GRC Lead – India

ION Group

India

On-site

INR 2,500,000 - 4,500,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

ION Group seeks an experienced Governance, Risk & Compliance leader to mature its governance, risk management and compliance capabilities. You will oversee the ISMS, maintain regulatory and certification compliance, drive risk governance, manage customer assurance programmes, and ensure security policies are implemented across the organisation.

The role requires extensive experience in large enterprises, ISO 27001 certification, risk management frameworks, and responding to audits, with the

Qualifications

  • Bachelor's degree or equivalent related experience.
  • ISO27001 Lead Implementer / Auditor with leadership experience in certification programmes.
  • Experience designing and maintaining enterprise risk management frameworks.
  • Experience developing and managing information security policies and control frameworks.
  • Experience managing customer assurance activities and Right-to-Audit engagements.

Responsibilities

  • Own lifecycle management of information security policies, standards, frameworks and procedures.
  • Develop and maintain governance documentation aligned with regulatory requirements.
  • Establish governance processes to ensure consistent implementation of controls.
  • Monitor adherence to security policies and drive remediation of non-compliance.
  • Lead ISMS maintenance, effectiveness, and continual improvement across the organisation.
  • Coordinate ISO 27001 certification and recertification activities; maintain audit records.
  • Oversee internal audits, external certification audits and remediation activities.
  • Manage enterprise information security risk management framework and risk register.
  • Lead responses to client security questionnaires and regulatory enquiries.
  • Coordinate Right-to-Audit engagements with regulated financial institutions and strategic clients.
  • Act as primary contact for external auditors and customer assurance teams.

Skills

Governance excellence
Risk management
Regulatory liaison
Stakeholder communication

Education

Bachelor's degree or equivalent

Tools

ISO 27001
NIST CSF
GDPR

Job description

Responsible for leading and maturing ION Group's governance, risk management and compliance capabilities. The role will oversee the Information Security Management System (ISMS), maintain regulatory and certification compliance, drive risk governance activities, manage customer assurance programmes, and ensure security policies and standards are effectively implemented across the organisation.

The successful candidate will have extensive experience operating within large, complex enterprises and demonstrate a proven track record of achieving and maintaining ISO 27001 certification, implementing risk management frameworks, responding to customer and regulatory audits, and building effective governance programmes.

Key responsibilities:
Governance & Policy Management
  • Own the lifecycle management of Information Security policies, standards, frameworks and procedures.
  • Develop, review and maintain governance documentation to ensure alignment with business objectives and regulatory requirements.
  • Establish governance processes to ensure policies, standards and controls are consistently implemented across the organisation.
  • Monitor adherence to security policies and standards and drive remediation of non-compliance findings.
Information Security Management System (ISMS)
  • Lead the ongoing maintenance, effectiveness and continual improvement of the Information Security Management System (ISMS).
  • Drive ISO 27001 certification & recertification activities and ensure certification evidence, control documentation and audit records are maintained and auditable.
  • Coordinate internal audit programmes, external certification audits and remediation activities.
  • Own and continuously improve the enterprise information security risk management framework.
  • Maintain and oversee the Group Security Risk Register. Facilitate risk identification, assessment, treatment, acceptance and reporting activities across business units.
Client Assurance & Regulatory Compliance
  • Lead responses to client security questionnaires, due diligence requests, regulatory enquiries and customer assessments.
  • Manage and coordinate customer Right-to-Audit engagements, particularly with regulated financial institutions and strategic clients.
  • Act as the primary contact for external auditors, assessors & customer assurance teams
  • Monitor emerging regulatory requirements and assess their impact on the organisation.
Third-Party Risk Management
  • Conduct & oversee security assessments for vendors, suppliers and strategic partners.
  • Review contracts, security documentation, certifications and audit reports to evaluate risk and ensure supplier risks are appropriately documented, managed and escalated.
Stakeholder Management
  • Partner with Security Operations, Engineering, Architecture, Legal, Compliance, Internal Audit and business stakeholders to address identified risks and compliance obligations.
  • Provide guidance and subject matter expertise on governance, regulatory compliance and risk management matters.
  • Support security awareness initiatives and promote a culture of risk management and compliance.
Required Skills, Experience & Qualification:
  • Min 8 to 10 years of experience in Governance, Risk & Compliance, Information Security, Audit or Risk Management roles, preferably within a financial services environment
  • Bachelor’s degree of equivalent related experience.
  • ISO27001 Lead Implementer / Auditor - demonstrable experience leading ISO 27001 certification and recertification programmes within large, complex organisations.
  • Proven experience designing, implementing and maintaining enterprise risk management frameworks.
  • Extensive experience developing, reviewing and managing information security policies, standards and control frameworks.
  • Significant experience managing customer assurance activities, security questionnaires and Right-to-Audit engagements.
  • Experience presenting risk and compliance information to senior stakeholders and executive leadership.
  • Strong knowledge of:
  • ISO 27001 / ISO 27002
  • ISO 31000 / ISO 27005
  • ISO 22301 / ISO 42001
  • NIST Cybersecurity Framework
  • SOC 1 / SOC 2
  • GDPR
  • DORA
  • NIS2
  • Experience presenting risk and compliance information to senior stakeholders and executive leadership.
About ION:

We’re a diverse group of visionary innovators who provide trading and workflow automation software, high-value analytics, and strategic consulting to corporations, central banks, financial institutions, and governments. Founded in 1999, we’ve achieved tremendous growth by bringing together some of the best and most successful financial technology companies in the world.

Over 2,000 of the world’s leading corporations, including 50% of the Fortune 500 and 30% of the world’s central banks, trust ION solutions to manage their cash, in-house banking, commodity supply chain, trading and risk.

Over 800 of the world’s leading banks and broker-dealers use our electronic trading platforms to operate the world’s financial market infrastructure.

ION is committed to maintaining a supportive and inclusive environment for people with diverse backgrounds and experiences. We respect the varied identities, abilities, cultures, and traditions of the individuals who comprise our organization and recognize the value that different backgrounds and points of view bring to our business.

ION adheres to an equal employment opportunity policy that prohibits discriminatory practices or harassment against applicants or employees based on any legally impermissible factor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Lead - India
GRC Lead - India

ION Group • India

On-site
INR 4,000,000 - 7,000,000
Information Security Engineer - GRC
Information Security Engineer - GRC

EDGE Executive Search • Gurugram District

On-site
INR 900,000 - 1,500,000
Sr. Information Security Engineer (GRC)
Sr. Information Security Engineer (GRC)

Osttra • Gurugram District

On-site
INR 1,800,000 - 2,600,000
The Trust employee ownership plan
GRC Lead / Security Compliance Lead
GRC Lead / Security Compliance Lead

Gnani Innovations Private Limited. • India

On-site
INR 350,000 - 600,000
GRC Manager/ GRC Lead
GRC Manager/ GRC Lead

Riskpro India Ventures • Mumbai

On-site
INR 1,000,000 - 1,500,000
Vice President-Information Security.Information Security Group-ISG
Vice President-Information Security.Information Security Group-ISG

Mashreq • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Module Lead Information Security
Module Lead Information Security

IDfy • Mumbai

On-site
INR 350,000 - 550,000
Senior Role - GRC & Infosec
Senior Role - GRC & Infosec

NPCI Bharat BillPay Limited • Mumbai

On-site
INR 2,000,000 - 3,000,000
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

844 Altera Semiconductor Technology India Pvt. Ltd. • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Deputy General Manager-GRC
Deputy General Manager-GRC

SupportFinity™ • Ahmedabad District

On-site
INR 1,200,000 - 2,000,000