GRC Lead / Security Compliance Lead

Gnani Innovations Private Limited.

India

On-site

INR 350,000 - 600,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Gnani Innovations Private Limited. is seeking a Senior GRC lead who will own the certification and audit lifecycle, risk management, and security-questionnaire programs.

You will drive regulatory compliance across DPDP, RBI, IRDAI, GDPR, HIPAA, and cross-border transfers, working with Legal to review MSAs and DPAs. You will mentor GRC analysts, establish repeatable processes, and deliver board-ready risk reporting.

Qualifications

  • 8-12 years in GRC / information security compliance, with real ownership of ISO 27001 and SOC 2 programs end-to-end.
  • Experience resolving audit non-conformities and regulator disputes personally.
  • Strong DPDP Act & RBI/IRDAI expectations for tech vendors, plus GDPR/HIPAA/PCI familiarity.

Responsibilities

  • Own the certification & audit lifecycle: ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR, etc.
  • Own the enterprise risk register and drive a formal risk appetite statement.
  • Lead the client security-questionnaire (ISQ) program: SLAs, answer library, and automation strategy.
  • Be the authority on DPDP, RBI, IRDAI, GDPR, HIPAA, cross-border transfers; review MSAs with Legal.
  • Own the policy lifecycle: currency, enforcement, SOPs, KPIs/SLAs, and evidence of controls.
  • Mentor GRC Analysts and interns; make compliance repeatable and measurable.

Skills

GRC ownership
ISO 27001 lead implementer
SOC 2 auditor
DPDP Act knowledge
Regulatory compliance
Auditing skills
Written English

Job description

This is the senior judgment layer of Gnani's security function and the CISO's right hand on all things compliance and risk looking after every hard regulatory call - how to optimize our internal process to map all compliances and successfully maintain compliant statuses, how to safeguard the organization from all the liabilities, how to read the liability clauses in MSAs, what our DPDP cross-border position is and many more. You will own those calls. You'll run the certification and audit program end-to-end, own the enterprise risk register, lead the client security-questionnaire (ISQ) function, and be the person regulators and enterprise clients can be handed to with confidence.

What you'll own
  • Own the certification & audit lifecycle: ISO 27001, ISO 42001, SOC 2 Type 2, PCI DSS, HIPAA, GDPR etc. and the various information security guidelines from the regulatory bodies like RBI, IRDA etc.
  • Own the enterprise risk register and drive a formal, board-ready risk appetite statement
  • Lead the client security-questionnaire (ISQ) program: SLAs, the pre-approved answer library, and the strategy to automate it without compromising data protection
  • Be the authority on hard regulatory questions across DPDP, RBI, IRDAI, GDPR, HIPAA and cross-border transfers - and the go-to for MSA/DPA security & liability reviews alongside Legal/Counsel
  • Own the policy lifecycle: currency, enforcement, SOPs, KPIs/SLAs, and the evidence that controls operate
  • Mentor GRC Analysts and interns; turn compliance from ad-hoc heroics into a repeatable, measured program
What we're looking for
  • 8-12 years in GRC / information security compliance, with real ownership (not just 'support') of ISO 27001 and SOC 2 programs end-to-end
  • Demonstrated experience resolving audit non-conformities and client/regulator disputes personally
  • Strong working command of DPDP Act & Rules, RBI and IRDAI expectations for technology vendors, plus GDPR/HIPAA/PCI
  • ISO 27001 Lead Implementer/Auditor; SOC 2 and ideally ISO 42001 implementation experience
  • Excellent written English - your answers go directly to enterprise clients and regulators
  • Regulated industry (BFSI, insurance, healthcare) or SaaS/AI compliance background
Nice to have
  • ISO 27000, ISO 42001 Lead Implementer; privacy certification (DCPP/CIPP/CIPM)
  • Exposure to CAIQ, SIG, HECVAT frameworks
  • Experience standing up GRC automation tooling
  • Prior work with AI/ML or data-heavy platforms
Your first 90 days
  • Take full ownership of the certification calendar; resolve the SOC 2 bridge-letter / client-acceptance issue and document the standard playbook for it
  • Publish a consolidated risk register with the top risks, owners and treatment plans, and a draft risk appetite statement for CISO/board sign-off
  • Stand up the ISQ program with a defined SLA (≤5 business days for complex questionnaires) and a first version of the answer library
  • Deliver a 90-day compliance-posture readout to the CISO: what's audit-ready, what's at risk, and the 6-month plan
Why join now
  • You will be an early member of a security function being built from the ground up - you shape process and precedent, not inherit a backlog with no context.
  • High-visibility work with the CISO, Engineering, Legal and Sales - your decisions are felt company-wide within a quarter.
  • A rare chance to secure a genuinely AI-native platform at a fast-scaling, company, without enterprise bureaucracy.
Skills Required

Primary Skills SOC 2 Information Security (ISO 27001) Compliance (SOC 2, GDPR, HIPAA, PCI DSS) Information Security

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Module Lead Information Security
Module Lead Information Security

IDfy • Mumbai

On-site
INR 4,000,000 - 7,000,000
Governance, Risk and Compliance (GRC) Lead
Governance, Risk and Compliance (GRC) Lead

Money Honey Financial Services • Mumbai

On-site
INR 1,500,000 - 2,000,000
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

844 Altera Semiconductor Technology India Pvt. Ltd. • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Information Security Manager / GRC Lead
Information Security Manager / GRC Lead

Flamapp • India

On-site
INR 1,500,000 - 2,100,000
GRC Analyst
GRC Analyst

Security Brigade • Delhi, Mumbai

Hybrid
INR 60,000 - 80,000
Competitive salary aligned to experience
Hybrid + remote-friendly
Sponsorship for relevant certifications
+2
Information Security Manager / GRC Lead
Information Security Manager / GRC Lead

Keka Technologies Private Limited • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Governance, Risk & Compliance (GRC) Manager
Governance, Risk & Compliance (GRC) Manager

TeamsWork.In • India

On-site
INR 1,500,000 - 2,100,000
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

Altera • Bengaluru

On-site
INR 3,000,000 - 4,500,000
Information Security & Compliance Lead
Information Security & Compliance Lead

Infra360 Solutions Pvt. Ltd. • Haryana

On-site
INR 1,000,000 - 1,500,000
Product GRC Consultant
Product GRC Consultant

CyRAACS™ • Bengaluru

On-site
INR 600,000 - 1,200,000