Talent.com
Senior Role - Grc & Infosec
Senior Role - Grc & InfosecNPCI Bharat BillPay Limited • Republic Of India, IN
Senior Role - Grc & Infosec

Senior Role - Grc & Infosec

NPCI Bharat BillPay Limited • Republic Of India, IN
8 days ago
Job description

Job Description – GRC (Infosec)

Job Summary : The selected candidate will lead the development, implementation, and continuous improvement of the organization's governance, risk management, and compliance frameworks and programs. This role is critical in fostering a strong risk-aware and compliant culture across all departments, ensuring the organization meets its legal, regulatory, and ethical obligations while strategically managing potential threats to its operations and objectives.

Education & Qualification :

B.E. / B.Tech with minimum 13 + years of experience in in Governance, Risk, and Compliance roles, with a significant portion in a leadership capacity.

Professional certifications such as Security+, Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Governance of Enterprise IT (CGEIT), GRC Professional, Certified Chief Information Security Officer (CCISO) or similar are preferred.

Key Responsibilities :

Define the overall GRC strategy, policies, standards, and procedures.

Oversee the identification, assessment, analysis, and prioritization of enterprise-wide risks, including operational, reputational, and cybersecurity risks.

Develop and implement robust risk mitigation strategies and controls

Monitor the effectiveness of risk management activities and report on the organization's risk posture to senior leadership and the Board.

Ensure the organization complies with all applicable laws, regulations, industry standards, and internal policies (e.G., data privacy regulations like DPDPA, RBI regulatory requirements and compliance)

Develop and manage compliance programs, internal audits, and assessments to identify and address compliance gaps.

Drive a strong governance culture by establishing clear accountability, transparency, and ethical conduct throughout the organization

Develop and implement governance policies and procedures to guide decision-making and operational processes

Develop meaningful GRC metrics, dashboards, and reports for various stakeholders, including executive management and the Board.

Collaborate closely with various departments, including Enterprise Risk, IT Operations, Legal, Finance and HR to integrate GRC principles into daily business operations.

Act as a trusted advisor to business on Infosec Risk and Compliance matters.

Thoroughly review of all incoming information security requests (e.G., user access, system configuration changes, firewall rules creation / modifications, software installations, data access, third-party system integrations) and approve them.

Assess requests for completeness, accuracy, and adherence to established information security policies, procedures, & guidelines and analyse potential security risks, impacts associated with each request, including data confidentiality, integrity, and availability.

Review and approve access requests to sensitive systems, applications, and data and validate justifications, roles, and least-privilege principles prior to approval.

Maintain a comprehensive understanding of evolving security threats, vulnerabilities, and regulatory changes related to upcoming technologies like Blockchain and AI to take informed approval decisions.

Review and recommend exceptions to security policies and standards, identify and document any residual risks associated with approved exceptions, and ensure that compensating controls are in place for recommended exceptions, documenting the rationale, validity period, and expiration tracking.

Communicate clearly and concisely with requestors, providing detailed explanations for approvals, denials, or requests for additional information.

Identify opportunities to streamline the request approval process, enhance efficiency, and improve security controls.

Evaluate security architectures and designs to determine the adequacy of security design and architecture proposed or provided in response to requirements

Provide guidance and mentorship to junior security team members.

Technical Skills :

  • Deep understanding of GRC principles, methodologies, and best practices.
  • Strong analytical and problem-solving skills with the ability to identify, assess, and mitigate complex risks.
  • Excellent communication, interpersonal, and presentation skills, with the ability to articulate complex GRC concepts to diverse audiences (technical and non-technical, all levels of management).
  • Proven leadership and team management abilities, including the ability to influence and collaborate across departments.
  • Strategic thinking with a proactive approach to GRC challenges.
  • High level of integrity and ethical conduct.
  • Ability to manage multiple projects and priorities in a dynamic environment.
  • Proven track record of developing, implementing, and managing successful GRC programs in a complex organizational environment.
  • Strong experience with risk assessment methodologies, control frameworks, and compliance audits.
  • Experience with relevant regulatory frameworks (e.G., ISO 27001, NIST, SOC 2, PCI DSS, DPDPA, GDPR etc.).
  • Strong understanding of security domains (e.G., network security, data security, application security).
  • Understanding on cryptographic standards, application security, enterprise architecture, software development lifecycle etc.
  • Experience with security frameworks (e.G., MITRE, NIST, ISO).
  • Familiar in Vulnerability Management and Configuration Management with a commitment to staying current on emerging security threats and technological advancements.
  • Knowledge of identity and access management (IAM) concepts and technologies and Familiarity with role-based access control (RBAC) models and approval workflows.
  • Knowledge of cryptography, secure communication protocols, data encryption techniques, understanding of Key management process.
  • Deep understanding of security vulnerabilities exploits applications, infrastructure and APIs
  • Strong analytical and problem-solving skills.
  • Basic understanding of cloud security principles (AWS, Azure, GCP) is a plus.
  • Experience with ITSM or request / ticketing systems (e.G., ServiceNow, Jira, Remedy).
Create a job alert for this search

Senior • Republic Of India, IN

Related jobs
Senior GenAI Engineer

Senior GenAI Engineer

Mitra AI • Nagpur, IN
AI System Design & Development : .Architect, develop, and deploy large-scale Generative AI, LLM-based systems, including intelligent agents and automation workflows. LLM Integration & Optimization : .In...Show more
Last updated: 1 hour ago • Promoted • New!
Senior Consultant

