GRC Lead
6 days ago
We are seeking a mid- to senior-level Governance, Risk & Compliance (GRC) professional to own and evolve our security compliance program. This role is responsible for managing our security-related RFP and questionnaire processes and leading the preparation and execution of all audits tied to our compliance certifications (including SOC 2 Type II, ISO27001, and others).
This is a high-impact role that partners closely with Security, Engineering, Legal, Sales, and Customer Success to ensure we consistently meet our customers' expectations and our regulatory obligations.
Responsibilities:
Compliance Management
- Lead external audit engagements for SOC 2 Type II, ISO 27001, ISO 27701, ISO 42001, and CSA STAR.
- Own the relationship with external auditors and certification bodies.
- Develop and drive Swimlane's compliance maturity roadmap, including future programs such as FedRAMP, CMMC, the EU AI Act, IRAP, and additional emerging frameworks.
- Monitor evolving regulations, industry standards, and global compliance requirements impacting security, privacy, and AI governance.
Governance & Policy Management
- Develop, maintain, and continuously improve policies, procedures, and plans within Swimlane's integrated management system (security, privacy, and AI governance).
- Coordinate annual policy and documentation reviews in alignment with audit schedules and certification timelines.
- Assign and reinforce control ownership across business units, ensuring accountability and operational alignment.
- Provide guidance to teams to ensure organizational processes and business objectives remain compliant with policies and regulatory expectations.
- Define and track key GRC metrics (KPIs/KRIs), such as policy exceptions, risk register health, audit status, and control performance.
Risk Management
- Oversee the annual risk assessment and risk treatment planning aligned to ISO 27001, ISO 27701, and ISO 42001 requirements.
- Conduct targeted risk assessments and gap analyses to support strategic initiatives and emerging risks.
- Drive continuous improvement of enterprise risk processes and alignment of risk
ownership across all departments. - Collaborate closely with Engineering and Product teams to embed risk management
into roadmaps and development processes.
Internal Audit Program
- Lead full lifecycle internal audit engagements (planning, execution, reporting, and remediation).
Manage internal audits required for certification under ISO 27001, ISO 27701, and ISO 42001. - Implement and configure automation solutions for continuous control monitoring in partnership with GRC engineering resources.
Third-Party Risk Management
- Conduct risk assessments and due diligence for all new vendors and technology partners.
- Maintain a complete and up-to-date third-party inventory and oversee ongoing monitoring activities.
- Ensure third-party risk practices align with Swimlane's broader compliance obligations.
Trust & Customer Assurance
- Own and maintain the company's external Trust Center, ensuring accurate and up- to-date documentation.
- Lead the completion of customer security questionnaires, RFPs, and all due diligence processes.
- Curate, organize, and maintain a repository of GRC documentation for external stakeholders (prospects, customers, partners, auditors).
Serve as the primary SME for GRC topics, requiring strong familiarity with security architecture, engineering controls, and AI-related governance.
Business Continuity & Disaster Recovery
- Facilitate annual updates to the Business Continuity (BC) and Disaster Recovery (DR) plans.
- Coordinate BC/DR tabletop exercises and ensure alignment to audit and certification requirements.
- Support validation of cloud service availability, backup restoration, resiliency processes, and incident response playbooks.
Security Awareness & Training
- Deliver and track company-wide security awareness training.
- Develop role-specific training programs, including secure development, data protection, and acceptable use of AI technologies, aligned with compliance mandates.
Minimum Qualifications:
- 10+ years of experience in GRC, security compliance, risk management, or a related discipline.
- Hands-on experience managing SOC 2, ISO 27001, or similar security frameworks and audits.
- Strong understanding of security controls, compliance requirements, and industry best practices.
- Experience managing security questionnaires, RFP/RFI responses, or customer security due diligence processes.
- Excellent project management and organizational skills; ability to prioritize and manage multiple concurrent requests.
- Strong communication skills and comfort working with both internal stakeholders and external auditors.
- Familiarity with compliance or RFP tools is a plus.
Location: This role is based in India, and candidates must be current residents of India before applying to be considered.
Who we are, and what we offer:
Swimlane is a rapidly growing, innovative startup that provides cloud-scale, low-code security automation for organizations of all industries and sizes. Our technology is relied upon by major security-forward companies around the globe, and we are consistently rated as the #1 trusted low-code security automation platform. Our mission is to prevent breaches and enable continuous compliance via a low-code security automation platform that serves as the system of record for the entire security organization.
