Talent.com
Senior Role - GRC & Infosec
Senior Role - GRC & InfosecNPCI Bharat BillPay Limited • Delhi, India
Senior Role - GRC & Infosec

Senior Role - GRC & Infosec

NPCI Bharat BillPay Limited • Delhi, India
14 days ago
Job description

Job Description – GRC (Infosec)

Job Summary : The selected candidate will lead the development, implementation, and continuous improvement of the organization's governance, risk management, and compliance frameworks and programs. This role is critical in fostering a strong risk-aware and compliant culture across all departments, ensuring the organization meets its legal, regulatory, and ethical obligations while strategically managing potential threats to its operations and objectives.

Education & Qualification :

B.E. / B.Tech with minimum 13 + years of experience in in Governance, Risk, and Compliance roles, with a significant portion in a leadership capacity.

Professional certifications such as Security+, Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Governance of Enterprise IT (CGEIT), GRC Professional, Certified Chief Information Security Officer (CCISO) or similar are preferred.

Key Responsibilities :

Define the overall GRC strategy, policies, standards, and procedures.

Oversee the identification, assessment, analysis, and prioritization of enterprise-wide risks, including operational, reputational, and cybersecurity risks.

Develop and implement robust risk mitigation strategies and controls

Monitor the effectiveness of risk management activities and report on the organization's risk posture to senior leadership and the Board.

Ensure the organization complies with all applicable laws, regulations, industry standards, and internal policies (e.g., data privacy regulations like DPDPA, RBI regulatory requirements and compliance)

Develop and manage compliance programs, internal audits, and assessments to identify and address compliance gaps.

Drive a strong governance culture by establishing clear accountability, transparency, and ethical conduct throughout the organization

Develop and implement governance policies and procedures to guide decision-making and operational processes

Develop meaningful GRC metrics, dashboards, and reports for various stakeholders, including executive management and the Board.

Collaborate closely with various departments, including Enterprise Risk, IT Operations, Legal, Finance and HR to integrate GRC principles into daily business operations.

Act as a trusted advisor to business on Infosec Risk and Compliance matters.

Thoroughly review of all incoming information security requests (e.g., user access, system configuration changes, firewall rules creation / modifications, software installations, data access, third-party system integrations) and approve them.

Assess requests for completeness, accuracy, and adherence to established information security policies, procedures, & guidelines and analyse potential security risks, impacts associated with each request, including data confidentiality, integrity, and availability.

Review and approve access requests to sensitive systems, applications, and data and validate justifications, roles, and least-privilege principles prior to approval.

Maintain a comprehensive understanding of evolving security threats, vulnerabilities, and regulatory changes related to upcoming technologies like Blockchain and AI to take informed approval decisions.

Review and recommend exceptions to security policies and standards, identify and document any residual risks associated with approved exceptions, and ensure that compensating controls are in place for recommended exceptions, documenting the rationale, validity period, and expiration tracking.

Communicate clearly and concisely with requestors, providing detailed explanations for approvals, denials, or requests for additional information.

Identify opportunities to streamline the request approval process, enhance efficiency, and improve security controls.

Evaluate security architectures and designs to determine the adequacy of security design and architecture proposed or provided in response to requirements

Provide guidance and mentorship to junior security team members.

Technical Skills :

Deep understanding of GRC principles, methodologies, and best practices.

Strong analytical and problem-solving skills with the ability to identify, assess, and mitigate complex risks.

Excellent communication, interpersonal, and presentation skills, with the ability to articulate complex GRC concepts to diverse audiences (technical and non-technical, all levels of management).

Proven leadership and team management abilities, including the ability to influence and collaborate across departments.

Strategic thinking with a proactive approach to GRC challenges.

High level of integrity and ethical conduct.

Ability to manage multiple projects and priorities in a dynamic environment.

Proven track record of developing, implementing, and managing successful GRC programs in a complex organizational environment.

Strong experience with risk assessment methodologies, control frameworks, and compliance audits.

Experience with relevant regulatory frameworks (e.g., ISO 27001, NIST, SOC 2, PCI DSS, DPDPA, GDPR etc.).

Strong understanding of security domains (e.g., network security, data security, application security).

Understanding on cryptographic standards, application security, enterprise architecture, software development lifecycle etc.

Experience with security frameworks (e.g., MITRE, NIST, ISO).

Familiar in Vulnerability Management and Configuration Management with a commitment to staying current on emerging security threats and technological advancements.

Knowledge of identity and access management (IAM) concepts and technologies and Familiarity with role-based access control (RBAC) models and approval workflows.

Knowledge of cryptography, secure communication protocols, data encryption techniques, understanding of Key management process.

Deep understanding of security vulnerabilities exploits applications, infrastructure and APIs

Strong analytical and problem-solving skills.

Basic understanding of cloud security principles (AWS, Azure, GCP) is a plus.

Experience with ITSM or request / ticketing systems (e.g., ServiceNow, Jira, Remedy).

