Information Security – Risk Manager – GRC

4 days ago


Delhi, Delhi, India SMC Group Full time

Started in the year 1990, SMC is a well-diversified financial service company in India & Abroad, offering one stop investment solutions in trading & investments. SMC believes in growing with its clients and creating valuable relationships. It's about having the passion to go that extra mile and it's about making the clients and partners a part of the family.

SMC offers advanced broking services across equity, derivative, currency and commodity asset classes, financial analytics, mortgage advisory, investment banking and executions in cash & future equities.

Specialties: -

Equity, Commodity & Currency trading, IPO & MF Distribution, Depository, Clearing Services, Research, Insurance Broking - Life & Non-Life, Wealth Advisory, Institutional Broking, Investment Banking, Real Estate Advisory, Mortgage Advisory, NBFC Financing, and AIF

Hiring for Information Security – Risk Manager – GRC (BCP & ISO 27001:2022 Implementation)

Experience required for the Job:
5 - 10 years

Job Location:
Delhi

Position/Title:
Risk Manager – GRC

Job Summary:

The
Risk Manager – GRC (ISO 27001:2022 & BCP)
is responsible for overseeing the implementation, maintenance, and continual improvement of the Information Security Management System (ISMS) in alignment with
ISO 27001:2022 standards
. This role ensures that the organization's information security practices meet regulatory requirements, client expectations, and industry best practices, while also mitigating risks to the confidentiality, integrity, and availability of information.

Education:

  • Bachelor's degree in Information Security, Computer Science, or a related field.
  • A Master's degree is a plus.

Experience:

  • 5+ years of experience in information security management, with a focus on ISO 27001 implementation and compliance.
  • Proven experience in leading ISMS implementation and managing information security compliance audits.

Certifications:

  • ISO 27001 Lead Implementer or Lead Auditor certification.
  • Additional certifications such as CISSP, CISM, or CISA are advantageous.

Skills:

  • In-depth knowledge of ISO 27001:2022 standards and information security best practices.
  • Strong understanding of risk management and incident management processes.
  • Excellent communication, documentation, and project management skills.
  • Ability to work collaboratively with cross-functional teams and influence decision-making.
  • Knowledgeable and experienced in crisis management best practices.
  • Experience with cloud (AWS) environments, SaaS provider architecture, and cloud-based disaster recovery methodologies.

Key Responsibilities:

1. ISMS Implementation & Maintenance

  • Lead the development, implementation, and continuous improvement of the Information Security Management System (ISMS) in accordance with ISO 27001:2022 standards.
  • Ensure that all policies, procedures, and controls are documented, communicated, and enforced throughout the organization.
  • Collaborate with various departments to integrate ISO 27001 requirements into business processes and operations.

2. Risk Management

  • Conduct regular risk assessments to identify, analyze, and evaluate information security risks.
  • Develop and implement risk treatment plans to mitigate identified risks.
  • Monitor the effectiveness of risk treatment plans and adjust them as necessary to ensure ongoing risk mitigation.

3. Compliance & Audit Management

  • Prepare and maintain compliance documentation required for ISO 27001:2022 certification.
  • Coordinate and facilitate internal and external audits to ensure compliance with ISO 27001 standards.
  • Address non-conformities identified during audits by developing and implementing corrective and preventive actions.

4. Training & Awareness

  • Develop and deliver information security awareness training programs to educate employees about their roles in maintaining the ISMS.
  • Ensure that staff members understand and comply with ISO 27001:2022 policies and procedures.

5. Incident Management

  • Oversee the incident management process, ensuring that information security incidents are promptly identified, reported, and managed.
  • Conduct post-incident reviews to identify root causes and implement corrective actions to prevent recurrence.

6. Continuous Improvement

  • Monitor and evaluate the effectiveness of the ISMS, identifying areas for improvement.
  • Lead initiatives to enhance the organization's information security posture, staying up to date with industry trends, emerging threats, and changes in the regulatory environment.

7. Stakeholder Communication

  • Act as the primary point of contact for all matters related to ISO 27001:2022 compliance.
  • Communicate ISMS performance, compliance status, and risk management activities to senior management and relevant stakeholders.

8. Vendor and Third-Party Management

  • Evaluate and monitor third-party vendors and service providers to ensure they meet the organization's information security requirements.
  • Develop and maintain vendor risk assessments and ensure that third-party agreements align with ISO 27001:2022 standards.

