Back to Jobs

GRC Team Lead – Information Security & Data Privacy

Kizhakkambalam, Ernakulam, Kerala · Onsite Full-time 5+ Years Any UG/PG Direct Client hiring Posted today💰 INR Not a constraint for the right candidate / mo
Apply now

Must Have Skills

ISO/IEC 27001:2022 Implementation ISO/IEC 27001:2022 Auditing ISMS Design & Governance DPDPA 2023 Implementation Data Privacy & DPIA Risk Assessment & Risk Treatment ISO 27005 Annex A Controls Mapping Statement of Applicability (SoA) Internal Audit & External Audit Management NCR / CAPA Management Policy & Procedure Governance Client & Stakeholder Management GRC Team LeadershipISO/IEC 27001:2022 ImplementationISO/IEC 27001:2022 AuditingISMS Design & GovernanceDPDPA 2023 ImplementationData Privacy & DPIARisk Assessment & Risk TreatmentISO 27005Annex A Controls MappingStatement of Applicability (SoA)Internal Audit & External Audit ManagementNCR / CAPA ManagementPolicy & Procedure GovernanceClient & Stakeholder ManagementGRC Team LeadershipSOC 2 Type I & Type II PCI DSS v4.0 GDPR QSA Coordination CISM CISSP CRISC CISA IAPP CIPM / CIPP DPIA Practitioner

Preferred Skills

ISO/IEC 27001:2022 Implementation ISO/IEC 27001:2022 Auditing ISMS Design & Governance DPDPA 2023 Implementation Data Privacy & DPIA Risk Assessment & Risk Treatment ISO 27005 Annex A Controls Mapping Statement of Applicability (SoA) Internal Audit & External Audit Management NCR / CAPA Management Policy & Procedure Governance Client & Stakeholder Management GRC Team LeadershipISO/IEC 27001:2022 ImplementationISO/IEC 27001:2022 AuditingISMS Design & GovernanceDPDPA 2023 ImplementationData Privacy & DPIARisk Assessment & Risk TreatmentISO 27005Annex A Controls MappingStatement of Applicability (SoA)Internal Audit & External Audit ManagementNCR / CAPA ManagementPolicy & Procedure GovernanceClient & Stakeholder ManagementGRC Team LeadershipSOC 2 Type I & Type II PCI DSS v4.0 GDPR QSA Coordination CISM CISSP CRISC CISA IAPP CIPM / CIPP DPIA Practitioner

Lead Implementer & Auditor – ISO/IEC 27001:2022 & DPDPA 2023

GRC Team Lead – Information Security & Data Privacy

Location: Kizhakkambalam, Ernakulam, Kerala

Employment Type: Full-Time, Permanent

Experience: 5+ Years

Department: Information Security / GRC

Work Mode: On-site

Reports To: CISO / Head of Information Security

About the Organization

We are hiring on behalf of a specialized Information Security, GRC and Data Privacy organization serving businesses with cybersecurity, compliance, risk management, and privacy requirements.

The organization works with clients across information security frameworks, regulatory compliance, data protection, audit readiness, and security governance.

This is an opportunity to work in a leadership-oriented GRC role with direct exposure to enterprise clients, senior stakeholders, auditors, certification bodies, and evolving privacy regulations.

About the Role

We are looking for a senior Information Security & GRC professional to take ownership of the organization's ISO/IEC 27001:2022 and DPDPA 2023 programmes.

The role combines ISMS implementation, internal and external audits, risk management, privacy compliance, regulatory frameworks, client consulting, and GRC team leadership.

The ideal candidate should be capable of independently driving an ISMS programme, leading audit engagements, managing compliance gaps and corrective actions, and communicating security and privacy risks effectively to senior management.