Senior Consultant

Proglite • Nagpur, IN
We are seeking a motivated and skilled.Network / Cloud / Security Engineer.AWS, Google Cloud Platform (GCP), Cisco Meraki, and Palo Alto firewalls. The ideal candidate will be responsible for design...Show more
Last updated: 30+ days ago • Promoted
UKG INTEGRATION SPECIALIST

UKG INTEGRATION SPECIALIST

Wimmer Solutions • India, India
At Wimmer Solutions, we believe care creates community.We work smart; we have built a reputation for results-oriented, innovative, business and technology solutions that help companies execute on t...Show more
Last updated: 16 days ago • Promoted
Senior Consultant

Senior Consultant

Valorant • Nagpur, IN
Valorant is a fast-growing consulting firm at the intersection of procurement and AI.We help global clients — across private equity, technology, life sciences, financial services, industrials, and ...Show more
Last updated: 30+ days ago • Promoted
Senior GRC Analyst

Senior GRC Analyst

Confidential • India
Demandbase is the Smarter GTM™ company for B2B brands.We help marketing and sales teams overcome the disruptive data and technology fragmentation that inhibits insight and forces them to spam their...Show more
Last updated: 9 days ago • Promoted
Gastroenterologist

Gastroenterologist

MedSciX • Nagpur, IN
MedSciX is partnering with leading hospitals across the Caribbean to recruit an experienced Consultant Gastroenterologist to provide expert care in the diagnosis, treatment, and management of gastr...Show more
Last updated: 3 days ago • Promoted
Senior AI Developer

Senior AI Developer

PioVation GmbH • Nagpur, IN
Cloud Operating System and we need someone who can ship.If you like taking AI from prototype → scalable product, this is for you. Design and ship AI / LLM features that run in production.Build RAG-sty...Show more
Last updated: 16 days ago • Promoted
Grc Consultant

Grc Consultant

Solytics Partners • Pune, Republic Of India, IN
Solytics Partners is a Global Analytics firm, recognized with multiple industry awards for innovation and excellence.Our team comprises experts with deep knowledge in risk, analytics, AI / ML, AML / FC...Show more
Last updated: 16 days ago • Promoted
Cyble - GRC Lead

Cyble - GRC Lead

Cyble • India
Description : About Cyble : Cyble is revolutionizing the landscape of cybersecurity intell...Show more
Last updated: 21 days ago • Promoted
GRC Analyst

GRC Analyst

Confidential • India
Demandbase is seeking a motivated and detail-oriented GRC Sr Analyst to support its global Governance, Risk, and Compliance program. Reporting to the Senior Director of GRC, you'll collaborate cross...Show more
Last updated: 19 days ago • Promoted
SAP GRC Consultant

SAP GRC Consultant

EliteRecruitments • India
GGN | Bangalore | Pune | Hyderabad.Individual Contributor / Supervisory.Deliver IT Risk & Controls Assessments, IT Audits, and Compliance reviews. Coordinate with global teams on engagements.Ensure ...Show more
Last updated: 2 hours ago • Promoted • New!
Freelance Opportunity : Sr. Epicor CMS Developer (IBM i / RPG / EDI)

Freelance Opportunity : Sr. Epicor CMS Developer (IBM i / RPG / EDI)

ThreatXIntel • Nagpur, IN
ThreatXIntel is a cybersecurity startup focused on protecting businesses and organizations from evolving cyber threats through innovative and tailored solutions. The company provides a range of serv...Show more
Last updated: 18 hours ago • Promoted • New!
Technical Consultant- Infor LX

Technical Consultant- Infor LX

Programmers.io • Nagpur, IN
The RPG Programmer will be responsible for analyzing, modifying, and developing programs and database files to ensure full compatibility with the upgraded Infor LX 8. This role requires a deep under...Show more
Last updated: 16 days ago • Promoted
Blockchain Lead

Blockchain Lead

Taazaa Inc • Nagpur, IN
Engineering team and to architect and guide the development of blockchain-based solutions across our emerging product lines — from ethical finance and payments to transparency-driven logistics and ...Show more
Last updated: 2 hours ago • Promoted • New!
GPO - InterCompany (F&A Ops)

GPO - InterCompany (F&A Ops)

Confidential • India
Be part of the solution at Technip Energies and embark on a one-of-a-kind journey.You will be helping to develop cutting-edge solutions to solve real-world energy problems.Technip Energies is a glo...Show more
Last updated: 30+ days ago • Promoted
GRC & Infosec Lead

GRC & Infosec Lead

NPCI Bharat BillPay Limited • Republic Of India, IN
Job Description – GRC (Infosec).The selected candidate will lead the development, implementation, and continuous improvement of the organization's governance, risk management, and compliance framew...Show more
Last updated: 8 days ago • Promoted
Grc Analyst

Grc Analyst

J.B. Poindexter & Co • Republic Of India, IN
Analyst, Governance, Risk and Compliance.As the GRC Analyst, you will play a critical role in developing and implementing comprehensive governance, risk, and compliance strategies, policies, and co...Show more
Last updated: 16 days ago • Promoted
Senior Pega Developer

Senior Pega Developer

Tenth Revolution Group • Nagpur, IN
We are looking for an experienced.This role is ideal for professionals who are passionate about designing enterprise-level Pega applications, leading technical teams, and delivering impactful digit...Show more
Last updated: 2 hours ago • Promoted • New!