Talent.com
Senior Role - GRC & Infosec

Senior Role - GRC & Infosec

NPCI Bharat BillPay LimitedMumbai, Maharashtra, India
11 days ago
Job description

Job Description – GRC (Infosec)

Job Summary : The selected candidate will lead the development, implementation, and continuous improvement of the organization's governance, risk management, and compliance frameworks and programs. This role is critical in fostering a strong risk-aware and compliant culture across all departments, ensuring the organization meets its legal, regulatory, and ethical obligations while strategically managing potential threats to its operations and objectives.

Education & Qualification :

B.E. / B.Tech with minimum 13 + years of experience in in Governance, Risk, and Compliance roles, with a significant portion in a leadership capacity.

Professional certifications such as Security+, Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Governance of Enterprise IT (CGEIT), GRC Professional, Certified Chief Information Security Officer (CCISO) or similar are preferred.

Key Responsibilities :

Define the overall GRC strategy, policies, standards, and procedures.

Oversee the identification, assessment, analysis, and prioritization of enterprise-wide risks, including operational, reputational, and cybersecurity risks.

Develop and implement robust risk mitigation strategies and controls

Monitor the effectiveness of risk management activities and report on the organization's risk posture to senior leadership and the Board.

Ensure the organization complies with all applicable laws, regulations, industry standards, and internal policies (e.g., data privacy regulations like DPDPA, RBI regulatory requirements and compliance)

Develop and manage compliance programs, internal audits, and assessments to identify and address compliance gaps.

Drive a strong governance culture by establishing clear accountability, transparency, and ethical conduct throughout the organization

Develop and implement governance policies and procedures to guide decision-making and operational processes

Develop meaningful GRC metrics, dashboards, and reports for various stakeholders, including executive management and the Board.

Collaborate closely with various departments, including Enterprise Risk, IT Operations, Legal, Finance and HR to integrate GRC principles into daily business operations.

Act as a trusted advisor to business on Infosec Risk and Compliance matters.

Thoroughly review of all incoming information security requests (e.g., user access, system configuration changes, firewall rules creation / modifications, software installations, data access, third-party system integrations) and approve them.

Assess requests for completeness, accuracy, and adherence to established information security policies, procedures, & guidelines and analyse potential security risks, impacts associated with each request, including data confidentiality, integrity, and availability.

Review and approve access requests to sensitive systems, applications, and data and validate justifications, roles, and least-privilege principles prior to approval.

Maintain a comprehensive understanding of evolving security threats, vulnerabilities, and regulatory changes related to upcoming technologies like Blockchain and AI to take informed approval decisions.

Review and recommend exceptions to security policies and standards, identify and document any residual risks associated with approved exceptions, and ensure that compensating controls are in place for recommended exceptions, documenting the rationale, validity period, and expiration tracking.

Communicate clearly and concisely with requestors, providing detailed explanations for approvals, denials, or requests for additional information.

Identify opportunities to streamline the request approval process, enhance efficiency, and improve security controls.

Evaluate security architectures and designs to determine the adequacy of security design and architecture proposed or provided in response to requirements

Provide guidance and mentorship to junior security team members.

Technical Skills :

  • Deep understanding of GRC principles, methodologies, and best practices.
  • Strong analytical and problem-solving skills with the ability to identify, assess, and mitigate complex risks.
  • Excellent communication, interpersonal, and presentation skills, with the ability to articulate complex GRC concepts to diverse audiences (technical and non-technical, all levels of management).
  • Proven leadership and team management abilities, including the ability to influence and collaborate across departments.
  • Strategic thinking with a proactive approach to GRC challenges.
  • High level of integrity and ethical conduct.
  • Ability to manage multiple projects and priorities in a dynamic environment.
  • Proven track record of developing, implementing, and managing successful GRC programs in a complex organizational environment.
  • Strong experience with risk assessment methodologies, control frameworks, and compliance audits.
  • Experience with relevant regulatory frameworks (e.g., ISO 27001, NIST, SOC 2, PCI DSS, DPDPA, GDPR etc.).
  • Strong understanding of security domains (e.g., network security, data security, application security).
  • Understanding on cryptographic standards, application security, enterprise architecture, software development lifecycle etc.
  • Experience with security frameworks (e.g., MITRE, NIST, ISO).
  • Familiar in Vulnerability Management and Configuration Management with a commitment to staying current on emerging security threats and technological advancements.
  • Knowledge of identity and access management (IAM) concepts and technologies and Familiarity with role-based access control (RBAC) models and approval workflows.
  • Knowledge of cryptography, secure communication protocols, data encryption techniques, understanding of Key management process.
  • Deep understanding of security vulnerabilities exploits applications, infrastructure and APIs
  • Strong analytical and problem-solving skills.
  • Basic understanding of cloud security principles (AWS, Azure, GCP) is a plus.
  • Experience with ITSM or request / ticketing systems (e.g., ServiceNow, Jira, Remedy).
Create a job alert for this search

Senior • Mumbai, Maharashtra, India

Related jobs
  • Promoted
GRC-SAP Controls ITAC Senior

GRC-SAP Controls ITAC Senior

FP&AMumbai, Maharashtra, India
At EY youll have the chance to build a career as unique as you are with the global scale support inclusive culture and technology to become the best version of you. And were counting on your unique ...Show moreLast updated: 30+ days ago
  • Promoted
Senior Consultant

Senior Consultant

ProgliteMumbai, IN
We are seeking a motivated and skilled.Network / Cloud / Security Engineer.AWS, Google Cloud Platform (GCP), Cisco Meraki, and Palo Alto firewalls. The ideal candidate will be responsible for design...Show moreLast updated: 30+ days ago
  • Promoted
Senior Director Legal

