Talent.com
GRC & Infosec Lead

GRC & Infosec Lead

NPCI Bharat BillPay LimitedRepublic Of India, IN
8 days ago
Job description

Job Description – GRC (Infosec)

Job Summary : The selected candidate will lead the development, implementation, and continuous improvement of the organization's governance, risk management, and compliance frameworks and programs. This role is critical in fostering a strong risk-aware and compliant culture across all departments, ensuring the organization meets its legal, regulatory, and ethical obligations while strategically managing potential threats to its operations and objectives.

Education & Qualification :

B.E. / B.Tech with minimum 13 + years of experience in in Governance, Risk, and Compliance roles, with a significant portion in a leadership capacity.

Professional certifications such as Security+, Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Governance of Enterprise IT (CGEIT), GRC Professional, Certified Chief Information Security Officer (CCISO) or similar are preferred.

Key Responsibilities :

Define the overall GRC strategy, policies, standards, and procedures.

Oversee the identification, assessment, analysis, and prioritization of enterprise-wide risks, including operational, reputational, and cybersecurity risks.

Develop and implement robust risk mitigation strategies and controls

Monitor the effectiveness of risk management activities and report on the organization's risk posture to senior leadership and the Board.

Ensure the organization complies with all applicable laws, regulations, industry standards, and internal policies (e.G., data privacy regulations like DPDPA, RBI regulatory requirements and compliance)

Develop and manage compliance programs, internal audits, and assessments to identify and address compliance gaps.

Drive a strong governance culture by establishing clear accountability, transparency, and ethical conduct throughout the organization

Develop and implement governance policies and procedures to guide decision-making and operational processes

Develop meaningful GRC metrics, dashboards, and reports for various stakeholders, including executive management and the Board.

Collaborate closely with various departments, including Enterprise Risk, IT Operations, Legal, Finance and HR to integrate GRC principles into daily business operations.

Act as a trusted advisor to business on Infosec Risk and Compliance matters.

Thoroughly review of all incoming information security requests (e.G., user access, system configuration changes, firewall rules creation / modifications, software installations, data access, third-party system integrations) and approve them.

Assess requests for completeness, accuracy, and adherence to established information security policies, procedures, & guidelines and analyse potential security risks, impacts associated with each request, including data confidentiality, integrity, and availability.

Review and approve access requests to sensitive systems, applications, and data and validate justifications, roles, and least-privilege principles prior to approval.

Maintain a comprehensive understanding of evolving security threats, vulnerabilities, and regulatory changes related to upcoming technologies like Blockchain and AI to take informed approval decisions.

Review and recommend exceptions to security policies and standards, identify and document any residual risks associated with approved exceptions, and ensure that compensating controls are in place for recommended exceptions, documenting the rationale, validity period, and expiration tracking.

Communicate clearly and concisely with requestors, providing detailed explanations for approvals, denials, or requests for additional information.

Identify opportunities to streamline the request approval process, enhance efficiency, and improve security controls.

Evaluate security architectures and designs to determine the adequacy of security design and architecture proposed or provided in response to requirements

Provide guidance and mentorship to junior security team members.

Technical Skills :

  • Deep understanding of GRC principles, methodologies, and best practices.
  • Strong analytical and problem-solving skills with the ability to identify, assess, and mitigate complex risks.
  • Excellent communication, interpersonal, and presentation skills, with the ability to articulate complex GRC concepts to diverse audiences (technical and non-technical, all levels of management).
  • Proven leadership and team management abilities, including the ability to influence and collaborate across departments.
  • Strategic thinking with a proactive approach to GRC challenges.
  • High level of integrity and ethical conduct.
  • Ability to manage multiple projects and priorities in a dynamic environment.
  • Proven track record of developing, implementing, and managing successful GRC programs in a complex organizational environment.
  • Strong experience with risk assessment methodologies, control frameworks, and compliance audits.
  • Experience with relevant regulatory frameworks (e.G., ISO 27001, NIST, SOC 2, PCI DSS, DPDPA, GDPR etc.).
  • Strong understanding of security domains (e.G., network security, data security, application security).
  • Understanding on cryptographic standards, application security, enterprise architecture, software development lifecycle etc.
  • Experience with security frameworks (e.G., MITRE, NIST, ISO).
  • Familiar in Vulnerability Management and Configuration Management with a commitment to staying current on emerging security threats and technological advancements.
  • Knowledge of identity and access management (IAM) concepts and technologies and Familiarity with role-based access control (RBAC) models and approval workflows.
  • Knowledge of cryptography, secure communication protocols, data encryption techniques, understanding of Key management process.
  • Deep understanding of security vulnerabilities exploits applications, infrastructure and APIs
  • Strong analytical and problem-solving skills.
  • Basic understanding of cloud security principles (AWS, Azure, GCP) is a plus.
  • Experience with ITSM or request / ticketing systems (e.G., ServiceNow, Jira, Remedy).
Create a job alert for this search

Lead • Republic Of India, IN

Related jobs
  • Promoted
GCP Platform Engineer

GCP Platform Engineer

PamTen IncNagpur, IN
The IT Cloud Platform Services teams is a dynamic mix of tech enthusiasts, problem solvers, and creative thinkers, united by our passion for leveraging cutting-edge technology to transform healthca...Show moreLast updated: 30+ days ago
  • Promoted
  • New!
Cybersecurity Director

Cybersecurity Director

Vriba SolutionsNagpur, IN
The Cybersecurity Director is responsible for the strategic vision and scaling of the cybersecurity practice to serve external clients. This leader will ensure robust security governance, risk manag...Show moreLast updated: 8 hours ago
  • Promoted
SAP GRC Security Lead Consultant - Australia (Onsite)

