{"id":6193,"date":"2026-05-27T11:41:36","date_gmt":"2026-05-27T11:41:36","guid":{"rendered":"https:\/\/cephasconsult.biz\/?post_type=job_listing&#038;p=6193"},"modified":"2026-05-27T11:41:37","modified_gmt":"2026-05-27T11:41:37","slug":"manager-sr-manager-grc-governance-risk-and-compliance-78992","status":"publish","type":"job_listing","link":"https:\/\/cephasconsult.biz\/index.php\/job\/manager-sr-manager-grc-governance-risk-and-compliance-78992\/","title":{"rendered":"Manager \/ Sr. Manager \u2013 GRC (Governance, Risk and Compliance) 78992"},"content":{"rendered":"<p><span class=\"flex-shrink-0\">Positions:<span class=\"font-semibold\">1 <\/span><\/span><span class=\"flex-shrink-0 font-semibold\">Full Time<\/span><\/p>\n<div class=\"col-span-1\">Experience<\/div>\n<div class=\"font-inter-semibold-paragraph2  text-cbrex-light-surface-pb col-span-2\">8 &#8211; 14 Years<\/div>\n<div><\/div>\n<div>\n<p><span data-raw-html=\"span\">Role :-Governance, Risk and Compliance &#8211; Manager \/ Sr. Manager<\/span><\/p>\n<p><span data-raw-html=\"span\">Experience :- Min 8 Years<\/span><\/p>\n<p><span data-raw-html=\"span\">Location :- Bangalore<\/span><\/p>\n<p><span data-raw-html=\"span\">Notice Period:- Immediate Joiners<\/span><\/p>\n<p><span data-raw-html=\"span\">Communication:- Excellent comm skills<\/span><\/p>\n<p><strong><em><span data-raw-html=\"span\">\u00a0\u00a0<\/span><\/em><\/strong><\/p>\n<table>\n<thead>\n<tr>\n<th>Role Overview<\/th>\n<th>The Manager \/ Senior Manager \u2013 GRC will be responsible for driving the organization\u2019s Governance, Risk, and Compliance (GRC) initiatives, ensuring alignment with regulatory, contractual, and cybersecurity requirements. The role involves managing security governance frameworks, enterprise risk management, compliance audits, supplier security assessments, cybersecurity awareness initiatives, and executive-level reporting.<\/p>\n<p>The candidate will work closely with internal stakeholders, auditors, customers, suppliers, and leadership teams to strengthen the organization\u2019s cybersecurity posture and ensure compliance with applicable standards and regulations.<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Key Responsibilities<\/td>\n<td><strong>Governance, Risk &amp; Compliance (GRC)<\/strong><\/p>\n<ul>\n<li>Manage and govern Information Security frameworks such as ISO 27001, ISO 27701, ISO 20000, SOC 2, HIPAA, PCI DSS, NIST, DPDP, and other applicable standards<\/li>\n<li>Drive enterprise-wide Governance, Risk &amp; Compliance initiatives<\/li>\n<li>Maintain and improve ISMS, PIMS, and ITSM programs<\/li>\n<li>Develop, review, and maintain security policies, procedures, standards, guidelines, and templates<\/li>\n<li>Ensure periodic review and continuous improvement of cybersecurity governance processes<\/li>\n<li>Track compliance obligations and ensure closure of non-conformities and audit observations<\/li>\n<\/ul>\n<p><strong>Risk Management<\/strong><\/p>\n<ul>\n<li>Execute end-to-end cybersecurity risk management lifecycle<\/li>\n<li>Conduct risk assessments, gap assessments, and control evaluations<\/li>\n<li>Maintain enterprise risk register and track mitigation plans<\/li>\n<li>Identify cybersecurity risks related to applications, infrastructure, cloud, vendors, and business operations<\/li>\n<li>Work with stakeholders to define remediation plans and risk treatment strategies<\/li>\n<li>Monitor security KPIs, KRIs, and compliance metrics<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>Audit &amp; Compliance Management<\/strong><\/p>\n<ul>\n<li>Coordinate and manage internal audits, external audits, certification audits, surveillance audits, and customer