Posted:2 days ago|
Platform:
On-site
Full Time
Job Description – GRC (Infosec)
Job Summary: The selected candidate will lead the development, implementation, and continuous improvement of the organization's governance, risk management, and compliance frameworks and programs. This role is critical in fostering a strong risk-aware and compliant culture across all departments, ensuring the organization meets its legal, regulatory, and ethical obligations while strategically managing potential threats to its operations and objectives.
Education & Qualification:
B.E. / B.Tech with minimum 13 + years of experience in in Governance, Risk, and Compliance roles, with a significant portion in a leadership capacity.
Professional certifications such as Security+, Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Governance of Enterprise IT (CGEIT), GRC Professional, Certified Chief Information Security Officer (CCISO) or similar are preferred.
Key Responsibilities:
Define the overall GRC strategy, policies, standards, and procedures.
Oversee the identification, assessment, analysis, and prioritization of enterprise-wide risks, including operational, reputational, and cybersecurity risks.
Develop and implement robust risk mitigation strategies and controls
Monitor the effectiveness of risk management activities and report on the organization's risk posture to senior leadership and the Board.
Ensure the organization complies with all applicable laws, regulations, industry standards, and internal policies (e.g., data privacy regulations like DPDPA, RBI regulatory requirements and compliance)
Develop and manage compliance programs, internal audits, and assessments to identify and address compliance gaps.
Drive a strong governance culture by establishing clear accountability, transparency, and ethical conduct throughout the organization
Develop and implement governance policies and procedures to guide decision-making and operational processes
Develop meaningful GRC metrics, dashboards, and reports for various stakeholders, including executive management and the Board.
Collaborate closely with various departments, including Enterprise Risk, IT Operations, Legal, Finance and HR to integrate GRC principles into daily business operations.
Act as a trusted advisor to business on Infosec Risk and Compliance matters.
Thoroughly review of all incoming information security requests (e.g., user access, system configuration changes, firewall rules creation/modifications, software installations, data access, third-party system integrations) and approve them.
Assess requests for completeness, accuracy, and adherence to established information security policies, procedures, & guidelines and analyse potential security risks, impacts associated with each request, including data confidentiality, integrity, and availability.
Review and approve access requests to sensitive systems, applications, and data and validate justifications, roles, and least-privilege principles prior to approval.
Maintain a comprehensive understanding of evolving security threats, vulnerabilities, and regulatory changes related to upcoming technologies like Blockchain and AI to take informed approval decisions.
Review and recommend exceptions to security policies and standards, identify and document any residual risks associated with approved exceptions, and ensure that compensating controls are in place for recommended exceptions, documenting the rationale, validity period, and expiration tracking.
Communicate clearly and concisely with requestors, providing detailed explanations for approvals, denials, or requests for additional information.
Identify opportunities to streamline the request approval process, enhance efficiency, and improve security controls.
Evaluate security architectures and designs to determine the adequacy of security design and architecture proposed or provided in response to requirements
Provide guidance and mentorship to junior security team members.
Technical Skills:
NPCI Bharat BillPay Limited
Upload Resume
Drag or click to upload
Your data is secure with us, protected by advanced encryption.
Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.
We have sent an OTP to your contact. Please enter it below to verify.
mumbai, maharashtra, india
Salary: Not disclosed
mumbai, maharashtra, india
Salary: Not disclosed