Information Security Governance Risk

7 days ago


Bengaluru, Karnataka, India Morae Global Corporation Full time ₹ 12,00,000 - ₹ 36,00,000 per year


Information Security Governance Risk and Compliance – Associate Manager

Job Type: Full Time

Reports to: Director of Information Security & IT Governance

POSITION OVERVIEW

This Information Security GRC Expert – Associate Manager contributes to Morae success by

implementing, and maintaining people, process and technology-oriented policies, procedures, and

controls to ensure ongoing security and compliance of Morae's innovative technology solutions and

information assets.

As a part of highly skilled Information Security team the role will focus on all areas of information

security governance, risk, and compliance for both our corporate IT environment as well as our

innovative client technology solutions serving some of the world's largest corporations.

The role will concentrate on maintaining both technology and procedural aspects of our ISO27001 and

SOC 2 Type II Regimes, Client Security Compliance, Third Party Risk Management, and Staff Security

Awareness efforts. In addition, the role will contribute to defining and developing both process and

toolsets for Data Classification, Data Loss Prevention, Data Privacy and Data Segregation in our

environments.

Working closely with Director of Information Security, global security operations and wider technology

teams GRC Associate Manager will contribute to development and review of Global Information

Security Strategy, IT Risk Registers and support the work of Risk Management Committee.

The GRC Associate Manager will be coaching and developing junior members of Information Security

GRC team. We are looking strong Information Security expert ready to develop both their technical

and GRC skillset to step up their career onto strategic management level.

KEY RESPONSIBILITIES:


• Contribute to maintenance and development of information security systems, policies and

procedures through implementation and maintenance of policies and identification of gaps

or non-compliance.


• Assist with the development, implementation, and improvement of the Morae Global

technical security processes.


• Ensuring Morae Global policies, applicable standards, customer requirements and best

practices are being followed.


• Supporting the delivery of information security projects and initiatives.


• Represent Morae Global in a professional and productive way while delivering the best in

service to our clients and during interactions with both clients and suppliers.


• Supporting the wider information security and technology team on providing a responsive

and pragmatic approach to day-to-day security issues and broader strategic initiatives


• Ensure security documents are controlled, reviewed, and updated in line with various

contractual and regulatory requirements.


• Develop and lead global information security awareness activities.


• Deliver related security communication across the organisation as required.


• Capturing evidence to support audit and compliance requirements.


• Provide support in responding to client security requests and client assurance assessments

and audits.


• Refine and maintain security dashboards and reports to support the production of security

metrics and quarterly security reporting.


• Initiate continuous improvement ideas and suggestions to increase efficiencies.


• Actively participate in wider, internal, and external information security initiatives.

SKILLS/EXPERIENCE:


• Bachelor's degree and 5+ years of experience of working with security, privacy and legal in a

regulated environment.


• Manage relationships with senior stakeholders in support of technology.


• Demonstrable experience of implementing ISO27001 and SOC 2 Type II Security compliance

frameworks.


• Demonstrable experience and knowledge of Data Governance, Data Classification, Data Loss

Prevention technical and process implementations.


• Experience in Data Privacy Regulatory Compliance implementations – GDPR, POPI, DPDP.


• Excellent English language written and verbal communication skills.


• Ability to write clear and concise policy documentation.


• Strong communication and presentation skills.


• Collaboration and conflict management skills.


• Experience in legal sector, eDiscovery and Document Management architecture would be

advantageous.


• Understanding of IT systems and security tools, including methods, procedures, equipment,

and software used for delivery.


• Planning, and strategic management skills.

Why Morae?

Morae's approach to employee development is unique in the marketplace. At Morae employees are

given opportunities to progress at their own pace and to influence the course of their professional

growth. This includes having the opportunity to earn a client facing role or even an oversight role

within their first year

About Morae:

Morae is a dynamic, high-growth organization that provides an integrated suite of solutions to

corporate law departments and law firms, and partners with leading software and services

providers, both within and outside the legal industry. We are a young company but are made up of

seasoned professionals in the legal industry, with a focus on building productive long-term

relationships with employees and clients in an environment where collaboration is encouraged,

knowledge is shared freely, and diversity of thought, cultures, communities, and points of view is

embraced. Our team has the vision to create an effective solution for any business problem and the

experience to execute that vision. Learn more at Our privacy policy can be found

here




  • Bengaluru, Karnataka, India Can Fin Homes Limited Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Responsible for Information Security (IS) Governance, risk management and compliance in the organization. 2. Develop and maintain documentation related to Information Security governance, risks, and audits in alignment with regulatory and compliance requirements. 3. Create, review, and update policies and standards to adapt to evolving organizational needs....


