Talent.com
Cybersecurity Governance & Compliance Lead
Cybersecurity Governance & Compliance LeadIHX - A Perfios Company • Bengaluru, Republic Of India, IN
Cybersecurity Governance & Compliance Lead

Cybersecurity Governance & Compliance Lead

IHX - A Perfios Company • Bengaluru, Republic Of India, IN
12 hours ago
Job description

The IT Risk Officer owns day-to-day information-security, privacy, and IT-risk governance for IHX. Acting as the single point of contact between local teams and the Perfios central security office, the role ensures that technology risks are identified, assessed, mitigated, and reported in line with ISO 27001 : 2022 , the Digital Personal Data Protection (DPDP) Act , and Perfios Group policies.

Key Responsibilities

Risk Governance & GRC

Maintain and periodically review the IT / InfoSec risk register with the IT Head and Perfios security lead.

Align the subsidiary’s Statement of Applicability (SoA) with the Perfios ISO 27001 scope and manage related evidence collection.

Policy & Compliance

Localize Perfios security, privacy, and AI policies for complete compliance across teams.

Monitor adherence to the DPDP Act, client contractual obligations, and emerging regulatory requirements.

Security Operations Oversight

Oversee the health and performance of security solutions including CrowdStrike, Netskope, JumpCloud, and SOC integrations.

Triage high-severity alerts and coordinate incident response activities including root-cause analysis.

System Troubleshooting & Correlation

Troubleshoot and correlate system-level issues across Linux / Windows environments with cybersecurity alerts.

Analyze security events across multiple systems and platforms.

Threat & Vulnerability Management

Schedule vulnerability assessments, penetration tests, configuration audits, and GuardDuty reviews.

Track remediation SLAs and provide monthly status updates.

Third-Party Risk Management (TPISA)

Perform risk-based assessments of third-party service providers.

Follow up on identified remediations and verify compliance with contract clauses.

Incident Response & Forensics

Participate in incident response activities including log analysis, forensic triage, containment, and remediation.

Collaborate with forensic specialists to validate findings and assist in root-cause analysis.

Business Continuity & Disaster Recovery

Support disaster-recovery drills for client deployments and verify RTO / RPO compliance.

Update and maintain DR documentation and runbooks.

Awareness & Training

Conduct phishing simulations, awareness programs, and secure-coding refreshers.

Track awareness performance metrics and implement improvements.

Reporting & Metrics

Prepare monthly KPI / KRI dashboards covering risk posture, incidents, and roadmap progress for leadership review.

Required Qualifications & Experience

Mandatory

  • Education : Bachelor’s degree in IT, Computer Science, Information Security, or a related field.
  • Experience : 5–6 years in InfoSec, IT Risk, or Security Operations with hands-on exposure to SIEM / EDR and audits.
  • Certifications : CISSP, CISM, ISO 27001 Lead Auditor, or equivalent.
  • Technical Skills : Vulnerability management, endpoint security, cloud security (AWS / Azure / GCP), IAM (JumpCloud / AD), EDR / AV, IDS / IPS, encryption, DLP, SIEM / SOC operations, DDoS protection, patch management.
  • Frameworks : ISO 27001, NIST CSF, DPDP Act, OWASP.

Preferred

  • Education : Post-graduate in Cybersecurity or MBA (Tech Management).
  • Experience : Familiarity with BFSI or FinTech domains.
  • Certifications : CRISC, CCSP, CCSK.
  • Technical : DevSecOps tooling, IaC security frameworks.
  • Frameworks : RBI / SEBI guidelines, SOC 2.
  • Core Competencies

  • Risk-based decision-making.
  • Strong communication skills (technical and executive).
  • Analytical problem-solving and root-cause analysis.
  • Ownership and execution discipline.
  • Continuous learning mindset.
  • Create a job alert for this search

    Cybersecurity Governance Lead • Bengaluru, Republic Of India, IN

    Related jobs
    Cyber Security Lead

    Cyber Security Lead

    Societe Generale Global Solution Centre • Bengaluru, Karnataka, India
    Ability to identify, propose, design and run the operational and security risk Controls.Sound understanding of various cybersecurity controls and their relevance to handle various threat scenarios....Show more
    Last updated: 8 days ago • Promoted
    Lead Cybersecurity Engineer-Ai

    Lead Cybersecurity Engineer-Ai

    Chevron • Bengaluru, Republic Of India, IN
    The Lead IT Cybersecurity Engineer is responsible for the technical design of IT cybersecurity architectural guidelines and standards, as well as the secure implementation of IT digital technologie...Show more
    Last updated: 7 days ago • Promoted
    Digile - Manager - Governance / Risk & Compliance

    Digile - Manager - Governance / Risk & Compliance

    DIGILE TECHNOLOGIES PRIVATE LIMITED • Bangalore, India
    Description : About the Role : We are seeking a highly experienced Governance, Risk, and Compliance (GRC) Manager to lead our enterprise risk manag...Show more
    Last updated: 17 days ago • Promoted
    Senior Cybersecurity Analyst (L3)

    Senior Cybersecurity Analyst (L3)

    HR Path • Bengaluru, Republic Of India, IN
    HR Path Group, a global leader in HR consulting, helps clients with their HR transformation projects, covering both human and HRIS (Human Resources Information System) aspects.Our 2,500 employees a...Show more
    Last updated: 7 days ago • Promoted
    Commure - Lead - Governance / Risk / Compliance - Information Technology

