Lead - Governance, Risk and Compliance

🗓️ Posted 2026-07-19 Gurugram, Haryana, India Full-time Hybrid ICT

Company shared salary

NA

Market rate

₹375,000–₹625,000/mo (₹4,500,000–₹7,500,000/yr)

Based on similar roles (title + domain + location).

Responsibilities

  • The Lead - Infosec Governance, Risk & Compliance (GRC) will be responsible for establishing, managing, and continuously enhancing the Information Security Governance, Risk Management, Compliance, programs across the NBFC. The role will ensure alignment with RBI regulations, applicable laws, industry security standards, and business objectives while driving a strong security and risk-aware culture across the organization.
  • The incumbent will act as the primary custodian of Information Security policies, cyber risk management, regulatory compliance, third-party risk governance, security awareness, audit management, and GRC transformation initiatives.
  • Develop, implement, and maintain the Information Security Governance framework.
  • Define and manage information security policies, standards, procedures, and guidelines.
  • Establish security committees, governance forums, and reporting mechanisms.
  • Present cyber risk posture, compliance status, and key metrics to executive leadership and Board committees.
  • Drive enterprise-wide security awareness and security culture initiatives.
  • Own and manage the Information Security Risk Management Framework.
  • Conduct enterprise cyber risk assessments and periodic reviews.
  • Facilitate risk identification, treatment, mitigation, acceptance, and monitoring processes.
  • Maintain the cyber risk register and track remediation activities.
  • Quantify and communicate cyber risks to senior management and stakeholders.
  • Ensure compliance with RBI Master Directions, Digital Lending Guidelines, IT Governance requirements, Cyber Security Frameworks, and applicable regulatory directives.
  • Manage compliance with:
  • RBI regulations
  • Information Technology Act
  • CERT-In Directions
  • NPCI security requirements
  • UIDAI Requirements
  • IRDAI Requirements
  • Establish compliance monitoring and reporting mechanisms.
  • Coordinate regulatory inspections and responses.
  • Lead Information Security audits, internal audits, statutory audits, and regulatory audits.
  • Manage external assessments including:
  • ISO 27001
  • PCI DSS (where applicable)
  • SOC Assessments
  • Track observations and ensure timely closure of audit findings.
  • Prepare management and Board-level audit updates.
  • Define and monitor Information Security KPIs and KRIs.
  • Develop executive dashboards for leadership and Board reporting.
  • Analyze security compliance trends and risk posture.
  • Prepare periodic reports for management committees.
  • Establish and operate Third-Party Risk Management (TPRM) programs.
  • Perform security due diligence of vendors, partners, fintechs, cloud providers, and service providers.
  • Review vendor security controls, contracts, SLAs, and compliance evidence.
  • Monitor supply chain cyber risk and remediation activities.
  • Lead implementation and maintenance of:
  • ISO 27001:2022
  • NIST Cybersecurity Framework

Requirements

  • Bachelor's degree or higher
  • ISO 27001 LA/LI, CISA, CRISC, ITIL certifications are preferred
  • 12 to 16 years
  • Minimum 5 years in Information Security Governance, Risk & Compliance.
  • Experience within NBFC, Banking, FinTech, Payments, Insurance, or Financial Services preferred
  • Information Security Governance, Enterprise Risk Management, Cyber Risk Quantification, Regulatory Compliance Management, RBI Regulatory Requirements, ISO 27001:2022, NIST CSF, Third-Party Risk Management, Audit & Assurance Management, Security Metrics & Reporting