  • Bengaluru, Karnataka, India Morae Global Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Location: Bangalore, IndiaJob DescriptionThe role is focused on:· Contribute to the ongoing development of information security and general compliance (HR, environmental, etc.) systems, policies, and procedures through implementation, maintenance, and identification of gaps or non-compliance.· Assisting with the development, implementation, and improvement...

  • Security governance

    6 days ago


    Bengaluru, Karnataka, India Ananta Services Full time ₹ 18,00,000 - ₹ 22,00,000 per year

    What You Will Do· Establish and manage the information security governance framework aligned with organizational goals.· Develop, review, and maintain security policies, procedures, and standards.· Conduct risk assessments, gap analysis, and compliance audits (ISO 27001, NIST, SOC 2, GDPR, etc.).· Define and monitor key risk indicators (KRIs) and key...

  • AVP Governance Risk

    4 days ago


    Bengaluru, Karnataka, India Mashreq Careers Full time

    To develop, manage, and execute Information Security Governance, Risk and Compliance across Mashreq to – Contribute strategically to the bank's success and enable the business and technology strategy of the bank to expand with secure and reliable service offering.  Navigate compliance complexities and support compliance with information security...


  • Bengaluru, Karnataka, India Navi Full time ₹ 8,00,000 - ₹ 20,00,000 per year

    About the TeamAt Navi, the InfoSec team safeguards our digital ecosystem - ensuring the confidentiality, integrity, and availability of critical systems and data. We lead the charge on cyber risk management, regulatory compliance, and data protection, while championing a security-first culture across all teams.Our mission: Protect what powers Navi -...


  • Bengaluru, Karnataka, India Equiniti Full time ₹ 8,00,000 - ₹ 24,00,000 per year

    Management LevelGCore Duties/ResponsibilitiesRisk Identification, Assessment and AnalysisAssist and conduct comprehensive risk assessments to identify potential cybersecurity threats and vulnerabilities across EQ's infrastructure, data, applications, mobile and networks.Assist in conducting comprehensive security risk assessments for internal systems,...

  • Governance, Risk

    7 days ago


    Bengaluru, Karnataka, India DIGILE TECHNOLOGIES PRIVATE LIMITED Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    About the Role : We are seeking a highly experienced Governance, Risk, and Compliance (GRC) Manager to lead our enterprise risk management and compliance initiatives across regulated industries. The ideal candidate will have deep expertise in HITRUST CSF, ISO 27001 : 2022, SOC 2 Type II, NIST 800-53, and other high-trust frameworks relevant to...


  • Bengaluru, Karnataka, India Saks Global Full time ₹ 8,00,000 - ₹ 12,00,000 per year

    Job DescriptionWHO WE ARE:Saks Global is the largest multi-brand luxury retailer in the world, comprising Saks Fifth Avenue, Neiman Marcus, Bergdorf Goodman, Saks OFF 5TH, Last Call and Horchow. Its retail portfolio includes 70 full-line luxury locations, additional off-price locations and five distinct e-commerce experiences. With talented colleagues...


  • Bengaluru, Karnataka, India Grant Thornton Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Role DescriptionThe Senior Manager, Information Security Third-party Risk Management position will be an integral member of the Information Security and Risk Management team. This role will be responsible for design, development, implementation and monitoring of risk management program. Work in Chief Information Security Officer (CISO) office under Associate...

  • Governance, Risk

    2 days ago


    Bengaluru, Karnataka, India Smarsh Full time ₹ 4,00,000 - ₹ 8,00,000 per year

    Who are we?Smarsh empowers its customers to manage risk and unleash intelligence in their digital communications. Our growing community of over 6500 organizations in regulated industries counts on Smarsh every day to help them spot compliance, legal or reputational risks in 80+ communication channels before those risks become regulatory fines or headlines. ...