Senior Security GRC & ISO 27001 Specialist

UST

Ernakulam

On-site

INR 2,800,000 - 4,200,000

Full time

15 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

UST seeks a senior GRC leader to own the end-to-end governance, risk, and compliance program, including policy frameworks, certifications, audit management, and resilience planning.

You will lead a team of GRC analysts and resilience engineers, coordinating with legal, risk, and executive leadership to deliver risk reports and remediation roadmaps, while embedding compliance into business processes.

Qualifications

  • 8+ years of cybersecurity/IT risk, with 4+ years in GRC, compliance, or resilience.
  • Experience designing and leading enterprise GRC programs covering governance, compliance, audit, and BC/DR.
  • Deep knowledge of ISO 27001, NIST CSF, NIST SP 800-53, CIS Controls.

Responsibilities

  • Lead end-to-end GRC program across governance, compliance, resilience, and audit.
  • Drive certification lifecycles: ISO 27001, SOC 2, PCI-DSS, DPDP, etc.
  • Manage internal and external audits, evidence collection, and remediation actions.
  • Develop and maintain policy library, controls, and metrics dashboards for execs and board.

Skills

GRC
Compliance
Risk Management
Security Governance
Audits

Tools

ServiceNow GRC
Archer
MetricStream
OneTrust
KnowBe4

Job description

Role Description

Role Overview

Own the end-to-end Security Governance, Risk & Compliance (GRC) tower, encompassing Security Governance, Compliance & Resilience, BCP & DR, and Audit & Compliance. Establish, lead, and continuously mature the organization's GRC program from policy frameworks and compliance certifications through to audit management and operational resilience. Lead a team of GRC analysts, compliance specialists, and resilience engineers; define team strategy, capability roadmap, and performance objectives. Act as the primary Subject-Matter Expert (SME) for GRC disciplines, interfacing with executive leadership, internal audit, legal, risk, engineering, and business unit heads. Deliver executive and board-level risk and compliance reporting, including metrics on control effectiveness, audit findings, certification status, and resilience posture. Drive a unified governance framework that integrates policies, standards, risk management, compliance, audit, and resilience into a cohesive operating model. Champion a risk-based, continuous compliance approach embedding security controls into business processes and technology lifecycle management.

Key Responsibilities

BCP & DR / Continuity Planning & Management

Audit & Compliance Lead

Business Impact Analysis (BIA) to identify critical processes, dependencies, RTO and RPO targets across the enterprise. Develop, maintain, and exercise Business Continuity Plans (BCPs) and Disaster Recovery (DR) plans aligned to regulatory and business requirements. Establish DR governance define DR tiers, own DR test scheduling, execution, and post-exercise reporting. Assess IS preparedness against continuity scenarios; identify gaps and drive remediation through structured action plans. Develop and maintain technology-business dependency maps to underpin continuity and DR planning. Own the Security Compliance Certification Lifecycle plan, execute, and manage certifications (ISO 27001, SOC 2, PCI-DSS, HIPAA, DPDP, etc.). Manage the calendar and execution of Internal and External Audits coordinate evidence collection, stakeholder responses, and management actions. Design and operate a Control Validation program continuously test and validate the operating effectiveness of security controls. Conduct formal Gap Assessments against regulatory frameworks and industry standards; produce gap remediation roadmaps with ownership and timelines.

Lead Crisis Management planning establish protocols, communication trees, and executive escalation runbooks. Report BCP/DR posture metrics to senior leadership and integrate findings into the enterprise risk register. Maintain audit-ready documentation, control registers, and evidence repositories at all times.

Engage with external auditors, certification bodies, and regulatory authorities as the primary organizational point of contact. Track and close audit findings, non‑conformities, and corrective action plans (CAPs) within agreed timelines. Operational Resilience & Governance

Recommended Roadmap Items (FY'25‑26)

Develop, publish, and maintain the enterprise Security Policies and Standards library ensuring alignment to regulatory requirements and business context. Define and track Security Metrics and KPIs/KRIs that measure governance program health and control effectiveness. Design and execute a Security Awareness & Training program including role‑based training curricula, completion tracking, and effectiveness measurement. Run a managed Phishing Simulation program configure scenarios, analyse results, and feed outcomes into targeted training interventions. Build and operate a Unified Governance Framework that aligns GRC processes, tools, and stakeholders under a single operating model. Ensure governance processes support regulatory change management tracking emerging laws, regulations, and standards impacting the organization. Continuity Planning & Management BIA execution, RTO/RPO establishment, and plan documentation. DR Tests & Governance scheduled tabletop and full failover DR exercises with formal governance reporting. Assess IS Preparedness IS readiness assessments against BCP/DR scenarios. Tech‑Business Dependency Mapping asset‑to‑process dependency mapping for all critical systems. Crisis Management crisis response protocols, playbooks, and communication frameworks. Security Compliance Certification Lifecycle roadmap to ISO 27001, SOC 2 Type II, and additional certifications. Internal & External Audits structured audit program with clear ownership and scheduling. Control Validation & Gap Assessment continuous control testing and annual framework gap analysis. Policies & Standards full policy library review/refresh cycle. Security Metrics executive dashboard of GRC KPIs and KRIs. Training & Awareness + Phishing Simulations annual awareness calendar with measurable outcomes. Unified Governance Framework integrated GRC operating model across all pillars.

