Senior Role - GRC & Infosec

NPCI Bharat BillPay Limited

Mumbai

On-site

INR 2,000,000 - 3,000,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

A financial services organization in Mumbai is looking for an Information Technology Governance Manager to lead governance and risk management initiatives. The candidate should have a B.E. / B.Tech and over 13 years of experience, with proven leadership skills in Governance, Risk, and Compliance. Responsibilities include defining GRC strategy, overseeing risk assessments, and ensuring compliance with industry regulations. This role offers a full-time position with opportunities for professional growth.

Qualifications

  • Minimum 13+ years of experience in Governance, Risk, and Compliance roles, with leadership experience.
  • Certifications like Security+, CEH, CISSP, and CISM preferred.

Responsibilities

  • Lead the development and implementation of governance frameworks.
  • Oversee enterprise-wide risk assessments and mitigation strategies.
  • Ensure compliance with laws and regulatory requirements.
  • Communicate with leadership about risk posture.
  • Review information security requests and approve them.

Skills

GRC principles
Analytical skills
Communication skills
Leadership abilities
Risk assessment methodologies
Compliance audits
Security frameworks (e.g., NIST, ISO)
Vulnerability Management

Education

B.E. / B.Tech
Professional certifications (Security+, CEH, etc.)

Tools

ServiceNow
Jira

Job description

Information Technology Governance Manager

Get AI-powered advice on this job and more exclusive features.

Direct message the job poster from NPCIBharatBillPayLimited

Job Summary

The selected candidate will lead the development, implementation, and continuous improvement of the organization’s governance, risk management, and compliance frameworks and programs. This role is critical in fostering a strong risk-aware and compliant culture across all departments, ensuring the organization meets its legal, regulatory, and ethical obligations while strategically managing potential threats to its operations and objectives.

