GRC Team Lead – Information Security & Data Privacy
Must Have Skills
Preferred Skills
Lead Implementer & Auditor – ISO/IEC 27001:2022 & DPDPA 2023
GRC Team Lead – Information Security & Data Privacy
Location: Kizhakkambalam, Ernakulam, Kerala
Employment Type: Full-Time, Permanent
Experience: 5+ Years
Department: Information Security / GRC
Work Mode: On-site
Reports To: CISO / Head of Information Security
About the Organization
We are hiring on behalf of a specialized Information Security, GRC and Data Privacy organization serving businesses with cybersecurity, compliance, risk management, and privacy requirements.
The organization works with clients across information security frameworks, regulatory compliance, data protection, audit readiness, and security governance.
This is an opportunity to work in a leadership-oriented GRC role with direct exposure to enterprise clients, senior stakeholders, auditors, certification bodies, and evolving privacy regulations.
About the Role
We are looking for a senior Information Security & GRC professional to take ownership of the organization's ISO/IEC 27001:2022 and DPDPA 2023 programmes.
The role combines ISMS implementation, internal and external audits, risk management, privacy compliance, regulatory frameworks, client consulting, and GRC team leadership.
The ideal candidate should be capable of independently driving an ISMS programme, leading audit engagements, managing compliance gaps and corrective actions, and communicating security and privacy risks effectively to senior management.
Key Responsibilities
-
ISO/IEC 27001:2022 – ISMS Leadership
-
Lead the design, implementation, maintenance, and continual improvement of the ISO/IEC 27001:2022 ISMS.
-
Conduct ISMS gap assessments and readiness assessments.
-
Map ISO/IEC 27001:2022 Annex A controls to business and technology processes.
-
Develop and maintain the Statement of Applicability (SoA).
-
Drive control implementation and evidence readiness.
-
Maintain ISMS policies, procedures, standards, and supporting documentation.
-
Internal & External Audits
-
Design and manage the internal information security audit programme.
-
Prepare audit schedules, checklists, evidence requirements, and audit reports.
-
Identify and document Non-Conformities (NCs) and observations.
-
Drive corrective and preventive actions through closure.
-
Coordinate with external auditors and certification bodies.
-
Support Stage 1, Stage 2, and surveillance audits.
-
Manage audit evidence and ensure timely responses to audit findings.
-
Risk Management & ISO 27005
-
Own and maintain the enterprise information security risk register.
-
Conduct information security risk assessments.
-
Develop risk treatment plans and monitor implementation.
-
Assess residual risk and coordinate risk acceptance.
-
Apply ISO 27005 principles to organizational risk management.
-
Identify emerging information security, technology, and compliance risks.
-
DPDPA 2023 & Data Privacy
-
Lead implementation of the Digital Personal Data Protection Act (DPDPA) 2023 requirements.
-
Map data fiduciary and data processor responsibilities.
-
Develop and maintain privacy governance processes.
-
Conduct and oversee Data Protection Impact Assessments (DPIAs).
-
Maintain Records of Processing Activities (RoPA).
-
Support consent management and data subject rights processes.
-
Establish privacy breach response and grievance-redressal mechanisms.
-
Coordinate with legal, technology, HR, and business teams on privacy requirements.
-
GDPR Compliance
-
Support GDPR compliance initiatives where applicable.
-
Conduct privacy assessments and DPIAs.
-
Review data processing activities and third-party data flows.
-
Support data subject rights and privacy governance requirements.
-
Integrate GDPR requirements with the organization's broader privacy and ISMS framework.
-
PCI DSS v4.0
-
Manage the PCI DSS v4.0 compliance lifecycle.
-
Coordinate with Qualified Security Assessors (QSAs).
-
Support SAQ / ROC activities and evidence preparation.
-
Review cardholder data flows and relevant security controls.
-
Coordinate with infrastructure and security teams on segmentation and control requirements.
-
SOC 2 Compliance
-
Support / lead SOC 2 Type I and Type II compliance activities.
-
Map controls against applicable Trust Services Criteria.
-
Coordinate evidence collection and control testing.
-
Track observations, gaps, and remediation activities.
-
Maintain compliance documentation and audit readiness.
-
Policy & Governance
-
Develop, review, and maintain information security and privacy policies.
-
Establish appropriate procedures, standards, and guidelines.
