Senior Cyber GRC Specialist

Mobility Global

Gurugram District

Hybrid

INR 1,500,000 - 2,200,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Health benefits
Retirement plan
Competitive compensation

Job summary

Mobility Global seeks a Senior Cyber GRC Specialist to assess and manage cybersecurity risks from third parties. You will review evidence, engage stakeholders, and translate risk into business impact to support decisions.

Hybrid role with in-office expectations; preference for ISO/NIST expertise and professional certifications, with collaboration across Security, Legal, Procurement, and Privacy teams.

Qualifications

  • 5–10 years of cybersecurity or related risk management experience.
  • Experience assessing vendors, cloud services, apps, or enterprise tech.
  • Experience evaluating policy exceptions and residual risk.
  • Knowledge of IAM, cloud security, vulnerability management, and incident response.
  • Familiarity with ISO 27001, NIST CSF, NIST SP 800-53, CIS Controls, TISAX.

Responsibilities

  • Perform risk-based cybersecurity assessments of third parties during onboarding and changes.
  • Review security questionnaires, PS/IS reports, certifications, and test results.
  • Engage with security, procurement, legal, and privacy teams to clarify controls.
  • Document risks, propose treatment, and track remediation through closure.
  • Develop risk metrics and report to governance forums.

Skills

Third-party risk
Security risk assessment
Policy compliance
SOC reports review
ISO 27001
NIST CSF
Vulnerability management
Cloud security
Stakeholder comms

Education

CISSP/CISM/CRISC or equivalent

Tools

ServiceNow
Archer
LogicGate
OneTrust

Job description

Job Description:

Why Mobility Global?

At Mobility Global, our mission is to provide the trusted information that helps billions of people build, sell, and own vehicles with confidence. As we shape the next generation of automotive intelligence through innovation, AI, and industry-leading data, we're creating new opportunities for our customers, our business, and our people.

The Team

A global Cyber Governance, Risk & Compliance (GRC) team that is responsible for managing cyber risk, driving policy adherence, enabling compliance, supporting customer trust initiatives, and delivering enterprise-wide governance processes. The team partners across IT, Security, Legal, Risk, Privacy, Sales, and Business functions to deliver integrated risk management and assurance capabilities.

Responsibilities And Impact

The Senior Cyber GRC Specialist is an individual contributor responsible for assessing and managing cybersecurity risks arising from third-party relationships and deviations from approved security policies and standards. The role serves as a technical risk advisor across Security, Technology, Procurement, Legal, Privacy, and business teams.

This position requires practical cybersecurity knowledge to review technical controls, ask appropriate follow-up questions, challenge incomplete or unsupported responses, evaluate compensating controls, and translate technical risk into clear business impact. The role assesses risk and provides recommendations; formal risk acceptance remains with the authorized business and security approvers.

