Hiring.Camp

GRC Lead

Qualys Careers

·

Mar 26, 2026

Location
Pune, India
Workplace
Hybrid
Type
Full-time
Seniority
Lead
Experience
8+ years
Source
Workday

Description

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

Job Description: GRC Lead

Role Title: Governance, Risk & Compliance (GRC) Lead
Department: Security Operations- Governance, Risk and Compliance (GRC)
Reporting To: Manager – GRC
Location: Pune (Hybrid)

Experience: 8–10 years

Role Type: Full‑time

Role Overview

The GRC Lead is responsible for establishing, leading, and continuously improving the organization’s Governance, Risk, and Compliance framework across technology, information security, and business operations. This role ensures alignment with regulatory requirements, industry standards, and organizational risk appetite while enabling business growth and resilience.

The GRC Lead partners closely with technology, security, legal, compliance, internal audit, procurement, and business stakeholders to proactively identify, assess, mitigate, and monitor risks, including third‑party, cyber, regulatory, and operational risks.

Key Responsibilities

Governance & Policy Management

  • Define and maintain enterprise‑level GRC frameworks, policies, standards, and procedures
  • Establish governance structures for risk ownership, escalation, and decision‑making
  • Ensure alignment between business objectives, risk appetite, and control frameworks
  • Drive security and risk awareness across the organization

Risk Management

  • Lead the enterprise and technology risk assessment lifecycle (identification, assessment, treatment, monitoring)
  • Own risk registers and ensure risks are tracked, reviewed, and mitigated effectively
  • Support risk quantification and scenario analysis where applicable
  • Report risk posture to senior leadership and governance committees
  • Integrate risk management into SDLC, cloud adoption, and digital initiatives

Compliance & Assurance

  • Ensure compliance with applicable laws, regulations, and standards, such as:
    • ISO 27001 / ISO 27701
    • NIST CSF / NIST 800‑53
    • SOC 1 / SOC 2
    • GDPR, DPDP Act, HIPAA, PCI DSS (as applicable)
  • Coordinate internal and external audits; manage audit responses and remediation
  • Maintain compliance evidence and documentation
  • Track regulatory changes and assess business impact

Third‑Party & Vendor Risk Management

  • Design and operate the Third‑Party Risk Management (TPRM) program
  • Conduct vendor risk assessments, including cybersecurity, operational, and data privacy risks
  • Partner with procurement, legal, and business owners on onboarding and renewals
  • Monitor critical vendors and ensure remediation of identified issues

Metrics, Reporting & Continuous Improvement

  • Define and track GRC KPIs and KRIs
  • Develop dashboards and executive‑level risk reports
  • Mature GRC processes through automation and GRC tooling
  • Benchmark program maturity against industry best practices

Leadership & Stakeholder Management

  • Act as a trusted advisor to executive leadership and business teams
  • Lead and mentor GRC analysts and specialists (if applicable)
  • Influence without authority across technical and non‑technical teams

Required Qualifications

Education

  • Bachelor’s degree in Information Technology, Cybersecurity, Risk Management, Law, or related field
  • Master’s degree preferred

Experience

  • 8–12+ years of experience in GRC, technology risk, cybersecurity, or compliance
  • Proven experience leading or managing enterprise‑scale GRC programs
  • Hands‑on experience with audits, risk assessments, and regulatory engagements
  • Experience working with global or regulated environments preferred

Technical & Professional Skills

  • Strong knowledge of:
    • IT risk, cybersecurity risk, and control frameworks
    • Regulatory compliance and audit practices
    • Third‑party risk management
  • Experience with GRC tools (e.g., ServiceNow GRC, RSA Archer, MetricStream, OneTrust)
  • Ability to translate technical risks into business impact
  • Excellent written and verbal communication skills
  • Strong stakeholder management and influencing skills

Certifications (Preferred)

  • CRISC, CISA, CISM
  • ISO 27001 Lead Implementer / Lead Auditor
  • CISSP (desirable)
  • FAIR or risk quantification certifications (optional but valued)

Skills

ServiceNowCybersecuritySOCRisk ManagementComplianceProcurementSOC 2HIPAAGDPRISO 27001CISSP

Similar Jobs

30

Compliance Lead (GRC)

BETSOL · Bengaluru, KA, India

2 days ago

CIT Information Security & GRC, Lead

Talentmanagementsolution · Markham, Ontario - CAN, Canada

3 days ago

Cybersecurity Governance and Risk Management (GRC) Lead

ERP International · Laurel, MD, US

3 days ago

SAP GRC Lead

Gafsgi · GAF Headquarters, United States of America

1 week ago

Associate General Manager – GRC Lead

Adani · Ahmedabad, Gujarat, India

2 weeks ago

Triton Cybersecurity GRC Lead

Northrop Grumman · Edinburgh, SA,AU, AU

2 weeks ago

Triton Cybersecurity GRC Lead

Northrop Grumman · A601 AUS - SA - Edinburgh, Australia

2 weeks ago

TECH LEAD - GRC ENGINEERING

Bdc · Montreal, Canada · Hybrid

3 weeks ago

Security GRC Lead

Salesforce · Virginia - Herndon, United States of America +2 · Onsite

1 month ago

IT GRC Lead Analyst

Westfield · Westfield Center, OH, United States, US · Hybrid

1 month ago

IT GRC Lead Analyst

Westfield Insurance · Westfield Center, OH, United States, US · Hybrid

1 month ago

Lead GRC Analyst (IT/Security)

Default Brand · Manor, TX

1 month ago

Senior Security GRC Lead

Gong.io · Austin | Chicago | New York City | Salt Lake City | San Francisco +1 · onsite

1 month ago

Security Lead (GRC & AppSec)

Innovapptive · Hyderabad, Telangana

2 months ago

Head of Security Governance — Deputy CISO — GRC lead (x/f/m)

Alan · Anywhere in France · Hybrid

2 months ago

Business Relationship Officer - Security & GRC Lead

Ivlglobaliod · IND-Mumbai, India

2 months ago

Security Compliance & GRC Lead Bengaluru, Karnataka, India

Cybrilla · Remote

3 months ago

Lead GRC Engineer AI & Automation

Micron · Hyderabad - Phoenix Aquila, India

3 months ago

Governance, Risk & Compliance (GRC) Lead

Glen Dimplex Europe Holdings Ltd · Cloghran, Dublin, Ireland

3 months ago

Senior GRC Lead

Brex · Remote, Hybrid, Onsite

7 months ago

Senior GRC Lead

Brex · Remote, Hybrid, Onsite

7 months ago

IT Security & GRC (Lead/Manager)

Cermati.com · Jakarta, Jakarta, Indonesia

1+ year ago

Lead Product GRC Subject Matter Expert

Vanta · Remote U.S. · Remote

2 days ago

SAP GRC ARCHITECT & LEAD CONSULTANT – INGLES – REMOTO

IRIUM - Spain · ESPAÑA, ESPAÑA

3 days ago

Cybersecurity GRC Operational Lead

Electrolux · SE-STO-001, Sweden

1 week ago

GRC Team Lead

CapTech Ventures · Richmond, VA, United States · Remote

1 month ago

GRC & Privacy Lead

Mitigata · Bangalore, Karnataka, India

1 month ago

Lead Analyst - GRC

Mattel · Hyderabad, India

2 months ago

Cybersecurity GRC Compliance Lead

NT Careers · Chicago, IL, United States of America

3 months ago

IT Governance, Risk & Audit Lead (IT GRC)

Careerally Pte Ltd · Singapore

6 months ago