-
Manage document version control and periodic policy reviews.
-
Ensure employee acknowledgement and policy awareness.
-
Drive security awareness and privacy training programmes.
-
GRC Team Leadership
-
Lead, mentor, and develop the GRC team.
-
Allocate projects and monitor delivery.
-
Establish GRC processes, templates, and quality standards.
-
Review team outputs and ensure timely completion of client engagements.
-
Build internal capability across information security, privacy, risk, and compliance.
-
Client & Stakeholder Management
-
Lead client discussions related to GRC, information security, privacy, and compliance.
-
Participate in project kick-offs, requirement discussions, audits, and review meetings.
-
Translate technical and regulatory requirements into practical business recommendations.
-
Coordinate with engineering, legal, IT, and business teams.
-
Ensure timely resolution of client concerns and maintain strong stakeholder relationships.
-
Executive & Regulatory Reporting
-
Prepare management and board-level reports on:
-
Security posture
-
Risk exposure
-
Compliance status
-
Audit findings
-
Remediation progress
-
Privacy risks
-
Present complex compliance and security matters in a clear business-oriented manner.
-
Support regulatory and certification-body interactions where required.
Required Qualifications
- 5+ years of relevant experience in Information Security, GRC, IT Risk, Compliance, Data Privacy, or related areas.
- Proven hands-on experience implementing and auditing ISO/IEC 27001:2022.
- Strong practical experience in DPDPA 2023 / Data Privacy compliance.
- Experience managing internal and external security/compliance audits.
- Experience in risk assessment, treatment planning, and compliance governance.
- Strong documentation and stakeholder-management skills.
- Experience leading or mentoring GRC professionals.
Mandatory Certifications
Candidates should ideally hold relevant certifications from recognized/accredited bodies:
- ISO/IEC 27001:2022 Lead Implementer
- ISO/IEC 27001:2022 Lead Auditor
- DPDPA / Data Privacy Lead Implementer
- DPDPA / Data Privacy Compliance Auditor
Certifications from PECB, BSI, or equivalent accredited bodies will be preferred.
Must-Have Skills
- ISO/IEC 27001:2022 Implementation
- ISO/IEC 27001:2022 Auditing
- ISMS Design & Governance
- DPDPA 2023 Implementation
- Data Privacy & DPIA
- Risk Assessment & Risk Treatment
- ISO 27005
- Annex A Controls Mapping
- Statement of Applicability (SoA)
- Internal Audit & External Audit Management
- NCR / CAPA Management
- Policy & Procedure Governance
- Client & Stakeholder Management
- GRC Team Leadership
Good-to-Have Skills
- SOC 2 Type I & Type II
- PCI DSS v4.0
- GDPR
- QSA Coordination
- CISM
- CISSP
- CRISC
- CISA
- IAPP CIPM / CIPP
- DPIA Practitioner
- Regulatory / Board Reporting
- Security Awareness Programmes
- Third-Party Risk Management
Framework Experience
Candidates with practical experience in the following frameworks will be strongly preferred:
ISO/IEC 27001:2022
- ISMS implementation
- Annex A control mapping
- Gap assessment
- SoA preparation
- Internal audits
- Certification audits
- Surveillance audits
DPDPA 2023
- Data fiduciary / processor mapping
- DPIA
- RoPA
- Consent management
- Data subject rights
- Privacy breach response
- Grievance redressal
GDPR
- Privacy impact assessments
- Data processing assessments
- Data subject rights
- Privacy governance
SOC 2
- Trust Services Criteria
- Control mapping
- Evidence collection
- Type I / Type II audit readiness
PCI DSS v4.0
- SAQ / ROC
- Cardholder data flow
- Network segmentation
- Control evidence
- QSA coordination
Preferred Candidate Profile
We are looking for a hands-on GRC leader, not someone limited to documentation or audit coordination.
The ideal candidate should be able to independently:
- Design and implement an ISMS.
- Conduct internal audits.
- Prepare an organization for external certification audits.
- Manage NCRs and CAPA.
- Conduct information security risk assessments.
- Implement DPDPA privacy controls.
- Conduct DPIAs and maintain RoPA.
- Handle client and senior stakeholder discussions.
- Lead a small GRC team.
- Translate regulatory requirements into practical controls.
Please fill the screening answers to the point
Screening questions
Asked of every applicant before they can apply.
