning and development programs to support continuous professional growth.
  • Access to global career development and internal mobility opportunities.
  • Inclusive, collaborative, and purpose-driven work environment focused on innovation and impact.
Why Sandoz?

Generic and Biosimilar medicines are the backbone of the global medicines industry. Sandoz, a leader in this sector, provided more than 900 million patient treatments across 100+ countries in 2024 and while we are proud of this achievement, we have an ambition to do more!

With investments in new development capabilities, production sites, new acquisitions, and partnerships, we have the opportunity to shape the future of Sandoz and help more patients gain access to low-cost, high-quality medicines, sustainably.

Our momentum is powered by an open, collaborative culture driven by our talented and ambitious colleagues, who, in return for applying their skills experience an agile and collegiate environment with impactful, flexible-hybrid careers, where diversity is welcomed and where personal growth is supported!

Join us!

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Manager TPRM - BD&L and M&A Deals
Sr. Manager TPRM - BD&L and M&A Deals

IN04 (FCRS = IN004) Sandoz Private Limited • Telangana

On-site
INR 1,200,000 - 1,800,000
Information Security Awareness and Training Specialist
Information Security Awareness and Training Specialist

IN04 (FCRS = IN004) Sandoz Private Limited • Turakapally

On-site
INR 1,200,000 - 2,200,000
Global Senior Solution Engineer: SAP GRC
Global Senior Solution Engineer: SAP GRC

IN04 (FCRS = IN004) Sandoz Private Limited • Telangana

On-site
INR 2,500,000 - 4,500,000
Gl.Assoc.Dir.Sol.Delivery Clinical&Med
Gl.Assoc.Dir.Sol.Delivery Clinical&Med

IN04 (FCRS = IN004) Sandoz Private Limited • Telangana

On-site
INR 6,000,000 - 12,000,000
Manager - Risk and Policies (P&O)
Manager - Risk and Policies (P&O)

Sandoz India • Telangana

On-site
INR 2,500,000 - 4,000,000
Global Lead Finance R2R, PCA Solutions
Global Lead Finance R2R, PCA Solutions

IN04 (FCRS = IN004) Sandoz Private Limited • Telangana

On-site
INR 3,000,000 - 6,000,000
Network Security Governance Expert
Network Security Governance Expert

Sandoz India • Telangana

Hybrid
INR 1,800,000 - 2,800,000
Hybrid work
Learning support
Certification programs
+1
Global Program Manager, ITO
Global Program Manager, ITO

IN04 (FCRS = IN004) Sandoz Private Limited • Telangana

On-site
INR 3,500,000 - 7,000,000
Global Senior Domain Solution Architect Enterprise Platforms
Global Senior Domain Solution Architect Enterprise Platforms

IN04 (FCRS = IN004) Sandoz Private Limited • Telangana

Hybrid
INR 2,400,000 - 3,600,000
Flexible and hybrid working
Learning, development & certification
Global exposure
+1
Global Medical Development Manager
Global Medical Development Manager

IN04 (FCRS = IN004) Sandoz Private Limited • Telangana

On-site
INR 4,200,000 - 6,500,000