Information Security Governance Risk
7 days ago
Information Security Governance Risk and Compliance – Associate Manager
Job Type: Full Time
Reports to: Director of Information Security & IT Governance
POSITION OVERVIEW
This Information Security GRC Expert – Associate Manager contributes to Morae success by
implementing, and maintaining people, process and technology-oriented policies, procedures, and
controls to ensure ongoing security and compliance of Morae's innovative technology solutions and
information assets.
As a part of highly skilled Information Security team the role will focus on all areas of information
security governance, risk, and compliance for both our corporate IT environment as well as our
innovative client technology solutions serving some of the world's largest corporations.
The role will concentrate on maintaining both technology and procedural aspects of our ISO27001 and
SOC 2 Type II Regimes, Client Security Compliance, Third Party Risk Management, and Staff Security
Awareness efforts. In addition, the role will contribute to defining and developing both process and
toolsets for Data Classification, Data Loss Prevention, Data Privacy and Data Segregation in our
environments.
Working closely with Director of Information Security, global security operations and wider technology
teams GRC Associate Manager will contribute to development and review of Global Information
Security Strategy, IT Risk Registers and support the work of Risk Management Committee.
The GRC Associate Manager will be coaching and developing junior members of Information Security
GRC team. We are looking strong Information Security expert ready to develop both their technical
and GRC skillset to step up their career onto strategic management level.
KEY RESPONSIBILITIES:
• Contribute to maintenance and development of information security systems, policies and
procedures through implementation and maintenance of policies and identification of gaps
or non-compliance.
• Assist with the development, implementation, and improvement of the Morae Global
technical security processes.
• Ensuring Morae Global policies, applicable standards, customer requirements and best
practices are being followed.
• Supporting the delivery of information security projects and initiatives.
• Represent Morae Global in a professional and productive way while delivering the best in
service to our clients and during interactions with both clients and suppliers.
• Supporting the wider information security and technology team on providing a responsive
and pragmatic approach to day-to-day security issues and broader strategic initiatives
• Ensure security documents are controlled, reviewed, and updated in line with various
contractual and regulatory requirements.
• Develop and lead global information security awareness activities.
• Deliver related security communication across the organisation as required.
• Capturing evidence to support audit and compliance requirements.
• Provide support in responding to client security requests and client assurance assessments
and audits.
• Refine and maintain security dashboards and reports to support the production of security
metrics and quarterly security reporting.
• Initiate continuous improvement ideas and suggestions to increase efficiencies.
• Actively participate in wider, internal, and external information security initiatives.
SKILLS/EXPERIENCE:
• Bachelor's degree and 5+ years of experience of working with security, privacy and legal in a
regulated environment.
• Manage relationships with senior stakeholders in support of technology.
• Demonstrable experience of implementing ISO27001 and SOC 2 Type II Security compliance
frameworks.
• Demonstrable experience and knowledge of Data Governance, Data Classification, Data Loss
Prevention technical and process implementations.
• Experience in Data Privacy Regulatory Compliance implementations – GDPR, POPI, DPDP.
• Excellent English language written and verbal communication skills.
• Ability to write clear and concise policy documentation.
• Strong communication and presentation skills.
• Collaboration and conflict management skills.
• Experience in legal sector, eDiscovery and Document Management architecture would be
advantageous.
• Understanding of IT systems and security tools, including methods, procedures, equipment,
and software used for delivery.
• Planning, and strategic management skills.
Why Morae?
Morae's approach to employee development is unique in the marketplace. At Morae employees are
given opportunities to progress at their own pace and to influence the course of their professional
growth. This includes having the opportunity to earn a client facing role or even an oversight role
within their first year
About Morae:
Morae is a dynamic, high-growth organization that provides an integrated suite of solutions to
corporate law departments and law firms, and partners with leading software and services
providers, both within and outside the legal industry. We are a young company but are made up of
seasoned professionals in the legal industry, with a focus on building productive long-term
relationships with employees and clients in an environment where collaboration is encouraged,
knowledge is shared freely, and diversity of thought, cultures, communities, and points of view is
embraced. Our team has the vision to create an effective solution for any business problem and the
experience to execute that vision. Learn more at Our privacy policy can be found
here
-
Information Security Governance, Risk
1 week ago
Bengaluru, Karnataka, India Can Fin Homes Limited Full time ₹ 15,00,000 - ₹ 25,00,000 per yearResponsible for Information Security (IS) Governance, risk management and compliance in the organization. 2. Develop and maintain documentation related to Information Security governance, risks, and audits in alignment with regulatory and compliance requirements. 3. Create, review, and update policies and standards to adapt to evolving organizational needs....