Create a job alert for this search

Senior • Delhi, India

Related jobs
Senior Associate-BAS Forensics-Gurgaon

Senior Associate-BAS Forensics-Gurgaon

BDO India • Delhi, India
BDO India Services Private Limited is the India member firm of BDO International.BDO India offers strategic, operational, accounting, tax & regulatory advisory and assistance for both domestic and ...Show more
Last updated: 3 days ago • Promoted
Manager-RAS-Gurgaon

Manager-RAS-Gurgaon

BDO India • Delhi, India
BDO India Services Private Limited is the India member firm of BDO International.BDO India offers strategic, operational, accounting, tax & regulatory advisory and assistance for both domestic and ...Show more
Last updated: 3 days ago • Promoted
Senior Analyst

Senior Analyst

Everest Group • Delhi, India
Job Title : Senior Analyst Location City : Gurgaon (New Delhi National Capital Region) Industry : Research and Advisory Services Company : Everest Group. Confident decisions driven by deep expertise...Show more
Last updated: 12 days ago • Promoted
Senior Associate - Due Diligence - Gurgaon / Bangalore - 2+ years of experience

Senior Associate - Due Diligence - Gurgaon / Bangalore - 2+ years of experience

BDO India • Delhi, India
Core Due Diligence role & responsibilities : .Assisting organisations with both buy side and sell side due diligence.Developing an understanding of the business, competitive positioning, strengths, ...Show more
Last updated: 3 days ago • Promoted
Manager - Due Diligence - Gurgaon - 5+ years of experience

Manager - Due Diligence - Gurgaon - 5+ years of experience

BDO India • Delhi, India
We at BDO India, we carry out a procedure review based on verification of records and meetings conducted with key persons, along with an extensive analysis of data and information.We not only verif...Show more
Last updated: 3 days ago • Promoted
AVP F&A Gurgaon

AVP F&A Gurgaon

Genpact • Delhi, India, India
At Genpact, we don’t just adapt to change—we drive it.AI and digital innovation are redefining industries, and we’re leading the charge. Genpact’s AI Gigafactory, our industryfirst accelerator, is a...Show more
Last updated: 22 days ago • Promoted
GRC Analyst

GRC Analyst

J.B. Poindexter & Co • Delhi, India
Job Title : Analyst, Governance, Risk and Compliance.As the GRC Analyst, you will play a critical role in developing and implementing comprehensive governance, risk, and compliance strategies, polic...Show more
Last updated: 21 days ago • Promoted
Associate-BAS Cyber-ISMS-Gurgaon

Associate-BAS Cyber-ISMS-Gurgaon

BDO India • Delhi, India
About Company BDO is a global network of professional services firms with a presence in over 166 countries, revenue of over USD 14 billion, and experience of over 60 years.It’s a leading service pr...Show more
Last updated: 3 days ago • Promoted
Analyst - GRC (Governance, Risk & Compliance)

Analyst - GRC (Governance, Risk & Compliance)

Amagi • Delhi, India
This role has been established to support the business in building sustainable governance andcompliance practices at Amagi. The basic factor required to be successful in this role warrants a good un...Show more
Last updated: 30+ days ago • Promoted
GRC Consultant

GRC Consultant

Solytics Partners • Delhi, India
Company Profile : Solytics Partners is a Global Analytics firm, recognized with multiple industry awards for innovation and excellence. Our team comprises experts with deep knowledge in risk, analyti...Show more
Last updated: 21 days ago • Promoted
SAP IDM and GRC Consultant

SAP IDM and GRC Consultant

Tata Consultancy Services • Delhi, India
Experience : 7 years to 11years.Interview Date : 27th Nov 2025 (Thursday).Interview Time : 10 : 00 AM to 4 : 00 PM.SAP GRC Implementation : Design, configure, and implement SAP GRC modules like Access Co...Show more
Last updated: 8 days ago • Promoted
Senior GRC Analyst

Senior GRC Analyst

Dezerv • Delhi, India
Dezerv is a house of investing solutions for high-net-worth and affluent Indians.Dezerv is co-founded by Sandeep Jethwani, Vaibhav Porwal, and Sahil Contractor. They have led successful wealth manag...Show more
Last updated: 30+ days ago • Promoted
GRC Executive / GRC Manager

GRC Executive / GRC Manager

ShieldByte Infosec Pvt. Ltd. • Delhi, India
Cybersecurity, IT Security, IT Audit Employment Type : .Role Overview : We are seeking Governance, Risk, and Compliance (GRC) professionals to join our team as GRC Executive / GRC Manager.The role inv...Show more
Last updated: 2 days ago • Promoted
Manager - SAP GRC Process Control - Delhi

Manager - SAP GRC Process Control - Delhi

Deloitte • new delhi, delhi, in
SAP GRC PC Professional should have : .As a GRC PC Manager in our Risk Advisory team, you’ll build and nurture positive working relationships with teams and clients with the intention to exceed clien...Show more
Last updated: 22 days ago • Promoted
Senior Assistant-RAS-Gurgaon / Chennai / Mumbai

Senior Assistant-RAS-Gurgaon / Chennai / Mumbai

BDO India • Delhi, India
BDO India Services Private Limited is the India member firm of BDO International.BDO India offers strategic, operational, accounting, tax & regulatory advisory and assistance for both domestic and ...Show more
Last updated: 3 days ago • Promoted
GRC Analyst - Information Security

GRC Analyst - Information Security

PINKVILLA • Delhi, India
Pinkvilla is seeking a dynamic Information Security professional, who will play a key role in driving compliance programs, managing audits, supporting data protection initiatives, and ensuring thir...Show more
Last updated: 5 days ago • Promoted
Senior Executive – HR (BGV & Compliance)

Senior Executive – HR (BGV & Compliance)

Coforge • Noida, Uttar Pradesh, India
Senior Executive – HR (BGV & Compliance).We are looking for a detail-oriented and proactive.This role is crucial in ensuring compliance with client-specific policies, local labor laws, and internal...Show more
Last updated: 15 days ago • Promoted
Sales Specialist – Cybersecurity & GRC

Sales Specialist – Cybersecurity & GRC

CloudHire • new delhi, delhi, in
We are seeking a motivated, organized, and creative Sales Specialist passionate about selling Cybersecurity and GRC consulting services. The role involves building strong customer relationships, ide...Show more
Last updated: 5 days ago • Promoted