Talent.com
Governance, Risk & Compliance Manager
Governance, Risk & Compliance ManagerNPCI Bharat BillPay Limited • Republic Of India, IN
Governance, Risk & Compliance Manager

Governance, Risk & Compliance Manager

NPCI Bharat BillPay Limited • Republic Of India, IN
15 days ago
Job description

Job Description – GRC (Infosec)

Job Summary : The selected candidate will lead the development, implementation, and continuous improvement of the organization's governance, risk management, and compliance frameworks and programs. This role is critical in fostering a strong risk-aware and compliant culture across all departments, ensuring the organization meets its legal, regulatory, and ethical obligations while strategically managing potential threats to its operations and objectives.

Education & Qualification :

B.E. / B.Tech with minimum 13 + years of experience in in Governance, Risk, and Compliance roles, with a significant portion in a leadership capacity.

Professional certifications such as Security+, Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Governance of Enterprise IT (CGEIT), GRC Professional, Certified Chief Information Security Officer (CCISO) or similar are preferred.

Key Responsibilities :

Define the overall GRC strategy, policies, standards, and procedures.

Oversee the identification, assessment, analysis, and prioritization of enterprise-wide risks, including operational, reputational, and cybersecurity risks.

Develop and implement robust risk mitigation strategies and controls

Monitor the effectiveness of risk management activities and report on the organization's risk posture to senior leadership and the Board.

Ensure the organization complies with all applicable laws, regulations, industry standards, and internal policies (e.G., data privacy regulations like DPDPA, RBI regulatory requirements and compliance)

Develop and manage compliance programs, internal audits, and assessments to identify and address compliance gaps.

Drive a strong governance culture by establishing clear accountability, transparency, and ethical conduct throughout the organization

Develop and implement governance policies and procedures to guide decision-making and operational processes

Develop meaningful GRC metrics, dashboards, and reports for various stakeholders, including executive management and the Board.

Collaborate closely with various departments, including Enterprise Risk, IT Operations, Legal, Finance and HR to integrate GRC principles into daily business operations.

Act as a trusted advisor to business on Infosec Risk and Compliance matters.

Thoroughly review of all incoming information security requests (e.G., user access, system configuration changes, firewall rules creation / modifications, software installations, data access, third-party system integrations) and approve them.

Assess requests for completeness, accuracy, and adherence to established information security policies, procedures, & guidelines and analyse potential security risks, impacts associated with each request, including data confidentiality, integrity, and availability.

Review and approve access requests to sensitive systems, applications, and data and validate justifications, roles, and least-privilege principles prior to approval.

Maintain a comprehensive understanding of evolving security threats, vulnerabilities, and regulatory changes related to upcoming technologies like Blockchain and AI to take informed approval decisions.

Review and recommend exceptions to security policies and standards, identify and document any residual risks associated with approved exceptions, and ensure that compensating controls are in place for recommended exceptions, documenting the rationale, validity period, and expiration tracking.

Communicate clearly and concisely with requestors, providing detailed explanations for approvals, denials, or requests for additional information.

Identify opportunities to streamline the request approval process, enhance efficiency, and improve security controls.

Evaluate security architectures and designs to determine the adequacy of security design and architecture proposed or provided in response to requirements

Provide guidance and mentorship to junior security team members.

Technical Skills :

