Senior Security GRC & ISO 27001 Manager

UST

Thiruvananthapuram

On-site

INR 2,500,000 - 4,500,000

Full time

23 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

UST is seeking a seasoned GRC leader to own end-to-end Governance, Risk & Compliance, including security governance, resilience, BCP/DR, and audit management. You will lead a team of GRC analysts and resilience engineers, defining strategy, roadmaps, and performance objectives.

You will serve as SME to executives, deliver board-ready risk reports, drive a unified governance framework, and embed risk-based compliance into processes and lifecycle management.

Qualifications

  • 8+ years of experience in cybersecurity and/or IT risk, with at least 4 years in GRC or resilience.
  • Design and lead enterprise GRC programs covering governance, compliance, audit, and BCP/DR.
  • Deep knowledge of ISO 27001, NIST CSF/800-53, CIS Controls.
  • Experience managing compliance lifecycles ISO 27001, ISO 22301, SOC 2, PCI-DSS, HIPAA, DPDP.
  • Strong BCP/DR program management including BIA, RTO/RPO, crisis management.
  • Excellent communication, stakeholder management; translate findings for execs.
  • Familiarity with GDPR/DPDP RBI etc.

Responsibilities

  • Lead BCP & DR governance, test scheduling, and post-exercise reporting.
  • Oversee internal and external audits; coordinate evidence and remediation.
  • Develop and maintain control validation and gap remediation roadmaps.
  • Report GRC posture metrics to senior leadership; integrate into risk register.
  • Define and mature enterprise security policies, standards, and KPIs.
  • Collaborate with CISO, legal, risk, and executives on program alignment.
  • Manage GRC tooling strategy and budget; integrate with broader cybersecurity program.