-
Information Security Governance Risk
1 week ago
Bengaluru, Karnataka, India Morae Global Full time ₹ 12,00,000 - ₹ 36,00,000 per yearLocation: Bangalore, IndiaJob DescriptionThe role is focused on:· Contribute to the ongoing development of information security and general compliance (HR, environmental, etc.) systems, policies, and procedures through implementation, maintenance, and identification of gaps or non-compliance.· Assisting with the development, implementation, and improvement...
-
Security governance
6 days ago
Bengaluru, Karnataka, India Ananta Services Full time ₹ 18,00,000 - ₹ 22,00,000 per yearWhat You Will Do· Establish and manage the information security governance framework aligned with organizational goals.· Develop, review, and maintain security policies, procedures, and standards.· Conduct risk assessments, gap analysis, and compliance audits (ISO 27001, NIST, SOC 2, GDPR, etc.).· Define and monitor key risk indicators (KRIs) and key...
-
AVP Governance Risk
4 days ago
Bengaluru, Karnataka, India Mashreq Careers Full timeTo develop, manage, and execute Information Security Governance, Risk and Compliance across Mashreq to – Contribute strategically to the bank's success and enable the business and technology strategy of the bank to expand with secure and reliable service offering. Navigate compliance complexities and support compliance with information security...
-
Bengaluru, Karnataka, India Navi Full time ₹ 8,00,000 - ₹ 20,00,000 per yearAbout the TeamAt Navi, the InfoSec team safeguards our digital ecosystem - ensuring the confidentiality, integrity, and availability of critical systems and data. We lead the charge on cyber risk management, regulatory compliance, and data protection, while championing a security-first culture across all teams.Our mission: Protect what powers Navi -...
-
Information Security Risk Analyst
2 weeks ago
Bengaluru, Karnataka, India Equiniti Full time ₹ 8,00,000 - ₹ 24,00,000 per yearManagement LevelGCore Duties/ResponsibilitiesRisk Identification, Assessment and AnalysisAssist and conduct comprehensive risk assessments to identify potential cybersecurity threats and vulnerabilities across EQ's infrastructure, data, applications, mobile and networks.Assist in conducting comprehensive security risk assessments for internal systems,...
-
Governance, Risk
7 days ago
Bengaluru, Karnataka, India DIGILE TECHNOLOGIES PRIVATE LIMITED Full time ₹ 12,00,000 - ₹ 36,00,000 per yearAbout the Role : We are seeking a highly experienced Governance, Risk, and Compliance (GRC) Manager to lead our enterprise risk management and compliance initiatives across regulated industries. The ideal candidate will have deep expertise in HITRUST CSF, ISO 27001 : 2022, SOC 2 Type II, NIST 800-53, and other high-trust frameworks relevant to...
-
Bengaluru, Karnataka, India Saks Global Full time ₹ 8,00,000 - ₹ 12,00,000 per yearJob DescriptionWHO WE ARE:Saks Global is the largest multi-brand luxury retailer in the world, comprising Saks Fifth Avenue, Neiman Marcus, Bergdorf Goodman, Saks OFF 5TH, Last Call and Horchow. Its retail portfolio includes 70 full-line luxury locations, additional off-price locations and five distinct e-commerce experiences. With talented colleagues...
-
Bengaluru, Karnataka, India Grant Thornton Full time ₹ 15,00,000 - ₹ 25,00,000 per yearRole DescriptionThe Senior Manager, Information Security Third-party Risk Management position will be an integral member of the Information Security and Risk Management team. This role will be responsible for design, development, implementation and monitoring of risk management program. Work in Chief Information Security Officer (CISO) office under Associate...
-
Governance, Risk
2 days ago
Bengaluru, Karnataka, India Smarsh Full time ₹ 4,00,000 - ₹ 8,00,000 per yearWho are we?Smarsh empowers its customers to manage risk and unleash intelligence in their digital communications. Our growing community of over 6500 organizations in regulated industries counts on Smarsh every day to help them spot compliance, legal or reputational risks in 80+ communication channels before those risks become regulatory fines or headlines. ...