Senior Director Legal

EveriseKalyan-Dombivli, IN
Senior Director – Legal (India).The Senior Director – Legal (India) will serve as the legal and compliance leader for Everise’s India operations, responsible for overseeing all legal, compliance, a...Show moreLast updated: 16 days ago
  • Promoted
Global Lead Statistical Programmer

Global Lead Statistical Programmer

SUN PHARMAKalyan-Dombivli, IN
Location : Hybrid at Gurugram / Mumbai.Remote for the right candidate.Lead one or more Phase I-IV studies programming activities as per the project strategies. Work independently implementing and execu...Show moreLast updated: 1 day ago
  • Promoted
Manager Infosec GRC

Manager Infosec GRC

ConfidentialMumbai, India
Department : Information Security.This role is responsible for driving the organization's Information Security Governance, Risk, and Compliance (GRC) function, Industry standards (ISO 27001, NIST CS...Show moreLast updated: 12 days ago
  • Promoted
GRC Analyst - Information Security

GRC Analyst - Information Security

PINKVILLAMumbai, Maharashtra, India
Pinkvilla is seeking a dynamic Information Security professional, who will play a key role in driving compliance programs, managing audits, supporting data protection initiatives, and ensuring thir...Show moreLast updated: 30+ days ago
  • Promoted
Senior Manager

Senior Manager

Lactalis IndiaThane, IN
Description : Manager – Accounts Payable & Accounts Receivable (Shared Services).Department : Finance Shared Services.Reports To : Head – Finance & Accounts. Location : Lactalis India, Chennai.To lead a...Show moreLast updated: 12 days ago
  • Promoted
Head of Token Strategy & Growth-Blockchain

Head of Token Strategy & Growth-Blockchain

Brainwave ScienceKalyan-Dombivli, IN
Head of Token Strategy & Growth .Using EEG and AI-driven analytics, our platform delivers measurable insights into stress, focus, anxiety, and relaxation—empowering individuals and organizations to...Show moreLast updated: 4 days ago
  • Promoted
Sales Specialist – Cybersecurity & GRC

Sales Specialist – Cybersecurity & GRC

CloudHireKalyan-Dombivli, IN
We are seeking a motivated, organized, and creative Sales Specialist passionate about selling Cybersecurity and GRC consulting services. The role involves building strong customer relationships, ide...Show moreLast updated: 1 day ago
  • Promoted
Senior Crypto Trader

Senior Crypto Trader

AAA GlobalThane, IN
We’re building a lean, high-performance trading desk and are seeking a.Run your own crypto trading strategy from day one. Full ownership from idea to execution, including risk and performance tracki...Show moreLast updated: 30+ days ago
  • Promoted
Senior Investment Professional

Senior Investment Professional

SLKKalyan-Dombivli, IN
Job Description – Senior Investment Professional.Senior Investment Professional.Remote work based in India (Full-Time).SLK is a specialist climate change and healthcare advisory firm dedicated to a...Show moreLast updated: 30+ days ago
  • Promoted
Senior Consultant

Senior Consultant

ValorantThane, IN
Valorant is a fast-growing consulting firm at the intersection of procurement and AI.We help global clients — across private equity, technology, life sciences, financial services, industrials, and ...Show moreLast updated: 30+ days ago
  • Promoted
Senior Compliance Manager

Senior Compliance Manager

KuCoin ExchangeThane, IN
Maintain registration and license in India.Provide compliance support to all business units of the company in India.Manage KYC and AML matters, to implement controls over KYC and AML in order to co...Show moreLast updated: 11 days ago
  • Promoted
GRC Manager / GRC Lead

GRC Manager / GRC Lead

ConfidentialMumbai
GRC, Information Security, or Compliance roles, preferably in a FinTech or financial services environment.Strong knowledge of PCI DSS, ISO 27001, SOC 2, GDPR, RBI guidelines, and other financial re...Show moreLast updated: 30+ days ago
  • Promoted
  • New!
Appsec-GRC-Senior- E

Appsec-GRC-Senior- E

EY Studio+ NederlandMumbai, Maharashtra, India
At EY youll have the chance to build a career as unique as you are with the global scale support inclusive culture and technology to become the best version of you. And were counting on your unique ...Show moreLast updated: 8 hours ago
  • Promoted
SAP-GRC-Senior E

SAP-GRC-Senior E

EY Studio+ NederlandMumbai, Maharashtra, India
At EY youll have the chance to build a career as unique as you are with the global scale support inclusive culture and technology to become the best version of you. And were counting on your unique ...Show moreLast updated: 1 day ago
  • Promoted
  • New!
SAP IDM & GRC Consultant

SAP IDM & GRC Consultant

Tata Consultancy ServicesMumbai Metropolitan Region, India
SAP GRC Implementation : Design, configure, and implement SAP GRC modules like Access Control, Process Control, and Risk Management. SAP IDM Implementation : Automate user provisioning and de-provisio...Show moreLast updated: 14 hours ago
  • Promoted
Senior Technical Recruiter – Engineering & Non-IT

Senior Technical Recruiter – Engineering & Non-IT

ITCO Solutions, Inc.Kalyan-Dombivli, IN
US Senior Technical Recruiter – Engineering & Non-IT.Long Term (Years) Contract / Commission / Spread.We are currently seeking experienced Recruiting Professionals with expertise in.Engineering and...Show moreLast updated: 30+ days ago