Skills

Compliance
Cybersecurity
GRC
Quality Metrics

Tools

ServiceNow GRC
Archer
MetricStream
OneTrust

Job description

Role Description

Role Overview
Own the end-to‑end Security Governance, Risk & Compliance (GRC) tower, encompassing Security Governance, Compliance & Resilience, BCP & DR, and Audit & Compliance. Establish, lead, and continuously mature the organization's GRC program from policy frameworks and compliance certifications through to audit management and operational resilience. Lead a team of GRC analysts, compliance specialists, and resilience engineers; define team strategy, capability roadmap, and performance objectives. Act as the primary Subject‑Matter Expert (SME) for GRC disciplines, interfacing with executive leadership, internal audit, legal, risk, engineering, and business unit heads. Deliver executive and board‑level risk and compliance reporting, including metrics on control effectiveness, audit findings, certification status, and resilience posture. Drive a unified governance framework that integrates policies, standards, risk management, compliance, audit, and resilience into a cohesive operating model. Champion a risk‑based, continuous compliance approach embedding security controls into business processes and technology lifecycle management.
Key Responsibilities
BCP & DR / Continuity Planning & Management Audit & Compliance Lead Business Impact Analysis (BIA) to identify critical processes, dependencies, RTO and RPO targets across the enterprise. Develop, maintain, and exercise Business Continuity Plans (BCPs) and Disaster Recovery (DR) plans aligned to regulatory and business requirements. Establish DR governance define DR tiers, own DR test scheduling, execution, and post‑exercise reporting. Assess IS preparedness against continuity scenarios; identify gaps and drive remediation through structured action plans. Develop and maintain technology‑business dependency maps to underpin continuity and DR planning. Own the Security Compliance Certification Lifecycle plan, execute, and manage certifications (ISO 27001, SOC 2, PCI‑DSS, HIPAA, DPDP, etc.). Manage the calendar and execution of Internal and External Audits coordinate evidence collection, stakeholder responses, and management actions. Design and operate a Control Validation program continuously test and validate the operating effectiveness of security controls. Conduct formal Gap Assessments against regulatory frameworks and industry standards; produce gap remediation roadmaps with ownership and timelines. Confidential Internal Use Only Page Lead Crisis Management planning establish protocols, communication trees, and executive escalation runbooks. Report BCP/DR posture metrics to senior leadership and integrate findings into the enterprise risk register. Maintain audit‑ready documentation, control registers, and evidence repositories at all times. Engage with external auditors, certification bodies, and regulatory authorities as the primary organizational point of contact. Track and close audit findings, non‑conformities, and corrective action plans (CAPs) within agreed timelines.
Operational Resilience & Governance
Recommended Roadmap Items (FY'25‑26) Develop, publish, and maintain the enterprise Security Policies and Standards library ensuring alignment to regulatory requirements and business context. Define and track Security Metrics and KPIs/KRIs that measure governance program health and control effectiveness. Design and execute a Security Awareness & Training program including role‑based training curricula, completion tracking, and effectiveness measurement. Run a managed Phishing Simulation program configure scenarios, analyse results, and feed outcomes into targeted training interventions. Build and operate a Unified Governance Framework that aligns GRC processes, tools, and stakeholders under a single operating model. Ensure governance processes support regulatory change management tracking emerging laws, regulations, and standards impacting the organization. Continuity Planning & Management BIA execution, RTO/RPO establishment, and plan documentation. DR Tests & Governance scheduled tabletop and full failover DR exercises with formal governance reporting. Assess IS Preparedness IS readiness assessments against BCP/DR scenarios. Tech‑Business Dependency Mapping asset‑to‑process dependency mapping for all critical systems. Crisis Management crisis response protocols, playbooks, and communication frameworks. Security Compliance Certification Lifecycle roadmap to ISO 27001, SOC 2 Type II, and additional certifications. Internal & External Audits structured audit program with clear ownership and scheduling. Control Validation & Gap Assessment continuous control testing and annual framework gap analysis. Policies & Standards full policy library review/refresh cycle. Security Metrics executive dashboard of GRC KPIs and KRIs. Training & Awareness + Phishing Simulations annual awareness calendar with measurable outcomes. Unified Governance Framework integrated GRC operating model across all pillars. Program Leadership & Governance Build, mentor, and manage the GRC team analysts, compliance specialists, and resilience practitioners; define career paths and performance goals. Develop and maintain GRC program policies, procedures, playbooks, and runbooks across all pillars (Governance, Compliance, Resilience, Audit). Collaborate with CISO, Legal, Risk, and Executive Leadership to align the GRC program with corporate risk appetite and strategic objectives. Drive quarterly Business Reviews (QBRs) with senior stakeholders and client CISOs on GRC program health, compliance status, and resilience posture. Evaluate, procure, and manage GRC tooling vendors; own the technology roadmap and budget for the GRC tower. Integrate GRC activities with the broader cybersecurity program VM, SOC, AppSec, and IAM to ensure a holistic risk management posture. Act as the domain lead for client‑facing advisory engagements involving GRC program maturity assessment and uplift. Support incident response by providing real‑time regulatory and compliance guidance during security incidents. Establish a continuous improvement cycle for all GRC processes, leveraging audit findings, control testing results, and industry benchmarks. Lead the design and delivery of a Metrics & Reporting framework providing CISO‑ready dashboards and board‑level visualizations of compliance posture and resilience health.
Required Qualifications
8+ years of experience in cybersecurity and/or IT risk, with at least 4 years focused on GRC, compliance management, or operational resilience. Proven experience designing and leading enterprise GRC programs covering governance, compliance, audit, and business continuity / DR. Deep knowledge of security policy and standards frameworks ISO 27001, NIST CSF, NIST SP 800‑53, CIS Controls, and equivalent. Hands‑on experience managing compliance certification lifecycles ISO 27001,ISO 22301,ISO 27701,HITRUST, SOC 2, PCI‑DSS, HIPAA, or DPDP. Strong background in BCP/DR program management BIA, RTO/RPO setting, DR governance, and crisis management. Experience conducting and managing internal and external audit engagements; familiarity with audit evidence collection and finding remediation. Proficiency with GRC platforms such as ServiceNow GRC, Archer, MetricStream, OneTrust, or equivalent. Experience designing and executing security awareness programs including phishing simulations. Excellent communication and stakeholder management skills ability to translate GRC findings into risk narratives for C‑suite and board audiences. Familiarity with regulatory and data protection requirements: GDPR, DPDP Act, RBI guidelines, SEBI CSCRF, or sector‑specific mandates.
Preferred Qualifications
Experience in a consulting or managed security services environment, advising multiple enterprise clients on GRC strategy and maturity uplift. Familiarity with integrated risk management (IRM) methodologies and enterprise risk management (ERM) frameworks. Exposure to OT/ICS compliance and resilience requirements in industrial or critical infrastructure environments. Experience with third‑party and supply chain risk management (TPRM/SCRM) programs. Background in security architecture or technical security assessments to complement governance expertise. Knowledge of AI governance and emerging regulatory requirements related to AI/ML risk management. Experience building and operating a Phishing Simulation program using platforms such as KnowBe4, Proofpoint Security Awareness, or Cofense. Certifications Required / Strongly Preferred ISO 27001 Lead Auditor or Lead Implementer ISO 22301 Lead Auditor or Lead Implementer CISA Certified Information Systems Auditor Nice to Have CISSP Certified Information Systems Security Professional CISM Certified Information Security Manager CRISC Certified in Risk and Information Systems Control CCSP Certified Cloud Security Professional
Skills
Compliance, Cybersecurity, GRC, Quality Metrics
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager- GRC
Manager- GRC

CyberCube Services • Gurugram District

On-site
INR 1,500,000 - 2,100,000
Governance, Risk & Compliance (GRC) Manager
Governance, Risk & Compliance (GRC) Manager

TeamsWork.In • India

On-site
INR 1,500,000 - 2,100,000
Senior Manager
Senior Manager

Pellera Technologies • India

On-site
INR 2,500,000 - 4,500,000
GRC Lead / Security Compliance Lead
GRC Lead / Security Compliance Lead

Gnani Innovations Private Limited. • India

On-site
INR 350,000 - 600,000
Sr Engineer, Governance, Risk & Compliance
Sr Engineer, Governance, Risk & Compliance

NextGen Healthcare India • Bengaluru

On-site
INR 1,600,000 - 2,800,000
Technical Manager
Technical Manager

Incedo Inc. • Gurugram District

On-site
INR 2,500,000 - 5,000,000
Product GRC Consultant
Product GRC Consultant

CyRAACS™ • Bengaluru

On-site
INR 600,000 - 1,200,000
Required Skillset
Required Skillset

eProtect 360 • Mumbai

On-site
INR 2,000,000 - 3,500,000
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

844 Altera Semiconductor Technology India Pvt. Ltd. • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Lead Security GRC Analyst
Lead Security GRC Analyst

Providence India • Hyderabad

On-site
INR 2,500,000 - 4,000,000