    Commure - Lead - Governance / Risk / Compliance - Information Technology

    Commure • Bangalore, India
    About The Role : - We're seeking an experienced GRC Lead to drive Commure's governance, risk, and compliance strategy across our global operations.In this critical lea...Show more
    Last updated: 28 days ago • Promoted
    Lead Cybersecurity Engineer-AI

    Lead Cybersecurity Engineer-AI

    Chevron • Bengaluru, Karnataka, India
    The Lead IT Cybersecurity Engineer is responsible for the technical design of IT cybersecurity architectural guidelines and standards, as well as the secure implementation of IT digital technologie...Show more
    Last updated: 7 days ago • Promoted
    Senior Manager–Cybersecurity & Cyber Defense Center

    Senior Manager–Cybersecurity & Cyber Defense Center

    Mashreq • Bengaluru, Karnataka, India
    To develop, manage, and execute cyber security project across Mashreq to –.Lead and oversee the strategic operations of the Cyber Defense Center (CDC) to ensure effective monitoring, detection, ana...Show more
    Last updated: 7 days ago • Promoted
    Director Enterprise Cybersecurity

    Director Enterprise Cybersecurity

    The Edge Partnership • Bangalore, India
    Our client is a leading global investment and advisory firm known for its deep expertise in private equity, real estate, and alternative asset management. The ideal professional will lead regional c...Show more
    Last updated: 15 days ago • Promoted
    Cyber Security Delivery Lead

    Cyber Security Delivery Lead

    YASH Technologies • Greater Bengaluru Area, India
    To lead the delivery of cybersecurity programs and projects, ensuring alignment with organizational objectives, compliance standards, and risk management frameworks. The role focuses on driving secu...Show more
    Last updated: 2 days ago • Promoted
    Digital Identity Governance Leader

    Digital Identity Governance Leader

    Global capability centre • Bengaluru, Republic Of India, IN
    Enterprise Identity Management environment where Zero Trust and Business continuity is key.Managing the end-to-end Identity governance solutions optimizing and automizing our processes.Driving the ...Show more
    Last updated: 14 days ago • Promoted
    Amagi - Analyst - Governance / Risk & Compliance

    Amagi - Analyst - Governance / Risk & Compliance

    Amagi Media Labs • Bangalore, India
    This role has been established to support the business in building sustainable governance andcompliance practices at Amagi. The basic factor required to be successful in this role warrants a good un...Show more
    Last updated: 30+ days ago • Promoted
    Cybersecurity Solution - Presales

    Cybersecurity Solution - Presales

    Mindsprint • Hosur, Tamil Nadu, India
    Position Summary : The Cybersecurity Solution (Presale) is responsible for leading cybersecurity presales activities, crafting secure and scalable solutions for enterprise clients, supporting RFP / RF...Show more
    Last updated: 4 hours ago • Promoted • New!
    AVP - Governance Risk & Compliance - Information Security Group

    AVP - Governance Risk & Compliance - Information Security Group

    Mashreq Global Services Private Limited • Bangalore, India
    Key Responsibilities : 1.Information Security Governance - Develop, implement, and maintain the Information Security Governance Framework in alignment with ...Show more
    Last updated: 30+ days ago • Promoted
    Senior Manager–cybersecurity & Cyber Defense Center

    Senior Manager–cybersecurity & Cyber Defense Center

    Mashreq • Bengaluru, Republic Of India, IN
    To develop, manage, and execute cyber security project across Mashreq to –.Lead and oversee the strategic operations of the Cyber Defense Center (CDC) to ensure effective monitoring, detection, ana...Show more
    Last updated: 7 days ago • Promoted
    Governance, Risk & Compliance Manager

    Governance, Risk & Compliance Manager

    DIGILE TECHNOLOGIES PRIVATE LIMITED • Bangalore
    About the Role : We are seeking a highly experienced Governance, Risk, and Compliance (GRC) Manager to lead our enterprise risk management and compliance initiatives...Show more
    Last updated: 18 days ago • Promoted
    Principal Governance, Risk & Compliance Manager Cybersecurity Governance

    Principal Governance, Risk & Compliance Manager Cybersecurity Governance

    Zscaler • Bengaluru, Karnataka, India
    Serving thousands of enterprise customers around the world including 45% of Fortune 500 companies Zscaler (NASDAQ : ZS) was founded in 2007 with a mission to make the cloud a safe place to do busine...Show more
    Last updated: 30+ days ago • Promoted
    Digital Identity Governance leader

    Digital Identity Governance leader

    Global capability centre • Bengaluru, Karnataka, India
    Enterprise Identity Management environment where Zero Trust and Business continuity is key.Managing the end-to-end Identity governance solutions optimizing and automizing our processes.Driving the ...Show more
    Last updated: 14 days ago • Promoted
    Director Enterprise Cybersecurity

    Director Enterprise Cybersecurity

    The Edge Partnership - The Edge in Asia • Bengaluru, Karnataka, India
    Our client is a leading global investment and advisory firm known for its deep expertise in private equity, real estate, and alternative asset management. The ideal professional will lead regional c...Show more
    Last updated: 20 days ago • Promoted