security assessments<\/li>\n<li>Represent the organization during client audits and compliance reviews<\/li>\n<li>Coordinate with certifying bodies, auditors, and regulatory stakeholders<\/li>\n<li>Ensure audit readiness and timely closure of findings<\/li>\n<li>Prepare audit schedules, reports, evidence documentation, and compliance dashboards<\/li>\n<li>Support regulatory and contractual compliance requirements<\/li>\n<\/ul>\n<p><strong>Security Awareness &amp; Training<\/strong><\/p>\n<ul>\n<li>Develop and execute cybersecurity awareness and training programs across the organization<\/li>\n<li>Conduct periodic awareness campaigns, phishing awareness initiatives, and security communication activities<\/li>\n<li>Publish advisory notes, security alerts, awareness mailers, and best practice guidelines<\/li>\n<li>Promote awareness related to ISMS, ITSM, privacy, and cybersecurity compliance requirements<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>Management Reporting &amp; Executive Communication<\/strong><\/p>\n<ul>\n<li>Prepare cybersecurity dashboards, scorecards, and management review presentations<\/li>\n<li>Create executive-level cybersecurity decks for leadership and management reviews<\/li>\n<li>Present security posture, risks, audit status, compliance metrics, and improvement plan to senior management<\/li>\n<li>Support Management Review Meetings with reports, metrics, and action tracking<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>Supplier &amp; Third-Party Security Management<\/strong><\/p>\n<ul>\n<li>Conduct supplier\/vendor cybersecurity risk assessments and due diligence reviews<\/li>\n<li>Evaluate supplier security controls, compliance posture, and contractual obligations<\/li>\n<li>Track vendor compliance findings and remediation activities<\/li>\n<li>Collaborate with procurement and legal teams on third-party security governance<\/li>\n<\/ul>\n<p><strong>Contract &amp; Security Review<\/strong><\/p>\n<ul>\n<li>Review MSAs, SOWs, NDAs, RFPs, RFIs, and customer security requirements from a cybersecurity compliance perspective<\/li>\n<li>Provide security and compliance inputs during customer onboarding and procurement processes<\/li>\n<li>Ensure contractual alignment with regulatory and organizational cybersecurity requirements<\/li>\n<li>Support security questionnaires and customer assurance activities<\/li>\n<\/ul>\n<p>&nbsp;<\/td>\n<\/tr>\n<tr>\n<td>Knowledge:<\/td>\n<td>\n<ul>\n<li>Information Security frameworks and standards:\n<ul>\n<li>ISO 27001:2022<\/li>\n<li>ISO 27701<\/li>\n<li>ISO 20000<\/li>\n<li>NIST CSF<\/li>\n<li>SOC 2<\/li>\n<li>HIPAA<\/li>\n<li>PCI DSS<\/li>\n<li>DPDP Act<\/li>\n<\/ul>\n<\/li>\n<li>Risk management methodologies and audit practices<\/li>\n<li>Security governance and compliance management<\/li>\n<li>Third-party\/vendor risk management<\/li>\n<li>Network and infrastructure security concepts<\/li>\n<li>\u00a0Regulatory and contractual cybersecurity compliance requirements<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td>Skills:<\/td>\n<td>\n<ul>\n<li>Governance of multiple security and compliance frameworks<\/li>\n<li>Enterprise risk assessment and mitigation planning<\/li>\n<li>Audit management and stakeholder coordination<\/li>\n<li>Policy and documentation management<\/li>\n<li>Vendor\/supplier security assessment<\/li>\n<li>MSA, RFP, and contractual security review<\/li>\n<li>Cybersecurity reporting and dashboard preparation<\/li>\n<li>Executive presentation and management communication<\/li>\n<li>Strong analytical and problem-solving skills<\/li>\n<li>Excellent verbal and written communication<\/li>\n<li>Ability to manage cross-functional stakeholders<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td>Tasks:<\/td>\n<td>\n<ul>\n<li>Review &amp; Analyse various InfoSec requirements and advise on implementation<\/li>\n<li>Be a Change Approver for the Information Security requirement<\/li>\n<li>Prepare &amp; Publish Advisory Notes, InfoSec Awareness mailers etc.