Senior Manager

Pellera Technologies

India

On-site

INR 2,500,000 - 4,500,000

Full time

Just now
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Pellera Technologies is seeking a Senior Governance, Risk, and Compliance (GRC) Lead to direct our security governance program and ongoing risk management across multiple frameworks including SOC 2, PCI, ISO, and CMMC-aligned environments.

The role focuses on policy lifecycle, control validation, audit readiness, and executive reporting, collaborating with Legal, Privacy, Compliance, and business stakeholders to drive risk-informed decisions and continuous improvement.

Qualifications

  • Bachelor's degree or equivalent in a relevant field and 7+ years in GRC/security/compliance roles.
  • Experience managing audit readiness programs, evidence collection, and cross-framework compliance.
  • Experience maintaining governance platforms and supporting evidence-management workflows is preferred.

Responsibilities

  • Lead the GRC program cadence, including risk committee activities and policy publication schedules.
  • Oversee audit readiness and evidence management across frameworks, ensuring complete and reusable artifacts.
  • Manage enterprise risk management, risk identification, ownership tracking, and executive reporting.
  • Handle policy lifecycle from drafting to publication and exception management.
  • Lead control effectiveness validation, design reviews, testing, and remediation follow-up.
  • Oversee access governance and align reviews with exception management processes.
  • Support AI governance, customer assurance activities, architecture reviews, and security reviews.
  • Track audit findings, risk remediation, customer due diligence, and program assessments.

Skills

Governance
Risk management
Policy lifecycle
Control validation
Audit readiness
Executive reporting
AI governance
Customer assurance
Stakeholder management
Policy development

Education

Bachelor's degree in computer science, Information Technology, Cybersecurity, Business Administration, Risk Management, or related field; or equivalent

Job description

The Senior Governance, Risk, and Compliance (GRC) Lead is responsible for leading the organization's security governance program and operational cadence. Reporting to the Director of Information Security, this role oversees risk management, policy lifecycle management, control validation, audit readiness, evidence quality, and executive reporting across multiple compliance frameworks, including SOC 2, PCI, ISO, and CMMC-aligned environments. The ideal candidate combines strong governance expertise, audit readiness experience, and stakeholder leadership capabilities to drive risk-informed decision-making, maintain compliance objectives, and promote a culture of accountability, evidence quality, and continuous improvement.

