Lead Consultant

Bindz Consulting

Bengaluru

On-site

INR 1,800,000 - 2,400,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Competitive remuneration
Health insurance for family
Parental leaves
Hybrid work model
Relocation benefits
PF contribution
Gratuity
Leave encashment
Offshore business opportunity
High-performance team

Job summary

CBIZ seeks a Manager - Governance Risk and Compliance in Bengaluru to assess and mitigate third-party risk, implement security policies, and drive a robust GRC program.

You will lead risk assessments, collaborate with legal and IT teams, and design KPI/KRI metrics while staying current on industry regulations. Strong security background and vendor risk experience are required; certifications (CISM/CRISC/CISA) preferred.

Qualifications

  • 10+ years of information security experience with focus on third-party/vendor risk management.
  • Strong understanding of information security principles, frameworks (NIST, ISO 27001, SOC 2 Type 2) and regulations (GDPR, HIPAA).
  • Experience with risk assessment methodologies and tools.
  • Excellent analytical and critical thinking skills, with ability to manage complex projects.
  • Proficient written and verbal communication, able to explain technical concepts to non-technical stakeholders.
  • Detail-oriented with strong organizational skills.
  • Ability to work independently as well as collaboratively in a team.

Responsibilities

  • Enhance security policies, controls and procedures; conduct annual certifications.
  • Operationalize the GRC tool and identify areas for improvement.
  • Develop and maintain a vendor risk management framework and related documentation.
  • Conduct risk assessments and review security policies, controls and procedures.
  • Collaborate with owners, vendors and legal to ensure security in contracts and SLAs.
  • Coordinate with security groups, IT Operations and other teams on audits and GRC recommendations.
  • Monitor changes in vendor services that could affect security posture.
  • Provide guidance on security risks and controls to internal stakeholders.

Skills

Analytical thinking
Critical thinking
Communication skills
Detail oriented
Team collaboration
Independent work

Education

Bachelor's degree in IT/Cybersecurity or related field; or equivalent
CISM
CRISC
CISA

Job description

Job Description
Manager - Governance Risk and Compliance
About CBIZ

CBIZ, Inc. (NYSE: CBZ) is a leading professional services advisor to middle-market businesses nationwide. With industry knowledge and expertise in accounting, tax, advisory, benefits, insurance, and technology, CBIZ delivers actionable insights to help clients anticipate what is next and discover new ways to accelerate growth. CBIZ has more than 9,500 team members across 23 major markets coast to coast.

CBIZ strives to be our team members employer of choice by creating an environment where team members are appreciated, recognized for their contributions, and provided with opportunities to grow, both personally and professionally, throughout their careers.

Together, CBIZ and CBIZ CPAs are ranked as one of the top providers of accounting services in the United States. CBIZ CPAs is an independent CPA firm that provides audit, review and attest services, while CBIZ provides business consulting, tax and financial services. In certain jurisdictions, CBIZ CPAs operates under its previous name, Mayer Hoffman McCann P.C.

Role Purpose

The GRC Specialist is responsible for assessing, managing, and mitigating risks associated with third-party vendors and service providers. Implement security best practices, policies, and controls through a repeatable process. This role involves conducting thorough security evaluations of potential and existing vendors, conducting regular security awareness trainings, and phishing campaigns, design and implementation of KPI s, KRI s, enhancing our internal policies and procedures.

Roles & Responsibilities
  • Enhance existing security policies, controls and procedures and conduct annual certifications.
  • Assist to operationalize the GRC tool and identify areas of improvement.
  • Develop and maintain a vendor risk management framework and supporting documentation.
  • Conduct detailed risk assessments, identify potential security risks associated with third-party vendors by reviewing and analyzing security policies, controls, and procedures.
  • Get to know the business side, meet with owners and vendors, while identifying opportunities to improve ease of vendor management.
  • Collaborate with legal, and other departments to ensure that security requirements are included in contracts and service level agreements (SLAs).
  • Collaborate and coordinate with other Security groups, IT Operations, and other teams on audits, assessments and GRC control recommendations.
  • Monitor and evaluate changes in vendor services or operations that may impact the organizations security posture.
  • Provide guidance and recommendations to internal stakeholders regarding security risks and controls.
  • Publish and collaborate outside vulnerability and threats. Stay current with industry best practices, regulatory requirements, and emerging threats related to third-party engagements.
  • Maintain Security Awareness, Compliance programs, Risk register.
  • Generate KPI s and KRI s for the security team.
Skills & Qualifications
  • Minimum of 10 years of experience in information security, with a focus on third-party/vendor risk management.
  • Strong understanding of information security principles, frameworks (e.g., NIST, ISO 27001, SOC 2 Type 2), and regulations (e.g., GDPR, HIPAA).
  • Experience with risk assessment methodologies and tools.
  • Excellent analytical and critical thinking skills, with the ability to manage complex projects.
  • Proficient communication skills, both written and verbal, with the ability to explain technical concepts to non-technical stakeholders.
  • Detail-oriented with strong organizational skills.
  • Ability to work independently as well as collaboratively within a team environment.
  • Bachelor s degree in information technology, Cybersecurity, or a related field; or equivalent work experience.
  • Relevant professional certifications, such as CISM, CRISC, or CISA are preferred.
Perks & Benefits
  • Competitive remuneration and benefits package:
  • Insurance Benefits - Health Insurance cover for family includes 2 parents, OPD & Term life Insurance
  • Paid time off - Parental leaves (Maternity & Paternity leaves), Paid Leaves
  • Work life Harmony - Hybrid work model
  • Mobility Benefits - Relocation benefits and door-to-door transportation
  • Retiral Benefits - Employee PF Contribution, Gratuity, Leave Encashment
  • Once in a lifetime opportunity to set up offshore business for one of the 10th largest Financial Services and CPA firms in the US.
  • Chance to work with a team of talented and passionate individuals who are committed to delivering high-quality work to our clients.
  • The opportunity to thrive in a high-performance environment while contributing to the foundation of a new division.

Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Executive- Talent Acquisition
Senior Executive- Talent Acquisition

CBIZ India • Pune District

Hybrid
INR 700,000 - 1,100,000
Health insurance for family
Paid time off
Hybrid work model
+2
GRC – Information Security Third‑Party Risk Assessment Specialist
GRC – Information Security Third‑Party Risk Assessment Specialist

Soffit Infrastructure Services (P) Ltd • Gurugram District

On-site
INR 1,200,000 - 2,100,000
Associate - Security Governance, Risk & Compliance
Associate - Security Governance, Risk & Compliance

Alvarez & Marsal • Bengaluru

On-site
INR 900,000 - 1,400,000
Performance development
Professional training
Global exposure
+1
Manager - Administration & Facilities
Manager - Administration & Facilities

CBIZ INDIA • Hyderabad

Hybrid
INR 1,800,000 - 3,000,000
Health insurance (family)?
Hybrid work model
Parental leaves
+2
GRC Information Security Third‑Party Risk Assessment Specialist
GRC Information Security Third‑Party Risk Assessment Specialist

Soffit Infrastructure Services (P) Ltd • Gurugram District

On-site
INR 900,000 - 1,300,000
GRC - Security Analyst
GRC - Security Analyst

Jobgether • India

Remote
INR 1,200,000 - 1,800,000
Fully remote in India
Full-time employment
Exposure to multiple security framesk—
+2
Information Security Engineer
Information Security Engineer

Cloudxtreme • Hyderabad, Chennai District, Bengaluru

On-site
INR 1,200,000 - 2,100,000
Senior Consultant - Data Engineer
Senior Consultant - Data Engineer

CBIZ India • Hyderabad

Hybrid
INR 2,800,000 - 4,000,000
Health insurance for family
Parental leaves (Maternity & Paternity
Hybrid work model
+2
Jr. GRC Engineer
Jr. GRC Engineer

Neurealm • Chennai District

On-site
INR 700,000 - 1,100,000
Cybersecurity Lead - GRC
Cybersecurity Lead - GRC

Medusind Solutions, Inc. • Mumbai

On-site
INR 1,500,000 - 2,100,000