Senior Security GRC & ISO 27001 Manager

UST

Thiruvananthapuram

On-site

INR 1,500,000 - 2,100,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

UST seeks an experienced Head of GRC to own and mature the organization’s governance, risk, and compliance program from policy to audit management and resilience. You will lead a team of GRC analysts and resilience engineers, interfacing with executives and business heads to drive continuous compliance.

The role requires 8+ years in cybersecurity and IT risk with deep GRC knowledge, including ISO 27001, NIST CSF, and regulatory requirements.

Qualifications

  • 8+ years in cybersecurity and IT risk with focus on GRC.
  • Experience leading enterprise GRC programs covering governance, compliance, audit, and resilience.
  • Proven ability to translate risk findings for C-suite and board audiences.

Responsibilities

  • Lead BCP/DR programs and crisis management.
  • Oversee internal and external audits and remediation.
  • Develop enterprise governance framework aligning policies and standards.
  • Provide executive risk and compliance reporting.

Skills

GRC governance
ISO 27001
NIST CSF
Audit management
BCP/DR
Regulatory compliance
Phishing simulations
Stakeholder management
GRC tools

Tools

ServiceNow GRC
Archer
MetricStream
OneTrust

Job description

Role Description Role Overview Own the end-to-end Security Governance, Risk & Compliance (GRC) tower, encompassing Security Governance, Compliance & Resilience, BCP & DR, and Audit & Compliance. Establish, lead, and continuously mature the organization's GRC program from policy frameworks and compliance certifications through to audit management and operational resilience. Lead a team of GRC analysts, compliance specialists, and resilience engineers; define team strategy, capability roadmap, and performance objectives. Act as the primary Subject-Matter Expert (SME) for GRC disciplines, interfacing with executive leadership, internal audit, legal, risk, engineering, and business unit heads. Deliver executive and board-level risk and compliance reporting, including metrics on control effectiveness, audit findings, certification status, and resilience posture. Drive a unified governance framework that integrates policies, standards, risk management, compliance, audit, and resilience into a cohesive operating model. Champion a risk-based, continuous compliance approach embedding security controls into business processes and technology lifecycle management. Key Responsibilities BCP & DR / Continuity Planning & Management Audit & Compliance Lead Business Impact Analysis (BIA) to identify critical processes, dependencies, RTO and RPO targets across the enterprise. Develop, maintain, and exercise Business Continuity Plans (BCPs) and Disaster Recovery (DR) plans aligned to regulatory and business requirements. Establish DR governance define DR tiers, own DR test scheduling, execution, and post- exercise reporting. Assess IS preparedness against continuity scenarios; identify gaps and drive remediation through structured action plans. Develop and maintain technology-business dependency maps to underpin continuity and DR planning. Own the Security Compliance Certification Lifecycle plan, execute, and manage certifications (ISO 27001, SOC 2, PCI-DSS, HIPAA, DPDP, etc.). Manage the calendar and execution of Internal and External Audits coordinate evidence collection, stakeholder responses, and management actions. Design and operate a Control Validation program continuously test and validate the operating effectiveness of security controls. Conduct formal Gap Assessments against regulatory frameworks and industry standards; produce gap remediation roadmaps with ownership and timelines. Confidential Internal Use Only Page Lead Crisis Management planning establish protocols, communication trees, and executive escalation runbooks. Report BCP/DR posture metrics to senior leadership and integrate findings into the enterprise risk register. Maintain audit-ready documentation, control registers, and evidence repositories at all times. Engage with external auditors, certification bodies, and regulatory authorities as the primary organizational point of contact. Track and close audit findings, non- conformities, and corrective action plans (CAPs) within agreed timelines. Operational Resilience & Governance Recommended Roadmap Items (FY'25-26) Develop, publish, and maintain the enterprise Security Policies and Standards library ensuring alignment to regulatory requirements and business context. Define and track Security Metrics and KPIs/KRIs that measure governance program health and control effectiveness. Design and execute a Security Awareness & Training program including role-based training curricula, completion tracking, and effectiveness measurement. Run a managed Phishing Simulation program configure scenarios, analyse results, and feed outcomes into targeted training interventions. Build and operate a Unified Governance Framework that aligns GRC processes, tools, and stakeholders under a single operating model. Ensure governance processes support regulatory change management tracking emerging laws, regulations, and standards impacting the organization. Continuity Planning & Management BIA execution, RTO/RPO establishment, and plan documentation. DR Tests & Governance scheduled tabletop and full failover DR exercises with formal governance reporting. Assess IS Preparedness IS readiness assessments against BCP/DR scenarios. Tech-Business Dependency Mapping asset-to-process dependency mapping for all critical systems. Crisis Management crisis response protocols, playbooks, and communication frameworks. Security Compliance Certification Lifecycle roadmap to ISO 27001, SOC 2 Type II, and additional certifications. Internal & External Audits structured audit program with clear ownership and scheduling. Control Validation & Gap Assessment continuous control testing and annual framework gap analysis. Policies & Standards full policy library review/refresh cycle. Security Metrics executive dashboard of GRC KPIs and KRIs. Training & Awareness + Phishing Simulations annual awareness calendar with measurable outcomes. Unified Governance Framework integrated GRC operating model across all pillars. Program Leadership & Governance Confidential Internal Use Only Page Build, mentor, and manage the GRC team analysts, compliance specialists, and resilience practitioners; define career paths and performance goals. Develop and maintain GRC program policies, procedures, playbooks, and runbooks across all pillars (Governance, Compliance, Resilience, Audit). Collaborate with CISO, Legal, Risk, and Executive Leadership to align the GRC program with corporate risk appetite and strategic objectives. Drive quarterly Business Reviews (QBRs) with senior stakeholders and client CISOs on GRC program health, compliance status, and resilience posture. Evaluate, procure, and manage GRC tooling vendors; own the technology roadmap and budget for the GRC tower. Integrate GRC activities with the broader cybersecurity program VM, SOC, AppSec, and IAM to ensure a holistic risk management posture. Act as the domain lead for client-facing advisory engagements involving GRC program maturity assessment and uplift. Support incident response by providing real-time regulatory and compliance guidance during security incidents. Establish a continuous improvement cycle for all GRC processes, leveraging audit findings, control testing results, and industry benchmarks. Lead the design and delivery of a Metrics & Reporting framework providing CISO-ready dashboards and board-level visualizations of compliance posture and resilience health. Required Qualifications 8+ years of experience in cybersecurity and/or IT risk, with at least 4 years focused on GRC, compliance management, or operational resilience. Proven experience designing and leading enterprise GRC programs covering governance, compliance, audit, and business continuity / DR. Deep knowledge of security policy and standards frameworks ISO 27001, NIST CSF, NIST SP 800-53, CIS Controls, and equivalent. Hands-on experience managing compliance certification lifecycles ISO 27001,ISO 22301,ISO 27701,HITRUST, SOC 2, PCI-DSS, HIPAA, or DPDP. Strong background in BCP/DR program management BIA, RTO/RPO setting, DR governance, and crisis management. Experience conducting and managing internal and external audit engagements; familiarity with audit evidence collection and finding remediation. Proficiency with GRC platforms such as ServiceNow GRC, Archer, MetricStream, OneTrust, or equivalent. Experience designing and executing security awareness programs including phishing simulations. Excellent communication and stakeholder management skills ability to translate GRC findings into risk narratives for C-suite and board audiences. Familiarity with regulatory and data protection requirements: GDPR, DPDP Act, RBI guidelines, SEBI CSCRF, or sector-specific mandates. Confidential Internal Use Only Page Preferred Qualifications Experience in a consulting or managed security services environment, advising multiple enterprise clients on GRC strategy and maturity uplift. Familiarity with integrated risk management (IRM) methodologies and enterprise risk management (ERM) frameworks. Exposure to OT/ICS compliance and resilience requirements in industrial or critical infrastructure environments. Experience with third-party and supply chain risk management (TPRM/SCRM) programs. Background in security architecture or technical security assessments to complement governance expertise. Knowledge of AI governance and emerging regulatory requirements related to AI/ML risk management. Experience building and operating a Phishing Simulation program using platforms such as KnowBe4, Proofpoint Security Awareness, or Cofense. Certifications Required / Strongly Preferred ISO 27001 Lead Auditor or Lead Implementer ISO 22301 Lead Auditor or Lead Implementer CISA Certified Information Systems Auditor Nice to Have CISSP Certified Information Systems Security Professional CISM Certified Information Security Manager CRISC Certified in Risk and Information Systems Control CCSP Certified Cloud Security Professional Compliance, Cybersecurity, GRC, Quality Metrics

