Security Governance, Risk & Compliance

Confidential

India

On-site

INR 1,800,000 - 2,400,000

Full time

7 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical insurance
Gratuity
Flexible work models

Job summary

Confidential in India is seeking a Senior Associate to lead security governance, risk and compliance, including ISO 42001 implementation and ISO 27001 control operations. You will coordinate vendor risk assessments, due diligence and evidence collection across Gurgaon and Bangalore.

You will collaborate with procurement, legal, privacy and technology teams to embed security requirements into contracts and onboarding, while reporting risk to senior stakeholders.

Qualifications

  • 5-7 years of experience in security governance, risk and compliance in a professional services setting.
  • ISO 42001 certification is mandatory; ISO 27001 experience expected.
  • Experience implementing, auditing or operating AI governance controls.
  • Strong stakeholder management and reporting to senior leadership.

Responsibilities

  • Own ISO 42001 governance and audit readiness across the organization.
  • Operate and assure ISO 27001 controls and risk treatment plans.
  • Lead end-to-end vendor and third-party risk management activities.
  • Maintain governance reporting with risk registers and dashboards.
  • Coordinate audits and response evidence for clients and internal teams.

Skills

Security governance
Risk management
Compliance
Stakeholder management
Audit readiness
Regulatory interpretation

Education

ISO 42001 certification
ISO 27001 certification

Tools

GRC platforms
Vendor risk workflow tools

Job description

Job Title: Senior Associate, Security Governance, Risk & Compliance

Experience: 5-7 years

About the Company

Our client is a global professional services firm providing advisory, business performance improvement, turnaround management and interim leadership services to companies, investors and government entities. Founded in 1983 as a restructuring boutique, the firm is recognized for practical, action-oriented solutions that help organizations tackle complex challenges, improve performance, create value and accelerate results across six continents. The firm's mission is to help organizations address complex business issues, boost operating performance and maximize stakeholder value. Its vision connects operations, performance improvement and value creation so companies can turn stagnation into growth. The firm's founding principles-Leadership. Action. Results.-are supported by integrity, quality, objectivity, fun, personal reward and inclusive diversity. It brings together independent thinkers, experienced operators and world-class consultants in a lean, entrepreneurial environment where professionals can take early responsibility and solve high-impact client problems. The organization values diverse teaming, fair opportunity, professional development and meaningful community contribution.

About the Role

As Senior Associate, Security Governance, Risk & Compliance, you will own the operating rhythm for security governance, compliance assurance and third-party risk management across the organization. You will translate regulatory and certification requirements into practical controls, evidence and decisions that strengthen resilience and client trust. The role requires hands‑on experience with ISO 42001 and ISO 27001, including implementation, audit readiness and ongoing control effectiveness. You will lead end-to-end vendor risk management, from due diligence and inherent risk assessment through remediation, monitoring and closure. Working with technology, procurement, legal, privacy and business stakeholders, you will make risk visible, resolve control gaps and improve the consistency of security outcomes across Gurgaon and Bangalore.

