





Tier-1 brand and Bangalore metro increase competition; specialized GRC focus reduces generalist applicant pool.
Role requires domain-specific GRC/security and cloud experience, so cross-industry transferability is limited.
Mandatory 8+ years, ISO/SOC2 expertise, and specific GRC tooling requirements make shortlisting highly strict.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Lead end-to-end third-party security risk assessments and SaaS vendor reviews to minimize supply chain vulnerabilities.
Own the enterprise security exception lifecycle and risk register, collaborating with technical teams to evaluate controls and track remediation.
Drive security awareness programs, phishing campaigns, compliance audits (ISO 27001, SOC 2), and mature GRC platform workflows for automation and risk visibility.
8+ years experience in governance, risk, compliance (GRC), information security, IT audit, or third-party risk management in global technology or cloud environments.
Expertise with risk identification, exception lifecycle management, control mapping, and vendor security assessments aligned with ISO 27001, SOC 2, NIST, or CIS Controls.
Proficiency in GRC platforms and tools such as ServiceNow IRM, Jira, and Graphite Connect.
Mandatory in-office work from Bangalore location per company policy.
Experienced in coordinating complex risk and compliance projects across multiple business units and regions.
Skilled in translating technical security risks into clear business impact and operational trade-offs for diverse stakeholders.
Autonomous practitioner capable of balancing stringent control discipline with business agility to improve global security maturity.