<\/li>\n<li>Develop and maintain documents (policies, procedures, templates), records, and templates related to ISO 27001\/27701, ISO 20000, NIST, SOC 2, HIPAA, PCI DSS, DPDPA<\/li>\n<li>Creation and Periodic review of policies, procedures, and templates<\/li>\n<li>Promoting awareness related to ISMS &amp; ITSM<\/li>\n<li>Preparing Audit Schedules \/ Plan, Conduct Internal Audits periodically, Publish Report, and track till closure<\/li>\n<li>Initiate necessary corrective and preventive action<\/li>\n<li>Measuring &amp; Monitoring the ISMS &amp; ITSM process performance \/ KPI periodically<\/li>\n<li>Prepare Management Review Meeting Reports, Plan, Schedule, and conduct periodic Management Review Meetings<\/li>\n<li>Coordinating with Certifying Body<\/li>\n<li>Representing the management during various external audits (certification &amp; surveillance audits, client InfoSec audits, etc)<\/li>\n<li>Ensuring the compliance of all the functions as per the ISO 27001\/27701, ISO 20000, NIST, SOC 2, HIPAA, PCI DSS<\/li>\n<li>Reporting to the top management on the performance, opportunities for improvement, issues, non-conformities, Audit reports, etc., related to ITSM &amp; ISMS<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td>Soft Skills:<\/td>\n<td>\n<ul>\n<li>Strong communication and report writing skills<\/li>\n<li>Analytical and problem-solving ability<\/li>\n<li>Stakeholder management and teamwork<\/li>\n<li>Proficiency in MS Excel, Word, and PowerPoint<\/li>\n<li>Presentation and audit handling skills<\/li>\n<li>Proactive mindset with strong ownership<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td>Certifications (Any Two or more):<\/td>\n<td>\n<ul>\n<li>ISMS LA\/LI ISO-27001:2022<\/li>\n<li>PIMS LA\/LI ISO-27701:2025<\/li>\n<li>ITSM LA\/LI ISO-20000:2018<\/li>\n<li>CEH, CHFI, CISSP or CISA certificate<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td>Education:<\/td>\n<td>\n<ul>\n<li>Any Graduate in Information Technology<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td>Experience:<\/td>\n<td>\n<ul>\n<li>7 to 10 years of experience in managing the Information Security framework of an organization<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"template":"","meta":{"_job_location":"Bangalore, Karnataka, India","_application":"hrm@cephasconsult.biz","_company_name":"","_company_website":"","_company_tagline":"","_company_twitter":"","_company_video":"","_filled":0,"_featured":0,"_remote_position":0,"_job_salary":"","_job_salary_currency":"","_job_salary_unit":""},"job-types":[],"class_list":["post-6193","job_listing","type-job_listing","status-publish","hentry"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cephasconsult.biz\/index.php\/wp-json\/wp\/v2\/job-listings\/6193","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cephasconsult.biz\/index.php\/wp-json\/wp\/v2\/job-listings"}],"about":[{"href":"https:\/\/cephasconsult.biz\/index.php\/wp-json\/wp\/v2\/types\/job_listing"}],"author":[{"embeddable":true,"href":"https:\/\/cephasconsult.biz\/index.php\/wp-json\/wp\/v2\/users\/1"}],"wp:attachment":[{"href":"https:\/\/cephasconsult.biz\/index.php\/wp-json\/wp\/v2\/media?parent=6193"}],"wp:term":[{"taxonomy":"job_listing_type","embeddable":true,"href":"https:\/\/cephasconsult.biz\/index.php\/wp-json\/wp\/v2\/job-types?post=6193"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}