Program Leadership & Governance

Build, mentor, and manage the GRC team analysts, compliance specialists, and resilience practitioners; define career paths and performance goals. Develop and maintain GRC program policies, procedures, playbooks, and runbooks across all pillars (Governance, Compliance, Resilience, Audit). Collaborate with CISO, Legal, Risk, and Executive Leadership to align the GRC program with corporate risk appetite and strategic objectives. Drive quarterly Business Reviews (QBRs) with senior stakeholders and client CISOs on GRC program health, compliance status, and resilience posture. Evaluate, procure, and manage GRC tooling vendors; own the technology roadmap and budget for the GRC tower. Integrate GRC activities with the broader cybersecurity program VM, SOC, AppSec, and IAM to ensure a holistic risk management posture. Act as the domain lead for client‑facing advisory engagements involving GRC program maturity assessment and uplift. Support incident response by providing real‑time regulatory and compliance guidance during security incidents. Establish a continuous improvement cycle for all GRC processes, leveraging audit findings, control testing results, and industry benchmarks. Lead the design and delivery of a Metrics & Reporting framework providing CISO‑ready dashboards and board‑level visualizations of compliance posture and resilience health.

Required Qualifications

8+ years of experience in cybersecurity and/or IT risk, with at least 4 years focused on GRC, compliance management, or operational resilience. Proven experience designing and leading enterprise GRC programs covering governance, compliance, audit, and business continuity / DR. Deep knowledge of security policy and standards frameworks ISO 27001, NIST CSF, NIST SP 800‑53, CIS Controls, and equivalent. Hands‑on experience managing compliance certification lifecycles ISO 27001,ISO 22301,ISO 27701,HITRUST, SOC 2, PCI‑DSS, HIPAA, or DPDP. Strong background in BCP/DR program management BIA, RTO/RPO setting, DR governance, and crisis management. Experience conducting and managing internal and external audit engagements; familiarity with audit evidence collection and finding remediation. Proficiency with GRC platforms such as ServiceNow GRC, Archer, MetricStream, OneTrust, or equivalent. Experience designing and executing security awareness programs including phishing simulations. Excellent communication and stakeholder management skills ability to translate GRC findings into risk narratives for C‑suite and board audiences. Familiarity with regulatory and data protection requirements: GDPR, DPDP Act, RBI guidelines, SEBI CSCRF, or sector‑specific mandates.

Preferred Qualifications

Experience in a consulting or managed security services environment, advising multiple enterprise clients on GRC strategy and maturity uplift. Familiarity with integrated risk management (IRM) methodologies and enterprise risk management (ERM) frameworks. Exposure to OT/ICS compliance and resilience requirements in industrial or critical infrastructure environments. Experience with third‑party and supply chain risk management (TPRM/SCRM) programs. Background in security architecture or technical security assessments to complement governance expertise. Knowledge of AI governance and emerging regulatory requirements related to AI/ML risk management. Experience building and operating a Phishing Simulation program using platforms such as KnowBe4, Proofpoint Security Awareness, or Cofense.

Certifications Required / Strongly Preferred

ISO 27001 Lead Auditor or Lead Implementer
ISO 22301 Lead Auditor or Lead Implementer
CISA Certified Information Systems Auditor
Nice to Have CISSP Certified Information Systems Security Professional
CISM Certified Information Security Manager
CRISC Certified in Risk and Information Systems Control
CCSP Certified Cloud Security Professional


Skills

Compliance, GRC, Risk Management

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security GRC & ISO 27001 Manager
Senior Security GRC & ISO 27001 Manager

UST • Thiruvananthapuram

On-site
INR 1,500,000 - 2,100,000
Governance, Risk & Compliance (GRC) Manager
Governance, Risk & Compliance (GRC) Manager

TeamsWork.In • India

On-site
INR 1,500,000 - 2,100,000
Senior Manager
Senior Manager

Pellera Technologies • India

On-site
INR 2,500,000 - 4,500,000
Product GRC Consultant
Product GRC Consultant

CyRAACS™ • Bengaluru

On-site
INR 600,000 - 1,200,000
Lead Compliance Specialist
Lead Compliance Specialist

TAC Security • Chandigarh

On-site
INR 2,600,000 - 3,200,000
GRC Lead / Security Compliance Lead
GRC Lead / Security Compliance Lead

Gnani Innovations Private Limited. • India

On-site
INR 350,000 - 600,000
Sr Engineer, Governance, Risk & Compliance
Sr Engineer, Governance, Risk & Compliance

NextGen Healthcare India • Bengaluru

On-site
INR 1,600,000 - 2,800,000
Technical Manager
Technical Manager

Incedo Inc. • Gurugram District

On-site
INR 2,500,000 - 5,000,000
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

844 Altera Semiconductor Technology India Pvt. Ltd. • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Senior Manager – Digital, Cyber Security (GRC)
Senior Manager – Digital, Cyber Security (GRC)

Tata Consumer Products • Bengaluru

On-site
INR 1,500,000 - 1,900,000