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Security GRC & ISO 27001 Manager
Sr Security GRC & ISO 27001 Manager

UST • Thiruvananthapuram

On-site
INR 2,500,000 - 4,000,000
Manager- GRC
Manager- GRC

CyberCube Services • Gurugram District

On-site
INR 1,500,000 - 2,100,000
Senior Manager
Senior Manager

Pellera Technologies • India

On-site
INR 2,500,000 - 4,500,000
Governance, Risk & Compliance (GRC) Manager
Governance, Risk & Compliance (GRC) Manager

TeamsWork.In • India

On-site
INR 1,500,000 - 2,100,000
Sr Engineer, Governance, Risk & Compliance
Sr Engineer, Governance, Risk & Compliance

NextGen Healthcare India • Bengaluru

On-site
INR 1,600,000 - 2,800,000
GRC Lead / Security Compliance Lead
GRC Lead / Security Compliance Lead

Gnani Innovations Private Limited. • India

On-site
INR 350,000 - 600,000
Technical Manager
Technical Manager

Incedo Inc. • Gurugram District

On-site
INR 2,500,000 - 5,000,000
Product GRC Consultant
Product GRC Consultant

CyRAACS™ • Bengaluru

On-site
INR 600,000 - 1,200,000
Lead Compliance Specialist
Lead Compliance Specialist

TAC Security • Chandigarh

On-site
INR 2,600,000 - 3,200,000
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

844 Altera Semiconductor Technology India Pvt. Ltd. • Bengaluru

On-site
INR 2,000,000 - 3,000,000