Senior Manager – IT Governance

Concept Medical

Surat

On-site

INR 4,000,000 - 7,000,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Concept Medical is seeking a Senior Manager – IT Governance to lead governance, information security, risk and compliance, ISMS, business continuity, and IT audit across the organization.

You will serve as Group ISMS Owner for ISO/IEC 27001:2022, drive GRC programs, and ensure security controls, incident response, and regulatory readiness including DPDP Act and GDPR.

Qualifications

  • 10–15 years of IT or information security experience.
  • Minimum 4 years in information security governance, IT compliance, risk management, or management systems.
  • Strong hands-on experience with ISO 27001 ISMS and ISO 22301.
  • Experience in regulated industries, preferably Medical Devices, Pharma, Healthcare, or Life Sciences.
  • Solid knowledge of IT risk, audits, IAM, cybersecurity, ITGC, BCM, privacy, and vendor security.

Responsibilities

  • Own ISO/IEC 27001:2022 ISMS including SoA, risk assessment, treatment plans, policies, and risk acceptance.
  • Lead IT Governance, Risk & Compliance and audit readiness (internal/external).
  • Govern IAM, PAM, MFA, SoD, and quarterly access reviews.
  • Drive ISO 22301 Business Continuity & Disaster Recovery governance.
  • Oversee cybersecurity governance, incident response, VAPT, vulnerability management, SIEM, and security controls.
  • Drive DPDP Act & GDPR readiness and third-party/vendor security assurance.
  • Ensure IT compliance with ISO 13485, GxP, and applicable regulatory requirements.
  • Align IT security controls with NIST CSF and CIS Controls.
  • Lead the IT Governance team and provide risk, compliance, and security reporting to management.

Skills

IT Governance
Information Security
Risk Management
Compliance
ISMS
Business Continuity
IT Audit
ISO 27001
ISO 22301
IAM
PAM
MFA
SoD
VAPT
SIEM
DPDP Act
GDPR readiness
NIST CSF
CIS Controls
ITGC
BCM
Vendor Security

Job description

Role Overview

We are looking for a Senior Manager – IT Governance to lead IT Governance, Information Security, Risk & Compliance, ISMS, Business Continuity, and IT Audit.

The role will serve as the Group ISMS Owner for ISO/IEC 27001:2022, ensuring strong governance, risk management, compliance, security controls, and business resilience across the organization.

Key Responsibilities
  • Own ISO/IEC 27001:2022 ISMS, including SoA, risk assessment, treatment plans, policies, and risk acceptance.
  • Lead IT Governance, Risk & Compliance (GRC) and internal/external audit readiness.
  • Govern IAM, PAM, MFA, SoD, and quarterly access reviews.
  • Drive ISO 22301 Business Continuity & Disaster Recovery governance.
  • Oversee cybersecurity governance, incident response, VAPT, vulnerability management, SIEM, and security controls.
  • Drive DPDP Act & GDPR readiness and third-party/vendor security assurance.
  • Ensure IT compliance with ISO 13485, GxP, and applicable regulatory requirements.
  • Align IT security controls with NIST CSF and CIS Controls.
  • Lead the IT Governance team and provide effective risk, compliance, and security reporting to management.
Candidate Profile
  • 10–15 years of relevant IT / Information Security experience.
  • At least 4 years specifically in Information Security Governance, IT Compliance, Risk Management, or Management Systems.
  • Strong hands‑on experience with ISO 27001 ISMS and ISO 22301.
  • Experience in regulated industries, preferably Medical Devices, Pharma, Healthcare, or Life Sciences.
  • Strong knowledge of IT risk, audits, IAM, cybersecurity, ITGC, BCM, privacy, and vendor security.
Certifications – Preferred

ISO 27001 / ISO 22301 Lead Auditor or Implementer | CISA | CISM | CRISC | CISSP

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager IT Governance & Compliance
Manager IT Governance & Compliance

Sabpaisa • Delhi

On-site
INR 1,500,000 - 2,500,000
Senior GRC Analyst
Senior GRC Analyst

Exotel • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Senior Security GRC & ISO 27001 Specialist
Senior Security GRC & ISO 27001 Specialist

UST • Ernakulam

On-site
INR 2,800,000 - 4,200,000
Deputy General Manager-GRC
Deputy General Manager-GRC

SupportFinity™ • Ahmedabad District

On-site
INR 1,200,000 - 2,000,000
Senior Security GRC & ISO 27001 Manager
Senior Security GRC & ISO 27001 Manager

UST • Thiruvananthapuram

On-site
INR 1,500,000 - 2,100,000
Information Security GRC Manager
Information Security GRC Manager

Mount Talent Consulting • Mumbai

On-site
INR 3,000,000 - 5,000,000
Information Security Manager
Information Security Manager

Altraize • Mumbai

On-site
Compliance Executive
Compliance Executive

Plutos One • Dadri

On-site
INR 1,200,000 - 1,800,000
Information Security and Data Privacy Manager
Information Security and Data Privacy Manager

Tiger Analytics • Chennai District

Hybrid
INR 2,500,000 - 6,000,000
Senior GRC Analyst
Senior GRC Analyst

Exotel Techcom Pvt Ltd • Bengaluru

On-site
INR 800,000 - 1,400,000