SAP GRC Security Lead Consultant - Australia (Onsite)

Avensys ConsultingNagpur, IN
Avensys is a reputed global IT professional services company headquartered in Singapore.Our service spectrum includes enterprise solution consulting, business intelligence, business process automat...Show moreLast updated: 13 days ago
  • Promoted
Head of Token Strategy & Growth-Blockchain

Head of Token Strategy & Growth-Blockchain

Brainwave ScienceNagpur, IN
Head of Token Strategy & Growth .Using EEG and AI-driven analytics, our platform delivers measurable insights into stress, focus, anxiety, and relaxation—empowering individuals and organizations to...Show moreLast updated: 1 day ago
  • Promoted
Cyble - GRC Lead - Information Security

Cyble - GRC Lead - Information Security

Cyble, India
About Cyble : - Cyble is revolutionizing the landscape of cybersecurity intelligence.Founded in 2019, Cyble began as a visionary college project and has quickly transformed into...Show moreLast updated: 28 days ago
  • Promoted
Senior GRC Analyst

Senior GRC Analyst

ConfidentialIndia
Demandbase is the Smarter GTM™ company for B2B brands.We help marketing and sales teams overcome the disruptive data and technology fragmentation that inhibits insight and forces them to spam their...Show moreLast updated: 9 days ago
  • Promoted
Cyble - GRC Lead

Cyble - GRC Lead

CybleIndia
Description : About Cyble : Cyble is revolutionizing the landscape of cybersecurity intell...Show moreLast updated: 20 days ago
  • Promoted
GRC Analyst

GRC Analyst

ConfidentialIndia
Demandbase is seeking a motivated and detail-oriented GRC Sr Analyst to support its global Governance, Risk, and Compliance program. Reporting to the Senior Director of GRC, you'll collaborate cross...Show moreLast updated: 19 days ago
  • Promoted
IT GRC Lead

IT GRC Lead

ENGIE IndiaPune, Republic Of India, IN
Deputy Manager - IT GRC (Governance, Risk, and Compliance) role.ENGIE India is crucial in ensuring the organization's Digital & IT landscape is secure, compliant, and aligned with business objectiv...Show moreLast updated: 4 days ago
  • Promoted
Technology Lead

Technology Lead

WPPNagpur, IN
WPP OPEN is WPP's proprietary, AI-powered operating system designed to connect our people, data, and technology to deliver integrated, creative, and effective solutions for our clients.It is a stra...Show moreLast updated: 30+ days ago
  • Promoted
Grc Analyst

Grc Analyst

J.B. Poindexter & CoRepublic Of India, IN
Analyst, Governance, Risk and Compliance.As the GRC Analyst, you will play a critical role in developing and implementing comprehensive governance, risk, and compliance strategies, policies, and co...Show moreLast updated: 15 days ago
  • Promoted
SAP IDM and GRC Consultant

SAP IDM and GRC Consultant

Tata Consultancy ServicesNagpur, IN
TCS PAN INDIA hiring for SAP S4 / HANA SAP IDM and GRC Consultant on 20th Nov(Thursday) through Virtual Mode of Interview !!!!!. SAP S4 / HANA SAP IDM and GRC Consultant.SAP GRC Implementation : Design, ...Show moreLast updated: 2 days ago
  • Promoted
Senior Role - Grc & Infosec

Senior Role - Grc & Infosec

NPCI Bharat BillPay LimitedRepublic Of India, IN
Job Description – GRC (Infosec).The selected candidate will lead the development, implementation, and continuous improvement of the organization's governance, risk management, and compliance framew...Show moreLast updated: 8 days ago
  • Promoted
RTL Design Lead – SoC Integration (HBM / PCIe Gen6)

RTL Design Lead – SoC Integration (HBM / PCIe Gen6)

eInfochips (An Arrow Company)Nagpur, IN
Job Title : RTL Design Lead – SoC Integration (HBM / PCIe Gen6).Bangalore, Hyderabad, Chennai, Pune, Noida, Ahmedabad, Indore. The ideal candidate will be responsible for leading RTL design, driving ...Show moreLast updated: 5 days ago
  • Promoted
Oracle Fusion HCM Functional Lead / / ORC

Oracle Fusion HCM Functional Lead / / ORC

Hiresquad ResourcesNagpur, IN
Hiring For Oracle Cloud HCM Functional Lead.Looking for candidates with max 1 Month of notice period or Immediate Joiners. Also Hiring for - OTL, Benefits, Talent Management, US Payroll, Core HR, Co...Show moreLast updated: 9 days ago
  • Promoted
HRSS and People Analytics Director

HRSS and People Analytics Director

ProductLife GroupNagpur, IN
ProductLife Group (PLG) is a dedicated life sciences outsourcing and consulting company.The group is having HQ in Paris and affiliates around the globe with teams in all key regions : North America,...Show moreLast updated: 2 days ago
  • Promoted
Senior Platform Engineer GCP

Senior Platform Engineer GCP

First American (India)Nagpur, IN
At First American (India), we don’t just build software—we build the future of real estate technology.Our people- first culture empowers bold thinkers and passionate technologists to solve real-wor...Show moreLast updated: 10 days ago
  • Promoted
Business Analyst (GIS)

Business Analyst (GIS)

SoftTech Engineers LtdNagpur, IN
Founded in 1996 and headquartered in Pune, India, SoftTech Engineers Limited.We constantly improve and maintain our high-quality solutions through dedicated, proactive market research and developme...Show moreLast updated: 1 day ago