JobRaahGet matched free

Jobs

Senior Manager

Calpion Software Technologies · Bangalore North, Karnataka, India · On-site

Posted Jul 22, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

Job Description – Security Governance & Risk Leader Position Title Security Governance, Risk & Compliance (GRC) Leader Department Information Security / Technology Reports To Chief Information Security Officer (CISO) / Chief Information Officer (CIO)/VP IT infrastructure and Information security Position Summary The Security Governance, Risk & Compliance (GRC) Leader is responsible for establishing and maintaining a robust security governance framework that aligns cybersecurity initiatives with organizational objectives, regulatory requirements, and industry best practices. This role provides strategic leadership for information security governance, risk management, compliance, policy administration, audit readiness, and security oversight across the enterprise. The incumbent will work closely with executive leadership, business stakeholders, IT teams, auditors, regulators, and third-party partners to ensure that security risks are effectively managed, compliance obligations are met, and security controls support business growth while protecting organizational assets. Key Responsibilities 1. Security Governance & Strategy Develop and implement enterprise-wide cybersecurity governance frameworks aligned with business objectives and regulatory requirements. Define, maintain, and enforce information security policies, standards, procedures, and guidelines. Establish governance structures, security committees, and reporting mechanisms to support security oversight. Partner with executive leadership to align security strategy with organizational goals and risk appetite. Develop security roadmaps and maturity improvement programs based on industry frameworks and emerging threats. Present security governance updates, risk posture, and compliance status to executive management and board committees. 2. Security Risk Management & Compliance Establish and maintain an enterprise information security risk management framework. Identify, assess, monitor, and mitigate cybersecurity risks affecting business operations and technology environments. Maintain security risk registers and track remediation activities to closure. Ensure compliance with applicable regulatory, legal, and contractual requirements, including: ISO 27001 NIST Cybersecurity Framework GDPR HIPAA PCI-DSS SOX RBI and other regional regulatory requirements Conduct compliance assessments and readiness reviews for certifications and audits. Collaborate with business units to implement risk treatment and control improvement plans. 3. Security Controls & Policy Management Design, implement, and monitor security control frameworks across infrastructure, applications, cloud platforms, and business processes. Oversee periodic review and enhancement of security policies and procedures. Ensure organization-wide awareness and adherence to security standards. Lead control testing, effectiveness evaluations, and compliance validation activities. Monitor key security controls including: Identity and Access…