Essential Functions:
  • Lead and manage the governance calendar and recurring GRC operating cadence, including risk committee activities, policy publication schedules, audit milestones, and control validation programs.
  • Oversee audit readiness and evidence management activities across applicable compliance frameworks, ensuring evidence is complete, timely, and reusable when appropriate.
  • Administer and continuously improve the enterprise risk management program, including risk identification, risk register maintenance, ownership tracking, risk reviews, and executive reporting.
  • Manage the full policy lifecycle, including drafting coordination, review processes, publication, communication, and exception management alignment.
  • Lead control effectiveness validation efforts, including control design reviews, operational effectiveness testing, evidence standards development, sampling methodologies, and remediation follow-up activities.
  • Oversee access governance programs from a compliance and risk perspective, ensuring reviews are completed, documented, and aligned with exception management processes.
  • Support governance initiatives related to AI governance, customer assurance activities, architecture reviews, and security review processes.
  • Track and manage audit findings, risk remediation efforts, customer diligence requests, and program assessment results, escalating significant risks and obstacles as appropriate.
  • Maintain customer-facing security assurance materials, evidence packages, and trust documentation supporting customer and sales engagements.
  • Prepare leadership-level reporting on governance decisions, risk posture, compliance status, and remediation progress.
  • Collaborate with Security, Internal IT, Legal, Privacy, Compliance, and business stakeholders to support evidence collection, testing, remediation planning, and validation activities.
  • Promote a culture of evidence quality, repeatable governance processes, accountability, and continuous improvement across the organization.
  • Strong knowledge of governance, risk management, compliance programs, policy management, and control validation methodologies.
  • Extensive understanding of multi-framework compliance environments, including SOC 2, PCI, ISO 27001, CMMC, and NIST-aligned standards.
  • Expertise in risk management practices, including risk identification, risk register administration, ownership tracking, risk assessments, and executive reporting.
  • Strong policy development, procedure documentation, and executive-level writing skills with the ability to translate control requirements into scalable operational processes.
  • Experience conducting control effectiveness reviews, operating effectiveness testing, evidence validation, remediation oversight, and audit support activities.
  • Knowledge of governance operating models, committee facilitation, calendar management, and follow-through on governance decisions and remediation actions.
  • Strong executive communication, presentation, and reporting skills that translate technical and compliance activities into actionable business insights.
  • Familiarity with access governance oversight, exception management, customer assurance programs, and cross-framework control mapping.
  • Knowledge of emerging governance disciplines, including AI governance, third-party risk management, and privacy governance.
  • Strong stakeholder management, relationship-building, accountability, and issue escalation skills.
  • Ability to establish priorities, manage multiple initiatives simultaneously, and meet deadlines in a fast-paced environment.
  • Demonstrated competencies in Governance Program Management, Risk Management, Policy Lifecycle Management, Control Effectiveness Validation, Audit Readiness, Multi-Framework Compliance, Executive Reporting, Customer Assurance, and Stakeholder Management.
Education and Experience:
  • Bachelor's degree in computer science, Information Technology, Cybersecurity, Business Administration, Risk Management, or a related field; or an equivalent combination of education and relevant professional experience.
  • Minimum of seven (7) years of experience in Governance, Risk and Compliance (GRC), Security Compliance, IT Audit, Enterprise Risk Management, or Security Program Management.
  • Experience managing audit readiness programs, evidence collection processes, control testing activities, and compliance initiatives across multiple security and regulatory frameworks.
  • Experience maintaining governance, risk, and compliance technology platforms and supporting evidence-management workflows is preferred.
  • Familiarity with customer-facing assurance programs, due diligence support, vendor security reviews, and security trust programs is preferred.
  • Experience supporting risk committees, governance forums, executive reporting, and enterprise-wide policy management processes.
  • Relevant certifications such as CISSP, CISA, CRISC, ISO Lead Auditor, ISO Lead Implementer, PCI QSA, or equivalent industry credentials are preferred.
  • Experience working in highly regulated, client-assurance-focused, or defense-adjacent environments is preferred.
Physical Requirements:
  • Prolonged periods of sitting at a desk and working on a computer.
  • Must be able to lift up to 15 pounds at times.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance, Risk & Compliance (GRC) Manager
Governance, Risk & Compliance (GRC) Manager

TeamsWork.In • India

On-site
INR 1,500,000 - 2,100,000
Senior Security GRC & ISO 27001 Manager
Senior Security GRC & ISO 27001 Manager

UST • Thiruvananthapuram

On-site
INR 2,500,000 - 4,500,000
Senior GRC Engineer
Senior GRC Engineer

Qualys • Pune District

On-site
INR 4,500,000 - 7,000,000
Manager- GRC
Manager- GRC

CyberCube Services • Gurugram District

On-site
INR 1,500,000 - 2,100,000
Lead Security GRC Analyst
Lead Security GRC Analyst

Providence India • Hyderabad

On-site
INR 2,500,000 - 4,000,000
Sr Engineer, Governance, Risk & Compliance
Sr Engineer, Governance, Risk & Compliance

NextGen Healthcare India • Bengaluru

On-site
INR 1,600,000 - 2,800,000
Senior GRC Engineer
Senior GRC Engineer

Qualys • Maharashtra

On-site
INR 4,000,000 - 8,000,000
Technical Manager
Technical Manager

Incedo Inc. • Gurugram District

On-site
INR 2,500,000 - 5,000,000
GRC Consultant
GRC Consultant

Lonvec Technologies Private Limited • Hyderabad

On-site
INR 1,200,000 - 2,200,000
Product GRC Consultant
Product GRC Consultant

CyRAACS™ • Bengaluru

On-site
INR 600,000 - 1,200,000