  • Perform risk-based cybersecurity assessments of vendors, suppliers, SaaS providers, cloud service providers, and other third parties during onboarding, reassessment, renewal, and material service changes.
  • Review security questionnaires, independent assurance reports, certifications, penetration test summaries, architecture information, vulnerability management practices, incident response capabilities, and other relevant security evidence.
  • Engage vendor and internal technical teams to clarify security architecture, control design, identified gaps, remediation commitments, and residual risk.
  • Identify and document third-party cyber risks, determine risk severity, recommend risk treatment, and track agreed remediation actions through closure.
  • Apply assessment depth based on service criticality, data sensitivity, connectivity, hosting model, regulatory exposure, and potential business impact.
  • Administer the security exception management lifecycle, including intake, completeness review, risk assessment, routing, approval coordination, expiration, renewal, closure, and reporting.
  • Evaluate exception requests against applicable security policies and standards, including the business justification, scope, duration, technical exposure, compensating controls, remediation plan, and residual risk.
  • Challenge exception submissions when risks are not adequately understood, supporting evidence is insufficient, or proposed compensating controls do not reasonably reduce exposure.
  • Partner with Security Architecture, Cloud Security, Application Security, Infrastructure, Identity and Access Management, Vulnerability Management, and other subject matter experts when specialized validation is required.
  • Prepare clear risk recommendations for authorized approvers and governance forums while maintaining appropriate separation between risk assessment, risk ownership, and risk acceptance.
  • Maintain accurate risk records and supporting evidence in the designated governance, risk, and compliance platform.
  • Develop and report metrics on assessment volume, risk severity, remediation status, overdue actions, exception aging, renewals, expirations, and risk concentrations.
  • Identify recurring control gaps and trends across vendors and exceptions and recommend improvements to policies, standards, assessment criteria, contract requirements, and governance processes.
  • Support audits, certifications, regulatory inquiries, and customer assurance activities related to third-party cyber risk and security exception management.
  • Contribute to continuous improvement of risk methodologies, procedures, templates, decision criteria, and stakeholder guidance.
  • This role would report to the Senior Manager, Cyber Governance & Risk Management.
What We're Looking For
  • 5 -10 years of experience in cybersecurity, information security risk, technology risk, third-party risk management, security architecture, security engineering, or a related discipline.
  • Demonstrated experience performing technical security assessments of vendors, cloud services, applications, infrastructure, or enterprise technology environments.
  • Experience evaluating policy or control exceptions, compensating controls, remediation plans, and residual risk is strongly preferred.
  • Working knowledge of identity and access management, multifactor authentication, privileged access, cloud security, network security, vulnerability management, endpoint protection, application security, encryption, logging and monitoring, incident response, resilience, and data protection.
  • Ability to interpret common security evidence, including SOC reports, ISO 27001 certifications, penetration test summaries, vulnerability information, security architecture documentation, and control descriptions.
  • Working knowledge of recognized cybersecurity and risk frameworks, such as ISO 27001, NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, and TISAX.
  • Strong analytical judgment with the ability to distinguish administrative gaps from material technical risk and to evaluate whether proposed controls adequately reduce exposure.
  • Ability to communicate clearly with technical teams, vendors, business owners, procurement, legal, privacy, auditors, and senior stakeholders.
  • Strong documentation, organization, and follow-through skills, with the ability to manage multiple assessments, exceptions, and remediation actions concurrently.
  • Ability to operate independently, escalation material concerns appropriately, and provide objective, evidence-based risk recommendations.
Preferred Qualifications
  • Professional certification such as CISSP, CISM, CRISC, CCSK, CCSP, Security+, or an equivalent credential.
  • Experience with a governance, risk, and compliance platform or third-party risk management solution, such as ServiceNow, Archer, LogicGate, OneTrust, or a comparable platform.
  • Experience supporting ISO 27001, SOC 2, TISAX, customer assurance, regulatory compliance, or audit activities.
  • Prior technical experience in security engineering, security architecture, cloud security, vulnerability management, incident response, or a security operations function.

This is a hybrid role with in-office expectations determined by location and subject to change based on evolving business needs.

What's In It For You
  • Competitive compensation package, including base salary and incentive opportunities where applicable.
  • Comprehensive health and wellness benefits for employees and eligible dependents.
  • Retirement savings programs, including company matching contributions where available.
Equal Opportunity Employer

Mobility Global is proud to be an Equal Opportunity Employer. We value diverse perspectives and are committed to fostering an inclusive workplace where everyone is respected, supported, and empowered to succeed. We provide reasonable accommodations throughout the hiring process and employment for qualified individuals with disabilities.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cyber GRC Specialist
Senior Cyber GRC Specialist

R.L. Polk Private Limited • Gurugram District

On-site
INR 1,200,000 - 1,800,000
Competitive compensation
Health and wellness benefits
Retirement savings plan
GRC - Security Analyst
GRC - Security Analyst

Jobgether • India

On-site
INR 1,200,000 - 1,800,000
Fully remote in India
Full-time employment
Exposure to multiple security framesk—
+2
Cybersecurity - Risk & Compliance Analyst
Cybersecurity - Risk & Compliance Analyst

Scybers • Chennai District

On-site
INR 900,000 - 1,500,000
Senior/Lead - Infosec
Senior/Lead - Infosec

usemultiplier.com • Bengaluru

On-site
INR 900,000 - 1,600,000
GRC Analyst
GRC Analyst

Cyderes • Bengaluru

On-site
INR 1,200,000 - 2,400,000
Medical Insurance
Life Insurance
Retirement Match Program
+6
Senior GRC Consultant
Senior GRC Consultant

CyberSRC Consultancy Pvt. Ltd. • Chennai District

On-site
INR 1,500,000 - 2,500,000
Senior GRC Analyst
Senior GRC Analyst

3M HEALTHCARE • Hyderabad

On-site
INR 1,500,000 - 2,200,000
Cybersecurity Lead - GRC
Cybersecurity Lead - GRC

Medusind • Mumbai

On-site
INR 2,500,000 - 4,500,000
Cybersecurity & Compliance Advisor
Cybersecurity & Compliance Advisor

Siemens • Gurugram District

On-site
INR 2,800,000 - 4,200,000
Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

Powerbridge • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Health insurance
Long-term benefit savings plan
Professional development opportunities