Experience: ~6 Years
Industry: Insurance (Life/General/Health)/BFSI
Role Overview
We are seeking an experienced IT Risk & Cybersecurity GRC professional (6+ years) to oversee our governance, internal audit readiness, regulatory compliance posture and user access review framework within a regulated insurance environment.
The role will play a critical part in managing internal audits, IRDAI/CERT-IN compliance, user access governance, third-party risk, control testing and executive risk reporting.
The ideal candidate must have hands‑on experience as both:
- An auditee for regulatory and internal audits
- A control assessor / reviewer conducting independent internal reviews
Key Responsibilities
- Strong understanding of IT Risk Management lifecycle (Integrated Risk Management, Risk and Control Self-Assessment, Information Risk Assessment, Business Impact Assessment)
- Perform risk assessments and control testing across IT and cybersecurity domains
- Identify control gaps and design new controls aligned with evolving threat landscape
- Track and ensure timely closure of audit observations and risk issues
- Maintain risk registers and document risk acceptance where applicable
- Coordinate security incident reporting, root cause analysis and remediation tracking.
Internal & Regulatory Audit Management
- Act as primary auditee for:
- IRDAI Cyber Security Audits
- CERT-IN compliance
- Internal audits (including Big 4)
- Coordinate evidence submission and stakeholder responses
- Conduct internal mock audits to assess control effectiveness
- Ensure 100% closure of audit issues within agreed timelines
- Track remediation and report to senior leadership
User Access Governance
- Deep understanding of:
- Privileged Access Reviews
- Normal User Access Reviews
- Role-based access control (RBAC)
- Segregation of Duties (SoD)
- Joiner-Mover-Leaver (JML) process
- Conduct periodic UAR across applications and infrastructure
- Validate access appropriateness and least privilege principles
- Coordinate with business owners and application teams for certifications
- Review PAM controls and session monitoring
- Publish interim and final access review reports
Third Party Risk Management
- Conduct third-party risk assessments during onboarding in accordance to the organization’s risk tolerance
- Perform annual continuous risk reassessment