Contractor - GRC Job
Hyderabad, TG, IN Hyderabad, IN
YASH Technologies is a leading technology integrator specializing in helping clients reimagine operating models, enhance competitiveness, optimize costs, foster exceptional stakeholder experiences, and drive business transformation.
At YASH, we’re a cluster of the brightest stars working with cutting-edge technologies. Our purpose is anchored in a single truth – bringing real positive changes in an increasingly virtual world and it drives us beyond generational gaps and disruptions of the future.
We are looking forward to hire GRC Professionals in the following areas :
Senior Manager - Cybersecurity Governance, Risk & Compliance (GRC)
Location: Hyderabad, India
Shift: Night Shift (US Business Hours)
About the Role
We are seeking an experienced Cybersecurity Governance, Risk & Compliance (GRC) leader to drive enterprise-wide security governance, risk management, compliance, and cyber operations oversight. This role will act as a strategic partner to business, technology, audit, and compliance teams, operating in a capacity closely aligned with a CISO function while providing leadership across cybersecurity programs, process controls, regulatory compliance, third-party risk management, and security awareness initiatives.
The ideal candidate will have strong experience in regulated environments, including SOX, Data Privacy, FDA-regulated controls, cybersecurity governance, and risk management frameworks.
Key Responsibilities
Governance, Risk & Compliance
- Lead and mature the organization's cybersecurity governance and compliance programs.
- Establish, monitor, and improve security policies, standards, procedures, and control frameworks.
- Drive compliance with SOX, data privacy regulations, FDA requirements, and internal corporate policies.
- Partner with internal and external auditors to support audits, assessments, and remediation activities.
- Conduct control reviews and risk assessments across business processes and technology environments.
- Develop executive-level risk reporting, dashboards, and governance metrics.
Process & System Controls
- Oversee implementation and effectiveness of IT and business process controls.
- Ensure adequate control coverage across critical applications, infrastructure, and business processes.
- Monitor control deficiencies and drive corrective and preventive actions.
- Collaborate with business stakeholders to strengthen operational resilience and regulatory compliance.
Cybersecurity Operations & Risk Management
- Provide oversight and governance for cybersecurity operations.
- Review security incidents, vulnerabilities, threat trends, and remediation programs.
- Drive vulnerability management governance and track risk reduction initiatives.
- Support the development and execution of cybersecurity roadmaps and strategic initiatives.
- Ensure alignment with industry frameworks such as NIST, ISO 27001, CIS Controls, and related standards.
Third-Party & Supplier Risk Management
- Lead cybersecurity assessments of vendors, suppliers, and strategic partners.
- Establish and maintain third-party risk management processes.
- Evaluate security controls, contractual requirements, and risk mitigation plans for external partners.
- Monitor ongoing risk exposure associated with third-party relationships.
Cybersecurity Awareness & Culture
- Develop and manage enterprise security awareness and training programs.
- Drive a strong culture of cybersecurity and risk management across the organization.
- Partner with HR, Legal, Compliance, and Leadership teams to enhance employee awareness and engagement.
Stakeholder & Leadership Engagement
- Act as a trusted advisor to senior management on cybersecurity and compliance matters.
- Present risk and compliance updates to leadership and governance committees.
- Collaborate with global teams across multiple geographies and time zones.
- Influence strategic decision-making through risk-based recommendations.
Required Qualifications
- Bachelor's degree in Information Security, Computer Science, Engineering, or related field.
- 12+ years of experience in Cybersecurity, Risk Management, Compliance, Audit, or Information Security Governance.
- Strong experience with:
- SOX Compliance
- Data Privacy Regulations
At YASH, you are empowered to create a career that will take you to where you want to go while working in an inclusive team environment. We leverage career-oriented skilling models and optimize our collective intelligence aided with technology for continuous learning, unlearning, and relearning at a rapid pace and scale.
Our Hyperlearning workplace is grounded upon four principles
- Flexible work arrangements, Free spirit, and emotional positivity
- Agile self-determination, trust, transparency, and open collaboration
- All Support needed for the realization of business goals,
- Stable employment with a great atmosphere and ethical corporate culture