9.
Coordinate business continuity and technology disaster recovery drills and tabletop exercises as appropriate.

10.
Identify critical systems and categorize them based on enterprise and operational risks crucial to continued business operations in the event of a disaster.

11.
Create reports as needed for different levels of leadership, covering all aspects of BCP.

12.
Conduct weekly status reports, DR readiness reviews, milestone reviews, and post-exercise reviews.

Note:
This role is 60% documentation and process-oriented.



  • Delhi, Delhi, India Careers at Tide Full time

    ABOUT TIDEAt Tide we help SMEs save time (and money) in the running of their businesses by not only offering business accounts and related banking services, but also a comprehensive set of highly usable and connected administrative solutions from invoicing to accounting.Tide is transforming the small business banking market with over 1.6 million members...


  • Delhi, Delhi, India Talent Worx Full time

    SAP GRC (Governance, Risk, and Compliance)/ Security Consultant to join our team. In this role, you will be responsible for implementing and managing security protocols and compliance measures within our SAP environment to safeguard sensitive data and ensure adherence to regulations.As a Senior Consultant, you will lead projects focused on SAP GRC solutions,...

  • SAP GRC PC Manager

    4 days ago


    Delhi, Delhi, India Deloitte Full time

    About the CompanyDeloitte India is looking for experienced Professionals in SAP GRC PC Manager to join in Delhi as Preferred and PAN India Locations.About the RolePosition: ManagerSAP GRC PC Professional should have:As a GRC PC Manager in our Risk Advisory team, you'll build and nurture positive working relationships with teams and clients with the intention...


  • Delhi, Delhi, India Dentsu Full time ₹ 6,00,000 - ₹ 18,00,000 per year

    You will be responsible for delivering information security initiatives through the region, for ensuring controls and culture are maintained, and for supporting business security requirements, leveraging global and regional capabilities. Led by the APAC CISO, our APAC Security team are responsible for driving global security initiatives across the APAC...


  • Delhi, Delhi, India Careers at Tide Full time

    ABOUT TIDEAt Tide we help SMEs save time (and money) in the running of their businesses by not only offering business accounts and related banking services, but also a comprehensive set of highly usable and connected administrative solutions from invoicing to accounting.Tide is transforming the small business banking market with over 1.6 million members...

  • GRC Instructor

    2 days ago


    Delhi, Delhi, India Thinkcloudly Full time

    Company DescriptionThinkcloudly is a global IT learning platform dedicated to helping individuals begin their journey to becoming IT professionals. We focus on upskilling our students by providing specialized courses to develop their employment abilities. Our mission is to deliver high-quality training and interview preparation skills to individuals who want...


  • Delhi, Delhi, India Deloitte Full time

    Job requisition ID :: 90753Date: Oct 29, 2025Location: DelhiDesignation: DirectorEntity: Deloitte Touche Tohmatsu India LLPWhat impact will you make?Every day, your work will make an impact that matters, while you thrive in a dynamic culture of inclusion, collaboration and high performance. As the undisputed leader in professional services, Deloitte is where...


  • Delhi, Delhi, India Neolytix Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Job descriptionAbout NeolytixNeolytix is a boutique Consulting and Management Services Organization that works with small & medium-sized healthcare providers across the United States. Our portfolio of services caters to micro verticals and is built on the expertise we have developed in enabling these practices.Work with a company where your work can make a...

  • ISO Auditor

    2 weeks ago


    Delhi, Delhi, India TAC Security Full time ₹ 15,00,000 - ₹ 30,00,000 per year

    Key Responsibilities:Plan, conduct, and report on internal audits of the ISMS as per ISO/IEC 27001 requirements.Identify non-conformities, risks, and improvement opportunities and follow up on corrective actions.Assist in maintaining ISO 27001 certification by ensuring compliance with applicable controls and standards.Provide guidance on the implementation...


  • Delhi, Delhi, India IT Company Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Company DescriptionWe suggest you enter details here.Role DescriptionThis is a full-time on-site role for an Information Technology (IT) Manager located in Delhi, India. The IT Manager will oversee the day-to-day operations of the IT department, manage IT projects, and ensure that systems, networks, and tools are effectively maintained and upgraded....