  • Deep understanding of GRC principles, methodologies, and best practices.
  • Strong analytical and problem-solving skills with the ability to identify, assess, and mitigate complex risks.
  • Excellent communication, interpersonal, and presentation skills, with the ability to articulate complex GRC concepts to diverse audiences (technical and non-technical, all levels of management).
  • Proven leadership and team management abilities, including the ability to influence and collaborate across departments.
  • Strategic thinking with a proactive approach to GRC challenges.
  • High level of integrity and ethical conduct.
  • Ability to manage multiple projects and priorities in a dynamic environment.
  • Proven track record of developing, implementing, and managing successful GRC programs in a complex organizational environment.
  • Strong experience with risk assessment methodologies, control frameworks, and compliance audits.
  • Experience with relevant regulatory frameworks (e.G., ISO 27001, NIST, SOC 2, PCI DSS, DPDPA, GDPR etc.).
  • Strong understanding of security domains (e.G., network security, data security, application security).
  • Understanding on cryptographic standards, application security, enterprise architecture, software development lifecycle etc.
  • Experience with security frameworks (e.G., MITRE, NIST, ISO).
  • Familiar in Vulnerability Management and Configuration Management with a commitment to staying current on emerging security threats and technological advancements.
  • Knowledge of identity and access management (IAM) concepts and technologies and Familiarity with role-based access control (RBAC) models and approval workflows.
  • Knowledge of cryptography, secure communication protocols, data encryption techniques, understanding of Key management process.
  • Deep understanding of security vulnerabilities exploits applications, infrastructure and APIs
  • Strong analytical and problem-solving skills.
  • Basic understanding of cloud security principles (AWS, Azure, GCP) is a plus.
  • Experience with ITSM or request / ticketing systems (e.G., ServiceNow, Jira, Remedy).
Create a job alert for this search

Compliance Manager • Republic Of India, IN

Related jobs
Governance, Risk, and Compliance Advisor

Governance, Risk, and Compliance Advisor

Solytics Partners • Pune, Republic Of India, IN
Solytics Partners is a Global Analytics firm, recognized with multiple industry awards for innovation and excellence.Our team comprises experts with deep knowledge in risk, analytics, AI / ML, AML / FC...Show more
Last updated: 22 days ago • Promoted
Compliance Risk Manager

Compliance Risk Manager

Glenmark Pharmaceuticals • Republic Of India, IN
DESIRED EXPERIENCE AND KNOWLEDGE.Designation : Manager Compliance.Business Unit : Corporate Functions.The Manager Corporate Ethics and Compliance will be the pivotal to creation and monitoring of com...Show more
Last updated: 7 days ago • Promoted
Governance and Compliance Specialist

Governance and Compliance Specialist

V-Guard • Cochin, Republic Of India, IN
Conduct follow-up audit to ensure implementation of controls suggested by co-sourced auditors.Conducts risk assessments and identifies controls in place to mitigate identified risks.To Coordinate w...Show more
Last updated: 30+ days ago • Promoted
Governance, Risk & Compliance Manager

Governance, Risk & Compliance Manager

KPMG India • Republic Of India, IN
KPMG is a global network of professional firms providing Audit, Tax and Advisory services.We operate in 156 countries and have 152,000 people working in member firms around the world.KPMG in India,...Show more
Last updated: 30+ days ago • Promoted
Governance, Risk, and Compliance (GRC) Specialist

Governance, Risk, and Compliance (GRC) Specialist

SQ1 Security • Chennai, Republic Of India, IN
SQ1 Security is seeking an experienced Cybersecurity and Compliance Expert to lead and drive our initiatives toward achieving SOC 2, ISO 27001, GDPR, and HITRUST certifications.Develop and Maintain...Show more
Last updated: 23 hours ago • Promoted
Senior Manager, Cybersecurity Risk and Governance

Senior Manager, Cybersecurity Risk and Governance

Career Stone Consultant • Republic Of India, IN
The job purpose is to lead and implement comprehensive cybersecurity and information security.Responsible for data privacy protection, infrastructure security, vendor management, and fostering a.Se...Show more
Last updated: 15 days ago • Promoted
Risk & Compliance Leader

Risk & Compliance Leader

NPCI BHIM • Republic Of India, IN
Preferred Educational Qualification : .Enterprise Risk Management (ERM), Operational Risk Management (ORM), incident governance, compliance and / or audit. Candidate should have worked extensively on ma...Show more
Last updated: 15 days ago • Promoted
Governance, Risk, and Compliance (GRC) Manager