Key Responsibilities

  1. ISO/IEC 27001:2022 – ISMS Leadership

  2. Lead the design, implementation, maintenance, and continual improvement of the ISO/IEC 27001:2022 ISMS.

  3. Conduct ISMS gap assessments and readiness assessments.

  4. Map ISO/IEC 27001:2022 Annex A controls to business and technology processes.

  5. Develop and maintain the Statement of Applicability (SoA).

  6. Drive control implementation and evidence readiness.

  7. Maintain ISMS policies, procedures, standards, and supporting documentation.

  8. Internal & External Audits

  9. Design and manage the internal information security audit programme.

  10. Prepare audit schedules, checklists, evidence requirements, and audit reports.

  11. Identify and document Non-Conformities (NCs) and observations.

  12. Drive corrective and preventive actions through closure.

  13. Coordinate with external auditors and certification bodies.

  14. Support Stage 1, Stage 2, and surveillance audits.

  15. Manage audit evidence and ensure timely responses to audit findings.

  16. Risk Management & ISO 27005

  17. Own and maintain the enterprise information security risk register.

  18. Conduct information security risk assessments.

  19. Develop risk treatment plans and monitor implementation.

  20. Assess residual risk and coordinate risk acceptance.

  21. Apply ISO 27005 principles to organizational risk management.

  22. Identify emerging information security, technology, and compliance risks.

  23. DPDPA 2023 & Data Privacy

  24. Lead implementation of the Digital Personal Data Protection Act (DPDPA) 2023 requirements.

  25. Map data fiduciary and data processor responsibilities.

  26. Develop and maintain privacy governance processes.

  27. Conduct and oversee Data Protection Impact Assessments (DPIAs).

  28. Maintain Records of Processing Activities (RoPA).

  29. Support consent management and data subject rights processes.

  30. Establish privacy breach response and grievance-redressal mechanisms.

  31. Coordinate with legal, technology, HR, and business teams on privacy requirements.

  32. GDPR Compliance

  33. Support GDPR compliance initiatives where applicable.

  34. Conduct privacy assessments and DPIAs.

  35. Review data processing activities and third-party data flows.

  36. Support data subject rights and privacy governance requirements.

  37. Integrate GDPR requirements with the organization's broader privacy and ISMS framework.

  38. PCI DSS v4.0

  39. Manage the PCI DSS v4.0 compliance lifecycle.

  40. Coordinate with Qualified Security Assessors (QSAs).

  41. Support SAQ / ROC activities and evidence preparation.

  42. Review cardholder data flows and relevant security controls.

  43. Coordinate with infrastructure and security teams on segmentation and control requirements.

  44. SOC 2 Compliance

  45. Support / lead SOC 2 Type I and Type II compliance activities.

  46. Map controls against applicable Trust Services Criteria.

  47. Coordinate evidence collection and control testing.

  48. Track observations, gaps, and remediation activities.

  49. Maintain compliance documentation and audit readiness.

  50. Policy & Governance

  51. Develop, review, and maintain information security and privacy policies.

  52. Establish appropriate procedures, standards, and guidelines.

  53. Manage document version control and periodic policy reviews.

  54. Ensure employee acknowledgement and policy awareness.

  55. Drive security awareness and privacy training programmes.

  56. GRC Team Leadership

  57. Lead, mentor, and develop the GRC team.

  58. Allocate projects and monitor delivery.

  59. Establish GRC processes, templates, and quality standards.

  60. Review team outputs and ensure timely completion of client engagements.

  61. Build internal capability across information security, privacy, risk, and compliance.

  62. Client & Stakeholder Management

  63. Lead client discussions related to GRC, information security, privacy, and compliance.

  64. Participate in project kick-offs, requirement discussions, audits, and review meetings.

  65. Translate technical and regulatory requirements into practical business recommendations.

  66. Coordinate with engineering, legal, IT, and business teams.

  67. Ensure timely resolution of client concerns and maintain strong stakeholder relationships.

  68. Executive & Regulatory Reporting

  69. Prepare management and board-level reports on:

  70. Security posture

  71. Risk exposure

  72. Compliance status

  73. Audit findings

  74. Remediation progress

  75. Privacy risks

  76. Present complex compliance and security matters in a clear business-oriented manner.

  77. Support regulatory and certification-body interactions where required.

Required Qualifications

  1. 5+ years of relevant experience in Information Security, GRC, IT Risk, Compliance, Data Privacy, or related areas.
  2. Proven hands-on experience implementing and auditing ISO/IEC 27001:2022.
  3. Strong practical experience in DPDPA 2023 / Data Privacy compliance.
  4. Experience managing internal and external security/compliance audits.
  5. Experience in risk assessment, treatment planning, and compliance governance.
  6. Strong documentation and stakeholder-management skills.
  7. Experience leading or mentoring GRC professionals.

Mandatory Certifications

Candidates should ideally hold relevant certifications from recognized/accredited bodies:

  1. ISO/IEC 27001:2022 Lead Implementer
  2. ISO/IEC 27001:2022 Lead Auditor
  3. DPDPA / Data Privacy Lead Implementer
  4. DPDPA / Data Privacy Compliance Auditor

Certifications from PECB, BSI, or equivalent accredited bodies will be preferred.

Must-Have Skills

  1. ISO/IEC 27001:2022 Implementation
  2. ISO/IEC 27001:2022 Auditing
  3. ISMS Design & Governance
  4. DPDPA 2023 Implementation
  5. Data Privacy & DPIA
  6. Risk Assessment & Risk Treatment
  7. ISO 27005
  8. Annex A Controls Mapping
  9. Statement of Applicability (SoA)
  10. Internal Audit & External Audit Management
  11. NCR / CAPA Management
  12. Policy & Procedure Governance
  13. Client & Stakeholder Management
  14. GRC Team Leadership

Good-to-Have Skills

  1. SOC 2 Type I & Type II
  2. PCI DSS v4.0
  3. GDPR
  4. QSA Coordination
  5. CISM
  6. CISSP
  7. CRISC
  8. CISA
  9. IAPP CIPM / CIPP
  10. DPIA Practitioner
  11. Regulatory / Board Reporting
  12. Security Awareness Programmes
  13. Third-Party Risk Management

Framework Experience

Candidates with practical experience in the following frameworks will be strongly preferred:

ISO/IEC 27001:2022

  1. ISMS implementation
  2. Annex A control mapping
  3. Gap assessment
  4. SoA preparation
  5. Internal audits
  6. Certification audits
  7. Surveillance audits

DPDPA 2023

  1. Data fiduciary / processor mapping
  2. DPIA
  3. RoPA
  4. Consent management
  5. Data subject rights
  6. Privacy breach response
  7. Grievance redressal

GDPR

  1. Privacy impact assessments
  2. Data processing assessments
  3. Data subject rights
  4. Privacy governance

SOC 2

  1. Trust Services Criteria
  2. Control mapping
  3. Evidence collection
  4. Type I / Type II audit readiness

PCI DSS v4.0

  1. SAQ / ROC
  2. Cardholder data flow
  3. Network segmentation
  4. Control evidence
  5. QSA coordination

Preferred Candidate Profile

We are looking for a hands-on GRC leader, not someone limited to documentation or audit coordination.

The ideal candidate should be able to independently:

  1. Design and implement an ISMS.
  2. Conduct internal audits.
  3. Prepare an organization for external certification audits.
  4. Manage NCRs and CAPA.
  5. Conduct information security risk assessments.
  6. Implement DPDPA privacy controls.
  7. Conduct DPIAs and maintain RoPA.
  8. Handle client and senior stakeholder discussions.
  9. Lead a small GRC team.
  10. Translate regulatory requirements into practical controls.

Please fill the screening answers to the point

Apply to this job

Required — upload a file or paste the text