Key Responsibilities
  • Own ISO 42001 governance and certification readiness by maintaining the AI management system, mapping controls to evidence and closing audit findings with accountable stakeholders.
  • Drive ISO 27001 control operation and assurance through risk treatment plans, evidence management, internal reviews and corrective actions that improve information security maturity.
  • Lead end-to-end third-party and vendor risk management, including intake, due diligence, risk tiering, assessments, remediation tracking, periodic reviews and documented acceptance decisions.
  • Maintain security governance reporting through risk registers, control dashboards and management updates that highlight material exposure, overdue actions and business impact.
  • Coordinate audits, client assurance requests and compliance reviews by producing accurate evidence, aligning contributors and ensuring responses are timely, complete and defensible.
  • Partner with procurement, legal, privacy, technology and business teams to embed security requirements into contracts, onboarding, change processes and supplier oversight.
  • Improve governance processes, standards and operating procedures through measurable control enhancements that reduce execution gaps and strengthen organizational resilience.
  • Mandatory: ISO 42001 certification and practical working experience implementing, operating or auditing AI management system controls in a business environment.
  • ISO 27001 certification with hands‑on experience in information security management systems, control testing, risk treatment, audit preparation and evidence‑based assurance.
  • Strong end‑to‑end third-party risk management and vendor risk management experience, including assessments, risk scoring, remediation, exceptions, monitoring and executive reporting.
  • Working knowledge of security governance frameworks, risk registers, control libraries, policy management and compliance evidence repositories used to maintain accountable oversight.
  • Ability to interpret regulatory, contractual and client security requirements and convert them into operational controls, clear ownership and measurable remediation outcomes.
  • Strong stakeholder management, written communication and analytical skills, with the judgment to elevate material risks and drive closure across distributed teams.
Additional Plus
  • Experience with GRC platforms, vendor risk workflow tools, security questionnaires, automated evidence collection or dashboarding that improves assurance efficiency and transparency.
  • Familiarity with privacy, cloud security, business continuity, cybersecurity controls or responsible AI governance will help broaden risk coverage and improve cross-functional decisions.
  • Experience in professional services, consulting, financial services or other client-facing environments where confidentiality, responsiveness and evidence quality are essential.
What You'll Bring
  • You bring 5-7 years of experience across security governance, risk and compliance, with demonstrated ownership of control operations, audit readiness and risk remediation in a complex environment.
  • You hold ISO 42001 certification and can show practical working experience applying its requirements; this is mandatory for the role. ISO 27001 certification and working experience are also expected.
  • You have led vendor and third-party risk management end-to-end, balancing structured assessment discipline with pragmatic decisions that protect the business without slowing essential operations.
  • You communicate clearly with senior stakeholders, technical teams and business owners, turning complex risk information into prioritization, accountability and action.
  • You work with integrity, objectivity and attention to detail, while staying effective in a lean, fast-paced and entrepreneurial environment.
  • You are comfortable operating across Gurgaon and Bangalore teams, managing competing priorities and maintaining reliable governance records under audit, client and regulatory scrutiny.
Why Join Us

Your work will directly support the trust, resilience and performance of a global professional services firm solving complex problems for organizations, investors and government entities. You will have meaningful ownership across security governance, AI management system assurance, information security compliance and third-party risk-areas that influence how confidently the business serves clients and manages change. The role offers exposure to senior stakeholders and challenging, high-impact work in a lean environment where experienced operators and independent thinkers are expected to make practical decisions. The firm's culture is grounded in Leadership, Action and Results, with integrity, quality, objectivity and inclusive diversity shaping how teams work. You will benefit from mentorship, internal mobility, structured professional development and access to an in-house corporate university. Flexible work models, work-life balance, employee resource groups, wellness initiatives and community programs support a workplace where people can contribute, grow and create lasting value. Medical insurance and gratuity are provided in addition to the role's compensation package.

What We Offer
  • Opportunity to own high-impact security governance, ISO assurance and third-party risk outcomes within a global professional services organization serving complex client needs.
  • Early access to responsibility, mentorship, internal mobility and professional development through training and an in-house corporate university.
  • Flexible work models, work-life balance, employee resource groups, wellness initiatives, comprehensive benefits, medical insurance and gratuity.
  • A collaborative, inclusive culture that values diverse perspectives, practical action, community contribution and measurable results.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Associate, Security Governance, Risk & Compliance
Senior Associate, Security Governance, Risk & Compliance

Athena Executive Search And Consulting • Gurugram District, Bengaluru

Hybrid
INR 1,500,000 - 2,500,000
Medical insurance
Gratuity
Flexible work models
Governance, Risk and Compliance (GRC) Specialist
Governance, Risk and Compliance (GRC) Specialist

Career Guideline • Pune District

On-site
INR 1,500,000 - 2,500,000
Control Advisor
Control Advisor

Notified • Bengaluru

Hybrid
INR 800,000 - 1,100,000
Cab pickup/drop
Office in Bengaluru
Hybrid work schedule
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

844 Altera Semiconductor Technology India Pvt. Ltd. • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

Altera • Bengaluru

On-site
INR 3,000,000 - 4,500,000
Governance Risk & Compliance Specialist
Governance Risk & Compliance Specialist

Jobgether • India

Hybrid
INR 1,200,000 - 1,800,000
Hybrid work arrangement
Global technology compliance exposure
AI and automation initiatives
+1
GRC Lead / Security Compliance Lead
GRC Lead / Security Compliance Lead

Gnani Innovations Private Limited. • India

On-site
INR 350,000 - 600,000
Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

Power Bridge • Arishinakunte

On-site
INR 1,200,000 - 2,400,000
Health insurance
Long-term benefit savings plan with em
Professional development opportunities
Senior GRC Analyst
Senior GRC Analyst

Litmos • India

On-site
INR 2,400,000 - 3,200,000
Governance, Risk & Compliance Analyst
Governance, Risk & Compliance Analyst

Hero Fincorp • India

On-site
INR 1,800,000 - 2,600,000