← Back to Jobs

Lead InfoSec Audit and GRC

Experience : 7-10 Years Project Location(s) : Trivandrum / Kochi

Work mode: Hybrid/ Remote ( Quarterly 5 days in office for Remote Employees)

Number of Openings: 1

Risk Management

  • Lead Information Security and IT risk management activities across the organisation.
  • Oversee identification, assessment, treatment and ongoing monitoring of information security risks.
  • Provide independent risk advisory to Risk Owners, business and technology stakeholders.
  • Monitor residual risk, emerging threats, risk trends and overall organisational risk exposure.
  • Report the Information Security risk posture, material risks and key risk indicators to Senior Management.

Compliance & Regulatory Management

  • Govern the organisation’s continuous compliance and assurance readiness across ISO 27001, ISO 42001, SOC 2 and PCI DSS.
  • Maintain alignment with applicable GDPR, HIPAA, contractual and other regulatory requirements.
  • Oversee compliance assessments, control-gap analysis and remediation of identified deficiencies.
  • Maintain an integrated control framework and control mappings across GRC platforms including Vanta and Drata.
  • Ensure the control environment evolves in line with regulatory developments, emerging AI governance requirements and changes to the organisation’s risk profile.

Audit & Assurance Management

  • Lead the organisation’s year-round Information Security audit and assurance programme.
  • Conduct internal Information Security audits and coordinate external audits, certification assessments and independent assurance engagements.
  • Provide assurance across ISO 27001, ISO 42001, SOC 2 and PCI DSS requirements.
  • Oversee periodic security assurance reviews across enterprise and third-party technology environments.
  • Maintain governance over the complete audit lifecycle and provide independent advisory on findings, corrective actions and compensating controls.
  • Provide assurance over the adequacy and effectiveness of remediation arising from audit and security-review activities.

Security Control Assurance

  • Govern the design, implementation control framework.
  • Assess control effectiveness and identify material control deficiencies or areas requiring enhancement.
  • Work with Control Owners and relevant stakeholders to drive sustainable remediation of control gaps.
  • Define additional, compensating or custom controls where required to address identified risk.
  • Maintain oversight of the organisation’s overall control-effectiveness posture. Policy & GRC Governance
  • Own the development, maintenance and governance of Information Security policies, standards and supporting frameworks.
  • Ensure the policy framework remains aligned with business objectives, security risks and applicable regulatory and assurance requirements.
  • Govern policy ownership, periodic review, exceptions and associated risk acceptance.
  • Maintain clear security governance, accountability and control ownership across the organisation.

Third-Party Risk Management

  • Manage Information Security risk n and ongoing effectiveness of the organisation’s Information Security management across the third-party tools used by the organization.
  • Oversee security due diligence, risk assessment and periodic assurance of critical and relevant third parties.
  • Assess third-party control environments and residual security risk based on independent assurance and other relevant evidence.
  • Provide risk advisory on third-party remediation, compensating controls and risk-treatment decisions.
  • Oversee security due diligence, risk assessment and periodic assurance of vendors, service providers and third-party applications. Customer Security Assurance & Trust Centre
  • Lead customer-facing Information Security assurance and due-diligence activities.
  • Provide governance over the organisation’s security and compliance assurance information provided to customers and external stakeholders.
  • Build and maintain the organisation’s Trust Centre as the authoritative source for security, privacy and compliance assurance.
  • Ensure customer assurance commitments remain consistent with the organisation’s actual control and compliance posture.

Data Security & Governance

  • Provide governance and assurance over enterprise data-security and data-protection controls.
  • Oversee data classification, information protection, Data Loss Prevention and related data-security requirements.
  • Govern the use of Microsoft Purview and associated data-protection capabilities as part of the broader Information Security control environment.
  • Assess data-security risks and provide assurance over the effectiveness of associated controls.
  • Ensure data-security governance remains aligned with applicable security, privacy and regulatory requirements.

Reporting & Senior Management Assurance

  • Provide independent reporting to Senior Management on the organisation’s Information Security risk, compliance, audit and control-assurance posture.
  • Establish meaningful KPIs, KRIs, metrics and assurance scorecards to measure the effectiveness of the GRC programme.
  • Highlight material risks, control weaknesses, compliance exposures and significant remediation concerns requiring management attention.
  • Provide consolidated assurance and recommendations to support risk-based Senior Management decision-making.

Preferred Skills

  • Experience with GRC and compliance platforms such as Vanta and Drata.
  • Understanding of AI governance and evolving AI regulatory requirements.
  • Knowledge of enterprise data-security governance, Microsoft Purview and Data Loss Prevention.
  • Strong stakeholder management, risk advisory and Senior Management reporting capabilities.

InApp India Office

121 Nila, Technopark Campus
Trivandrum, Kerala 695581
+91 (471) 277 -1800
mktg@inapp.com

InApp USA Office

999 Commercial St. Ste 210 Palo Alto, CA 94303
+1 (650) 283-7833
mktg@inapp.com

InApp Japan Office

6-12 Misuzugaoka, Aoba-ku
Yokohama,225-0016
+81-45-978-0788
mktg@inapp.com
Terms Of Use
© 2000-2026 InApp, All Rights Reserved
Upcoming Events
Join Raleigh-Area Leaders on September 24 Request Your Seat → Raleigh Roundtable | Request Your Seat → Going to APHSA ISM 2026? Meet InApp at Booth 822. Schedule a Meeting → APHSA ISM 2026 | Meet InApp →