Role Overview
We are seeking an experienced GRC Specialist to drive governance, risk, compliance, and third-party risk management initiatives in our organization. The ideal candidate will possess deep expertise in regulatory compliance (ISO 27001, GDPR, Indian privacy laws), risk assessment frameworks, and hands-on experience in managing third-party/vendor risk programs.
Key Responsibilities
- Develop, implement, and manage organization-wide GRC policies, processes, and controls in alignment with legal industry standards.
- Lead Third-Party Risk Management (TPRM) lifecycle, including vendor assessments, onboarding, monitoring, and due diligence.
- Perform risk assessments of external vendors/partners, identifying, quantifying, and mitigating risks in data privacy, cybersecurity, and regulatory compliance.
- Maintain and update vendor risk register; ensure effective risk tracking and regular reporting to leadership.
- Create and manage GRC dashboards, metrics, and executive reports.
- Collaborate with procurement, legal, and IT teams to enforce TPRM and GRC requirements throughout the vendor lifecycle.
- Conduct periodic compliance audits, risk reviews, and policy updates.
- Develop educational programs to raise GRC awareness across the organization.
- Monitor changes in regulatory requirements and ensure timely policy alignment and implementation.
- Support incident response actions involving vendors and ensure regulatory reporting where required.
Required Skills and Qualifications
- Bachelor's degree in Information Security, Risk Management, or Law (preferred).
- 2–3 years of direct experience working in GRC roles, specifically in Third-Party Risk Management.
- Solid understanding of regulatory frameworks: ISO 27001, GDPR, HIPAA, Indian IT Act, or similar compliance standards.
- Strong analytical skills in risk identification, quantification, and treatment.
- Excellent verbal and written communication skills for policy documentation, reporting, and cross-functional collaboration.
- Demonstrated ability to manage multiple vendor relationships and drive risk mitigation strategies.
- Familiarity with legal industry compliance requirements is advantageous.
Preferred Certifications
- ISO 27001 Lead Implementer/Auditor
Location:
Bangalore