
Search by job, company or skills
ZS is a place where passion changes lives. As a management consulting and technology firm focused on improving life and how we live it, we transform ideas into impact by bringing together data, science, technology and human ingenuity to deliver better outcomes for all. Here you'll work side-by-side with a powerful collective of thinkers and experts shaping life-changing solutions for patients, caregivers and consumers, worldwide. ZSers drive impact by bringing a client-first mentality to each and every engagement. We partner collaboratively with our clients to develop custom solutions and technology products that create value and deliver company results across critical areas of their business. Bring your curiosity for learning, bold ideas, courage and passion to drive life-changing impact to ZS.
Manager - GRC
Technical Audit & Assurance . AI Risk Governance . Project Risk
About ZS
ZS is a professional services firm that works side by side with companies to help develop and deliver products that drive customer value and company results. From R&D to portfolio strategy, customer insights, marketing and sales, operations, and technology, we leverage data, science, and technology to enable higher-impact decisions, sharper execution, and more transformative outcomes. ZS has more than 15,000 employees worldwide, operating from 40+ offices across the Americas, Europe, and Asia-Pacific, and is trusted by the world's leading pharmaceutical, biotech, medtech, and technology companies.
About the GRC Function
Governance, Risk & Compliance (GRC) is ZS's enterprise-wide second-line governance function - governing the integrity of the firm's control environment, managing the certification and assurance portfolio, and providing the independent risk signal that enables leadership to make informed decisions with confidence.
The function operates alongside ERM and Legal/Compliance within ZS's governance structure and works closely with the ZS's Delivery Excellence (DEX) organization for delivery governance and audit. GRC's four accountability areas span control environment integrity, regulatory and certification compliance, risk intelligence and oversight, and delivery and operational assurance. The function is midway through a deliberate expansion of its assurance capabilities, and this role is central to that growth.
The Role
The Manager - GRC (Technical Audit & Assurance) is a senior individual contributor and program leader responsible for GRC's technical audit and assurance capabilities. The role leads client security audits, owns GRC's AI risk governance workstream, and strengthens the Project Risk Assessment (PRA) program through technical depth and independent oversight.
The Manager works closely with three peer leads - Certifications & Compliance, Risk Operations, and Third-Party Risk & Data Compliance - and is a key partner to the Delivery Excellence organization and ZS's Technology, Platform Services and Client Service organizations. The role reports to the Head of GRC.
Key Responsibilities
Client & Delivery Security Audit Program
Lead GRC's client and delivery security audit program - independent, evidence-based reviews of security and governance controls in live client engagements and across ZS's delivery organization.
AI Risk Governance
Own GRC's AI risk and compliance governance workstream - building the assessment methodology, control framework, and assurance infrastructure that enables ZS to scale AI-enabled delivery responsibly and credibly.
Project Assurance - PRA and Special Interventions
Strengthen the Project Risk Assessment (PRA) program - GRC's unified governance gate for client-facing projects - through technical rigor, assurance quality, and hands-on intervention capability.
GxP and Life Sciences Compliance (specialization valued)
ZS serves leading life sciences organizations across pharma, biotech, payer, and healthcare sectors. Candidates with GxP, CSV, or 21 CFR Part 11 experience will find an active need in this role - providing specialist assurance coverage on life sciences client engagements, contributing to GxP audit frameworks, and advising CSTs and project teams on regulatory compliance requirements within GRC's scope.
Stakeholder Engagement and Reporting
Skills, Experience & Qualifications
Professional Experience
Core Technical Expertise
Leadership and Behavioral Competencies
Education & Certifications
Education
Certifications (preferred - not all required)
What Makes This Role Unique
ZS is committed to building an inclusive and diverse workforce and welcomes applications from all qualified candidates. We are an equal opportunity employer.
How you'll grow:
Perks & Benefits:
At ZS, your growth matters. We offer a comprehensive total rewards package that supports your health and well‑being, financial future, time away, and professional development. With robust skills‑building programs, multiple career progression paths, internal mobility, and a deeply collaborative culture, you'll have the opportunity to do meaningful work, expand your capabilities, and thrive as part of a global community. For details on total rewards in , visit .
Hybrid working model:
We are committed to giving our employees a flexible and connected way of working. A flexible and connected ZS allows us to combine work from home and on-site presence at clients/ZS offices for the majority of our week. The magic of ZS culture and innovation thrives in both planned and spontaneous face-to-face connections.
Travel:
Travel is a requirement at ZS for client facing ZSers business needs of your project and client are the priority. While some projects may be local, all client-facing ZSers should be prepared to travel as needed. Travel provides opportunities to strengthen client relationships, gain diverse experiences, and enhance professional growth by working in different environments and cultures.
Considering applying
At ZS, we honor the visible and invisible elements of our identities, personal experiences, and belief systems-the ones that comprise us as individuals, shape who we are, and make us unique. We believe your personal interests, identities, and desire to learn are integral to your success here. We are committed to building a team that reflects a broad variety of backgrounds, perspectives, and experiences. about our inclusion and belonging efforts and the networks ZS supports to assist our ZSers in cultivating community spaces and obtaining the resources they need to thrive.
If you're eager to grow, contribute, and bring your unique self to our work, we encourage you to apply.
ZS is an equal opportunity employer and is committed to providing equal employment and advancement opportunities without regard to any class protected by applicable law.
To complete your application:
Candidates must possess or be able to obtain work authorization for their intended country of employment. An on-line application, including a full set of transcripts (official or unofficial), is required to be considered.
NO AGENCY CALLS, PLEASE.
Find Out More At:
Job ID: 152351127
Skills:
risk frameworks , technology risk , Gxp, Csv, 21 Cfr Part 11, Application Security, CI CD pipeline security, cloud security controls, secrets management, cyber assurance, It Audit, technical GRC, access and identity management, AI governance, Security Audits, SDLC governance