The Perks of Being a Swimlaner:
- Competitive Benefits & Compensation
- Stock Options
- Training & Professional Development Opportunities
- MacBook Pro
- Great Company Culture
- We value collaboration and innovation
- Give-back Volunteering Opportunities
Here at Swimlane, our core focus is to Automate the World of Security and we strive to represent our five core values in everything we do:
- Punch above your weight class - We make the most of our circumstances and constantly surprise and impress with our ability to deliver.
- Be a happy innovator - The hard problems are the fun problems to solve, we're excited to take on difficult challenges and find creative solutions.
- Always be leveling up - We are continuously improving, embracing change, and consuming information to better ourselves and each other.
- Move at the speed of WOW - We work with an extreme sense of urgency, but we never compromise quality.
- Have honesty and integrity in 'all the things' - We make decisions with the best of intentions, doing what is right for as many stakeholders as possible.
To complete your application, please submit your resume to
-
IT Grc Sme
20 hours ago
India CosMic IT Full timeFull Time - India - Posted 9 mins ago - CosMicIT - **CosMic IT** - Find Your Dream Job Here_ Hello Everyone, We at #CosMicIT are looking for a #IT GRC SME Locations: PAN India Job Description: **Responsibilities**: 1. GRC Program Management: - Develop, implement, and manage the overall IT GRC program. - Define and enhance policies, procedures, and...
-
SAP GRC
2 weeks ago
Chennai, India Kannanware Full timeJob Description We are looking for an experienced SAP GRC Solution Architect with strong expertise in SAP Security & GRC (10.x/12.x). The role involves designing and implementing GRC solutions, managing SAP access control, and ensuring compliance across SAP landscapes. Responsibilities: Lead SAP GRC Access Control design (ARA, ARM, EAM, BRM). Define SAP...
-
SAP Identify Access
3 days ago
Bengaluru, India ofi Full timeJob Description About Us As a leading provider of high-quality food and beverage ingredients, we work with farming communities across the globe to grow, source and produce ingredients that are good for consumers, farmers, and the world around us. We supply household food brands and manufacturers worldwide with cocoa, coffee, dairy, nuts and spices...
-
GRC Consultant – ICFR IT Controls Lead
7 days ago
India LanceSoft Middle East Full timeTitle: GRC Consultant – ICFR IT Controls Lead Location: Remote In India Job Type: 6 Months Required Skills and Qualifications Proven experience in GRC, ICFR, SOC, COSO compliance, and IT audit. Direct experience in IT ERP controls , particularly to support our team with the remediation activities for our ERP systems Strong understanding of ITGC and ITAC...
-
GRC Consultant – ICFR IT Controls Lead
7 days ago
India LanceSoft Middle East Full timeTitle: GRC Consultant – ICFR IT Controls LeadLocation: Remote In IndiaJob Type: 6 MonthsRequired Skills and QualificationsProven experience in GRC, ICFR, SOC, COSO compliance, and IT audit.Direct experience in IT ERP controls, particularly to support our team with the remediation activities for our ERP systemsStrong understanding of ITGC and ITAC...
-
GRC Consultant – ICFR IT Controls Lead
7 days ago
india, IN LanceSoft Middle East Full timeTitle: GRC Consultant – ICFR IT Controls LeadLocation: Remote In IndiaJob Type: 6 MonthsRequired Skills and QualificationsProven experience in GRC, ICFR, SOC, COSO compliance, and IT audit.Direct experience in IT ERP controls, particularly to support our team with the remediation activities for our ERP systemsStrong understanding of ITGC and ITAC...
-
Compliance Lead
4 weeks ago
Bengaluru, India BETSOL Full timeJob Description BETSOL is a cloud-first digital transformation and data management company offering products and IT services to enterprises in over 40 countries. BETSOL team holds several engineering patents, is recognized with industry awards, and BETSOL maintains a net promoter score that is 2x the industry average. BETSOL's open source backup and recovery...
-
Lead - GRC Risk Management
2 weeks ago
Gurugram, India IndiGo (InterGlobe Aviation Ltd) Full timeJob Description Position Overview We are seeking an experienced Security GRC (Governance, Risk & Compliance) Lead to own and drive our Risk Management Program. This role will be responsible for defining, implementing, and maturing enterprise-wide information security risk management practices, aligning them with business strategy, regulatory requirements,...
-
ServiceNow GRC Technical delivery Lead
3 days ago
Pune, India Northern Trust Full timeJob Description About Northern Trust Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889. Northern Trust is proud to provide innovative financial services and guidance to the world's most successful individuals, families, and institutions by remaining true to...
-
Director - Privacy and GRC
2 weeks ago
Gurugram, