Manager - GRC

ZS

Pune District

On-site

INR 2,500,000 - 4,500,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ZS is seeking a Manager – GRC (Technical Audit & Assurance) to lead client security audits, own AI risk governance, and strengthen the PRA program with technical depth and independent oversight. You will partner with cross-functional teams across Technology, Platform Services, and Delivery Excellence to scale assurance capabilities.

The role requires 10–12 years in IT audit or risk, deep security controls knowledge, and proven ability to communicate findings to senior leadership.

Qualifications

  • 10–12 years of IT audit, risk, or cyber assurance experience.
  • Proven track record leading technical security audits.
  • Strong foundation across SDLC governance, CI/CD, cloud security, IAM, and app security.
  • Experience designing assurance programs from concept to delivery.
  • Ability to engage senior stakeholders and translate findings clearly.
  • GxP, CSV, or 21 CFR Part 11 experience is a strong differentiator.

Responsibilities

  • Lead GRC's client and delivery security audit program — independent reviews of security controls.
  • Design and evolve the audit methodology and risk-based intake model.
  • Execute with depth across SDLC governance, CI/CD security, access management, change control, secrets mgmt, endpoint security, data protection, logging.
  • Coordinate audit logistics with Client Service Teams, ISBP, Information Security, and project leadership.
  • Aggregate cross-client findings into insights for GRC leadership and steering committees.
  • Own AI risk governance workstream — develop assessment framework and controls.

Skills

IT audit
Technical risk
Stakeholder engagement
Cloud security
CI/CD security
GRC leadership

Education

Bachelor's degree in Computer Science/Engineering
Master's degree preferred
CISA
CISSP/CISM
ISO 27001 Lead Auditor
GxP/CSV/21 CFR Part 11 accreditation

Tools

ISO 27001
SOC 2
NIST CSF
AI governance

Job description

Manager GRC

Technical Audit & Assurance AI Risk Governance Project Risk

About the GRC Function

Governance, Risk & Compliance (GRC) is ZS's enterprise-wide second-line governance function — governing the integrity of the firm's control environment, managing the certification and assurance portfolio, and providing the independent risk signal that enables leadership to make informed decisions with confidence.

The function operates alongside ERM and Legal/Compliance within ZS's governance structure and works closely with the ZS's Delivery Excellence (DEX) organization for delivery governance and audit. GRC's four accountability areas span control environment integrity, regulatory and certification compliance, risk intelligence and oversight, and delivery and operational assurance. The function is midway through a deliberate expansion of its assurance capabilities, and this role is central to that growth.

The Role

The Manager – GRC (Technical Audit & Assurance) is a senior individual contributor and program leader responsible for GRC's technical audit and assurance capabilities. The role leads client security audits, owns GRC's AI risk governance workstream, and strengthens the Project Risk Assessment (PRA) program through technical depth and independent oversight.

The Manager works closely with three peer leads — Certifications & Compliance, Risk Operations, and Third-Party Risk & Data Compliance — and is a key partner to the Delivery Excellence organization and ZS's Technology, Platform Services and Client Service organizations. The role reports to the Head of GRC.

Key Responsibilities
Client & Delivery Security Audit Program

Lead GRC's client and delivery security audit program — independent, evidence-based reviews of security and governance controls in live client engagements and across ZS's delivery organization.

  • Manage end-to-end audit execution: scoping, walkthroughs, evidence review, observation validation, management response, remediation tracking, and governance reporting
  • Design and evolve the audit methodology, observation framework, and risk-based intake model — ensuring rigor, consistency, and scalability across engagements
  • Execute with genuine technical depth across key control domains: SDLC governance, CI/CD security, access management, change control, secrets management, endpoint security, data protection, and logging
  • Coordinate audit logistics with Client Service Teams, ISBP, Information Security, and project leadership — presenting a coordinated assurance response to clients
  • Aggregate cross-client and cross-program findings into thematic insights; report recurring patterns to GRC leadership, DEX governance forums, and relevant steering groups
AI Risk Governance

Own GRC's AI risk and compliance governance workstream — building the assessment methodology, control framework, and assurance infrastructure that enables ZS to scale AI-enabled delivery responsibly and credibly.

  • Design and operationalize AI risk assessments for projects using AI and agentic tools — evaluating model risk, data governance, human review controls, security validation, output monitoring, and client data protection
  • Develop the AI controls framework: approved tool governance, risk acceptance standards, monitoring requirements, and privacy alignment
  • Lead GRC's evaluation and adoption of AI assurance credentials — including AIUC-1, ISO 42001, NIST AI RMF, and EU AI Act requirements — and advise leadership on appropriate adoption
  • Translate AI adoption signals from across ZS's delivery organization into governance insights for Leadership Steering Committees
  • Partner with Information Security, Cloud Centre of Excellcne, Legal, and Privacy to ensure ZS's AI governance framework is coherent across technology, security, regulatory, and delivery dimensions
Project Assurance — PRA and Special Interventions

Strengthen the Project Risk Assessment (PRA) program — GRC's unified governance gate for client-facing projects — through technical rigor, assurance quality, and hands-on intervention capability.

  • Bring technical depth to PRA scoping and risk identification — ensuring AI, security, privacy, GxP, and regulatory dimensions are correctly flagged and governed from project outset
  • Lead rapid diagnostic assessments and special assurance interventions for high-risk, complex, or escalated projects — providing in-flight control reviews and targeted remediation planning
  • Partner with the Delivery Excellence team to ensure project governance and delivery assurance operate as a single, integrated view rather than parallel tracks
  • Support the continuous improvement of PRA methodology — incorporating learnings from audit findings, client engagement patterns, and evolving risk themes
GxP and Life Sciences Compliance (specialization valued)

ZS serves leading life sciences organizations across pharma, biotech, payer, and healthcare sectors. Candidates with GxP, CSV, or 21 CFR Part 11 experience will find an active need in this role — providing specialist assurance coverage on life sciences client engagements, contributing to GxP audit frameworks, and advising CSTs and project teams on regulatory compliance requirements within GRC's scope.

Stakeholder Engagement and Reporting
  • Build trusted relationships with Technology and Platforms Practice, Client Service Teams, Information Security, Legal, and Delivery Excellence leadership — positioning GRC's assurance capabilities as a business enabler
  • Prepare and present findings, governance updates, and program insights for GRC leadership, and senior stakeholder / leadership committees and groups.
  • Support GRC's broader stakeholder engagement — contributing to how GRC communicates its mandate, capabilities, and value across the firm
Skills, Experience & Qualifications
Professional Experience
  • 10–12 years of professional experience in IT audit, technology risk, cyber assurance, or technical GRC — with significant experience at a Big 4, Big 3, or specialist assurance firm, or in a technically deep GRC / compliance leadership role within a regulated industry
  • Demonstrated track record of leading and executing technical security audits — hands-on experience conducting walkthroughs, reviewing evidence, and making independent control assessments
  • Strong technical foundation across SDLC governance, CI/CD pipeline security, cloud security controls, access and identity management, application security, and secrets management
  • Experience designing and building assurance program from concept through to operational delivery — not solely inheriting established frameworks
  • Proven ability to engage confidently with senior stakeholders — client service leaders, C-suite, and cross-functional enterprise teams — and translate technical findings into clear leadership communication
  • GxP, CSV, or 21 CFR Part 11 experience is a strong differentiator for this role, given ZS's active life sciences client base
Core Technical Expertise
  • Security standards and frameworks: ISO 27001/27017/27701, SOC 2 Type II, HITRUST CSF, NIST CSF — strong working familiarity and audit experience
  • SDLC and application security: code review governance, CI/CD pipeline security controls, vulnerability management, SAST/DAST, release governance, and traceability
  • Cloud security: cloud control frameworks, container security, secrets management, infrastructure-as-code governance
  • AI governance and risk frameworks: NIST AI RMF, ISO 42001, EU AI Act — awareness and growing expertise valued; prior experience with AI/ML assurance is a strong advantage
  • GxP / life sciences: 21 CFR Part 11, GCP/GMP/GLP, CSV / computer systems validation — valued, not required
Leadership and Behavioral Competencies
  • Technically credible and precise — able to interpret a CI/CD configuration, assess access governance control, and make an independent judgement on whether a finding is material
  • Clear and structured communicator — translates complex technical findings into leadership-ready observations and actionable guidance for delivery teams
  • Self-directed and accountable — comfortable owning a program end-to-end with a high degree of independence
  • Collaborative across functions — builds working relationships with delivery, product, legal, infosec, and client-facing teams without relying on formal authority
  • Composed and professional in high-stakes contexts — client security audits and project assurance reviews involve commercial sensitivity and senior stakeholder scrutiny
Education & Certifications
Education
  • Bachelor's degree required — Computer Science, Information Systems, Engineering, or a related technical discipline
  • Master's degree preferred — technical discipline, MBA, or equivalent
Certifications (preferred — not all required)
  • CISA (Certified Information Systems Auditor) — highest value for this role
  • CISSP or CISM — for technical security depth
  • ISO 27001 Lead Auditor
  • GIAC certifications — GSNA, GPEN, or equivalent security audit and assessment credentials
  • NIST AI RMF Practitioner or equivalent AI governance credential — or actively pursuing
  • GxP / CSV / 21 CFR Part 11 specialist accreditation — valued where applicable
What Makes This Role Unique
  • GRC at ZS has direct access to various internal ZS Leadership Steering Committee and Forums (e.g., Risk, Compliance & Professionalism Committee, Audit Committee, Information Security Working Group, etc.) the visibility and impact for a manager are meaningful and early
  • The technical audit and AI risk governance program are actively scaling — this is an opportunity to shape methodology and grow capability, not maintain an inherited framework
  • The role sits at the intersection of technical assurance, enterprise governance, and AI risk — a combination that is increasingly rare and commercially relevant
  • ZS's global delivery footprint and 15,000+ person scale create a complex, high-interest assurance environment across Technology, I&A, and Strategy & Transformation practices

ZS is committed to building an inclusive and diverse workforce and welcomes applications from all qualified candidates. We are an equal opportunity employer.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager - Governance, Risk & Compliance
Manager - Governance, Risk & Compliance

ZS • Maharashtra

Hybrid
INR 1,800,000 - 2,400,000
Manager - Governance, Risk & Compliance
Manager - Governance, Risk & Compliance

Zs Associates • Pune District

Hybrid
INR 2,800,000 - 6,000,000
GRC Lead / Security Compliance Lead
GRC Lead / Security Compliance Lead

Gnani Innovations Private Limited. • India

On-site
INR 350,000 - 600,000
Governance, Risk & Compliance (GRC) Manager
Governance, Risk & Compliance (GRC) Manager

TeamsWork.In • India

On-site
INR 1,500,000 - 2,100,000
Senior Manager
Senior Manager

Pellera Technologies • India

On-site
INR 2,500,000 - 4,500,000
Required Skillset
Required Skillset

eProtect 360 • Mumbai

On-site
INR 2,000,000 - 3,500,000
Governance, Risk & Compliance (GRC) Manager — Internal Audit Lead
Governance, Risk & Compliance (GRC) Manager — Internal Audit Lead

SymphonyAI • Bengaluru

On-site
INR 1,800,000 - 3,200,000
Governance, Risk & Compliance (GRC) Manager
Governance, Risk & Compliance (GRC) Manager

Zenwork, Inc • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Competitive compensation
Professional development support
Work in a fast-growing technology environment
Governance, Risk & Compliance (GRC) Manager — Internal Audit Lead
Governance, Risk & Compliance (GRC) Manager — Internal Audit Lead

Symphony Industrial AI, Inc. • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Manager- GRC
Manager- GRC

CyberCube Services • Gurugram District

On-site
INR 1,500,000 - 2,100,000