Education & Qualification
  • B.E. / B.Tech with minimum 13+ years of experience in Governance, Risk, and Compliance roles, with a significant portion in a leadership capacity.
  • Professional certifications such as Security+, CEH, CISSP, CISM, CGEIT, GRC Professional, CCISO or similar are preferred.
Key Responsibilities
  • Define the overall GRC strategy, policies, standards, and procedures.
  • Oversee the identification, assessment, analysis, and prioritization of enterprise-wide risks, including operational, reputational, and cybersecurity risks.
  • Develop and implement robust risk mitigation strategies and controls.
  • Monitor the effectiveness of risk management activities and report on the organization’s risk posture to senior leadership and the Board.
  • Ensure the organization complies with all applicable laws, regulations, industry standards, and internal policies (e.g., data privacy regulations like DPDPA, RBI regulatory requirements and compliance).
  • Develop and manage compliance programs, internal audits, and assessments to identify and address compliance gaps.
  • Drive a strong governance culture by establishing clear accountability, transparency, and ethical conduct throughout the organization.
  • Develop and implement governance policies and procedures to guide decision-making and operational processes.
  • Develop meaningful GRC metrics, dashboards, and reports for various stakeholders, including executive management and the Board.
  • Collaborate closely with various departments, including Enterprise Risk, IT Operations, Legal, Finance and HR to integrate GRC principles into daily business operations.
  • Act as a trusted advisor to business on Infosec Risk and Compliance matters.
  • Thoroughly review all incoming information security requests (e.g., user access, system configuration changes, firewall rules creation/modifications, software installations, data access, third-party system integrations) and approve them.
  • Assess requests for completeness, accuracy, and adherence to established information security policies, procedures, & guidelines and analyze potential security risks, impacts associated with each request, including data confidentiality, integrity, and availability.
  • Review and approve access requests to sensitive systems, applications, and data and validate justifications, roles, and least-privilege principles prior to approval.
  • Maintain a comprehensive understanding of evolving security threats, vulnerabilities, and regulatory changes related to upcoming technologies like Blockchain and AI to take informed approval decisions.
  • Review and recommend exceptions to security policies and standards, identify and document any residual risks associated with approved exceptions, and ensure that compensating controls are in place for recommended exceptions, documenting the rationale, validity period, and expiration tracking.
  • Communicate clearly and concisely with requestors, providing detailed explanations for approvals, denials, or requests for additional information.
  • Identify opportunities to streamline the request approval process, enhance efficiency, and improve security controls.
  • Evaluate security architectures and designs to determine the adequacy of security design and architecture proposed or provided in response to requirements.
  • Provide guidance and mentorship to junior security team members.
Technical Skills
  • Deep understanding of GRC principles, methodologies, and best practices.
  • Strong analytical and problem-solving skills with the ability to identify, assess, and mitigate complex risks.
  • Excellent communication, interpersonal, and presentation skills, with the ability to articulate complex GRC concepts to diverse audiences (technical and non-technical, all levels of management).
  • Proven leadership and team management abilities, including the ability to influence and collaborate across departments.
  • Strategic thinking with a proactive approach to GRC challenges.
  • High level of integrity and ethical conduct.
  • Ability to manage multiple projects and priorities in a dynamic environment.
  • Proven track record of developing, implementing, and managing successful GRC programs in a complex organizational environment.
  • Strong experience with risk assessment methodologies, control frameworks, and compliance audits.
  • Experience with relevant regulatory frameworks (e.g., ISO 27001, NIST, SOC 2, PCI DSS, DPDPA, GDPR etc.).
  • Strong understanding of security domains (e.g., network security, data security, application security).
  • Understanding on cryptographic standards, application security, enterprise architecture, software development lifecycle etc.
  • Experience with security frameworks (e.g., MITRE, NIST, ISO).
  • Familiar in Vulnerability Management and Configuration Management with a commitment to staying current on emerging security threats and technological advancements.
  • Knowledge of identity and access management (IAM) concepts and technologies and Familiarity with role-based access control (RBAC) models and approval workflows.
  • Knowledge of cryptography, secure communication protocols, data encryption techniques, understanding of Key management process.
  • Deep understanding of security vulnerabilities exploits applications, infrastructure and APIs.
  • Strong analytical and problem-solving skills.
  • Basic understanding of cloud security principles (AWS, Azure, GCP) is a plus.
  • Experience with ITSM or request/ticketing systems (e.g., ServiceNow, Jira, Remedy).
Seniority level
  • Mid-Senior level
Employment type
  • Full-time
Job function
  • Other
Industries
  • Banking, IT Services and IT Consulting, and Financial Services

Referrals increase your chances of interviewing at NPCIBharatBillPayLimited by 2x

Get notified about new Information Technology Governance Manager jobs in Mumbai, Maharashtra, India.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Manager/ GRC Lead
GRC Manager/ GRC Lead

Riskpro India Ventures • Mumbai

On-site
INR 1,000,000 - 1,500,000
Technical Manager
Technical Manager

Incedo Inc. • Gurugram District

On-site
INR 2,500,000 - 5,000,000
Senior Manager/ AVP- GRC
Senior Manager/ AVP- GRC

T&m • Mumbai

On-site
INR 4,500,000 - 6,500,000
GRC Manager - Cyber
GRC Manager - Cyber

Cubical Operations LLP • Chennai District

On-site
INR 800,000 - 1,200,000
Cybersecurity Lead - GRC
Cybersecurity Lead - GRC

Medusind • Mumbai

On-site
INR 2,500,000 - 4,500,000
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

844 Altera Semiconductor Technology India Pvt. Ltd. • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Senior Manager - Enterprise Risk Management
Senior Manager - Enterprise Risk Management

Aeries Technology • Mumbai

On-site
INR 300,000 - 600,000
Cybersecurity Lead - GRC
Cybersecurity Lead - GRC

Medusind Solutions, Inc. • Mumbai

On-site
INR 1,500,000 - 2,100,000
Governance, Risk and Compliance (GRC) Specialist
Governance, Risk and Compliance (GRC) Specialist

Career Guideline • Pune District

On-site
INR 1,500,000 - 2,500,000
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

Altera • Bengaluru

On-site
INR 3,000,000 - 4,500,000