Job Description – Security Governance & Risk Leader
Position Title
Security Governance, Risk
& Compliance (GRC) Leader
Department
Information Security / Technology
Reports To
Chief Information Security Officer (CISO) /
Chief Information Officer (CIO)/VP IT infrastructure and Information security
Position Summary
The Security Governance, Risk & Compliance
(GRC) Leader is responsible for establishing and maintaining a robust security
governance framework that aligns cybersecurity initiatives with organizational
objectives, regulatory requirements, and industry best practices. This role
provides strategic leadership for information security governance, risk
management, compliance, policy administration, audit readiness, and security
oversight across the enterprise.
The incumbent will work closely with executive
leadership, business stakeholders, IT teams, auditors, regulators, and
third-party partners to ensure that security risks are effectively managed,
compliance obligations are met, and security controls support business growth
while protecting organizational assets.
Key Responsibilities
1. Security Governance & Strategy
- Develop and implement enterprise-wide
cybersecurity governance frameworks aligned with business objectives and
regulatory requirements.
- Define, maintain, and enforce information
security policies, standards, procedures, and guidelines.
- Establish governance structures, security
committees, and reporting mechanisms to support security oversight.
- Partner with executive leadership to
align security strategy with organizational goals and risk appetite.
- Develop security roadmaps and maturity
improvement programs based on industry frameworks and emerging threats.
- Present security governance updates, risk
posture, and compliance status to executive management and board
committees.
2. Security Risk Management & Compliance
- Establish and maintain an enterprise
information security risk management framework.
- Identify, assess, monitor, and mitigate
cybersecurity risks affecting business operations and technology
environments.
- Maintain security risk registers and
track remediation activities to closure.
- Ensure compliance with applicable
regulatory, legal, and contractual requirements, including:
- ISO 27001
- NIST Cybersecurity
Framework
- GDPR
- HIPAA
- PCI-DSS
- SOX
- RBI and other regional
regulatory requirements
- Conduct compliance assessments and
readiness reviews for certifications and audits.
- Collaborate with business units to
implement risk treatment and control improvement plans.
3. Security Controls & Policy Management
- Design, implement, and monitor security
control frameworks across infrastructure, applications, cloud platforms,
and business processes.
- Oversee periodic review and enhancement
of security policies and procedures.
- Ensure organization-wide awareness and
adherence to security standards.
- Lead control testing, effectiveness
evaluations, and compliance validation activities.
- Monitor key security controls including:
- Identity and Access
Management (IAM)
- Privileged Access
Management (PAM)
- Change Management
- Data Protection
- Endpoint Security
- Cloud Security Controls
- Business Continuity and
Disaster Recovery
4. Information Security Governance & Security Oversight
- Collaborate with the CISO and security
operations teams to drive cybersecurity governance initiatives.
- Monitor compliance with internal security
standards and industry best practices.
- Oversee security assessment programs
including:
- Vulnerability Assessments
- Penetration Testing
- Security Architecture
Reviews
- Cybersecurity Maturity
Assessments
- Support security incident management and
crisis response governance processes.
- Review threat intelligence, emerging
risks, and cybersecurity trends to strengthen organizational resilience.
- Ensure periodic reporting of security
metrics, risks, incidents, and remediation activities.
5. Security Program & Operational Governance
- Establish governance frameworks for
security initiatives, projects, and transformation programs.
- Oversee security budgeting, planning, and
resource prioritization.
- Monitor vendor security performance and
third-party risk management programs.
- Ensure security requirements are
integrated into technology projects and procurement processes.
- Track security KPIs, KRIs, and
service-level metrics to drive continuous improvement.
- Evaluate effectiveness of security
investments and governance programs.
6. Audit Management & Regulatory Coordination
- Act as the primary liaison for internal
and external security audits.
- Coordinate audit planning, evidence
collection, and stakeholder engagement activities.
- Review audit findings and develop
remediation plans.
- Ensure timely closure of audit
observations and compliance gaps.
- Support regulatory examinations and
customer security assessments.
- Maintain documentation required for
compliance certifications and governance reviews.
7. Stakeholder Management & Leadership
- Serve as the key liaison between
Information Security, IT, Risk, Legal, Compliance, Audit, and Business
Units.
- Build strong relationships with executive
leadership and business stakeholders.
- Promote a culture of security awareness,
accountability, and compliance throughout the organization.
- Lead and mentor governance, risk, and
compliance teams.
- Drive security training, awareness, and
communication initiatives across the enterprise.
- Provide strategic recommendations to
leadership regarding security investments, risk mitigation, and governance
improvements.
Requirements
Qualifications & Experience
Education
- Bachelor's Degree in Computer Science,
Information Technology, Cybersecurity, Information Systems, or a related
discipline.
- Master's Degree (MBA, MS Information
Security, or equivalent) preferred.
Experience
- 12+ years of experience in Information
Security, IT Governance, Risk Management, Audit, or Compliance.
- Minimum 5+ years in a leadership or
management role within Security Governance, Risk, and Compliance.
- Proven experience implementing and
managing enterprise security governance frameworks.
- Hands-on experience managing security
audits, risk assessments, compliance programs, and security control
frameworks.
- Strong understanding of enterprise
technology environments, cloud security, cybersecurity operations, and
regulatory requirements.
Preferred Certifications
- Certified Information Security Manager
(CISM)
- Certified Information Systems Auditor
(CISA)
- Certified in Risk and Information Systems
Control (CRISC)
- Certified Information Systems Security
Professional (CISSP)
- COBIT Foundation / Design &
Implementation
- ISO 27001 Lead Auditor or Lead
Implementer
- ITIL Foundation or Expert
- Certified Cloud Security Professional
(CCSP) – Preferred
Key Competencies
Leadership
& Strategy
- Strategic thinking and business alignment
- Executive presence and influencing skills
- Decision-making and governance leadership
Risk &
Compliance
- Security risk assessment and mitigation
- Regulatory compliance management
- Control design and validation
Technical
Knowledge
- Information security frameworks and
standards
- Cybersecurity governance and operations
- Cloud security and data protection
Communication
& Collaboration
- Stakeholder management
- Board and executive reporting
- Negotiation and conflict resolution
- Presentation and communication excellence
Operational
Excellence
- Program and project governance
- Process improvement and optimization
- Performance measurement and reporting
Key Performance Indicators (KPIs)
Governance
& Compliance
- Audit compliance score
- Number of repeat audit findings
- Timely closure of audit observations
- Regulatory compliance adherence rate
Risk
Management
- Reduction in high-risk findings
- Risk remediation closure percentage
- Security control effectiveness scores
- Risk assessment completion rates
Security
Program Effectiveness
- Security maturity assessment improvement
- Security policy compliance rate
- Third-party risk assessment completion
rate
- Vulnerability remediation performance
Operational
Metrics
- SLA adherence for security governance
activities
- Budget utilization and optimization
- Security project delivery success rate
- Service delivery performance metrics
Stakeholder
Satisfaction
- Business stakeholder satisfaction score
- Executive reporting effectiveness
- Security awareness adoption metrics
- Alignment of security initiatives with
business objectives
Job Level: Senior Manager / Director / Head of
Information Security Governance & Risk Management