Governance, Risk, and Compliance (GRC) Manager

Digile • India
We are seeking a highly experienced.Governance, Risk, and Compliance (GRC) Manager.The ideal candidate will have deep expertise in. HITRUST CSF, ISO 27001 : 2022, SOC 2 Type II, NIST 800-53.Financial ...Show more
Last updated: 2 days ago • Promoted
Governance, Risk, and Compliance Manager

Governance, Risk, and Compliance Manager

The Glove • Republic Of India, IN
Manager Internal Audit (Non FS).Location- Bangalore, Gurgaon, Mumbai.Exciting Career Opportunity in Risk Consulting.Manager_Advisory_IA_GRC_Risk Consulting _Mumbai. Lead planning activities related ...Show more
Last updated: 12 days ago • Promoted
Governance, Risk, and Compliance Lead

Governance, Risk, and Compliance Lead

ShieldByte Infosec Pvt. Ltd. • Republic Of India, IN
Cybersecurity, IT Security, IT Audit.We are seeking Governance, Risk, and Compliance (GRC) professionals to join our team as GRC Executive / GRC Manager. The role involves risk assessment, regulator...Show more
Last updated: 2 days ago • Promoted
Compliance and Governance Specialist

Compliance and Governance Specialist

BDO India • Republic Of India, IN
Core Roles & Responsibilities : .Independently executing assignments or monitoring the assignments (Typical assignments comprise of conducting reviews of systems, internal controls -Internal financia...Show more
Last updated: 4 days ago • Promoted
Compliance and Risk Manager

Compliance and Risk Manager

Acme Services • Republic Of India, IN
Years of Experience : 10+ Years.Design, document, and implement standardized processes for datacenter operations, including incident management, change management, and operational workflows.Identify...Show more
Last updated: 15 days ago • Promoted
Retail Compliance and Governance Lead

Retail Compliance and Governance Lead

Piramal Finance • Republic Of India, IN
Regulatory Advisory : Incumbent will be responsible for providing regulatory clarifications to internal stakeholders and ensuring adherence to all regulatory requirements of the RBI and internal pol...Show more
Last updated: 9 days ago • Promoted
Manager - Governance, Risks and controls

Manager - Governance, Risks and controls

DIAGEO India • India
Role - : Manager - Governance, Risks and controls.Financial Governance & Risk Management.Drive compliant, efficient, and effective management of financial assets and resources in alignment with busi...Show more
Last updated: 2 days ago • Promoted
TPRM Governance & Compliance Senior Manager - Qatar

TPRM Governance & Compliance Senior Manager - Qatar

Cubical Operations LLP • Republic Of India, IN
Job Description – TPRM Senior Manager (Qatar Travel Requirement).Senior Manager – Third-Party Risk Management (TPRM).Qatar (Frequent travel to / from India). India (Work from India when not travelling...Show more
Last updated: 6 days ago • Promoted
Compliance Manager

Compliance Manager

Backbase • India
As an IT Governance, Risk and Compliance (GRC) Manager, you enable Backbase in conducting its business in full compliance with all relevant national and international laws and regulations.This also...Show more
Last updated: 2 days ago • Promoted
Senior Manager -Risk & Compliance

Senior Manager -Risk & Compliance

Flipkart • India
Stakeholder Management, Business Excellence, Risk Management.A Bachelor's degree in Business Administration, Finance, Information Technology, or a related field is required.We are seeking a highly ...Show more
Last updated: 2 days ago • Promoted
Governance & Compliance Lead

Governance & Compliance Lead

Fast&Up India • Republic Of India, IN
Nutrition, Pharma, FMCG, or D2C sectors.Provide legal support across business functions, including drafting and vetting agreements pertaining to manufacturing, supply, advertising, service provider...Show more
Last updated: 30+ days ago • Promoted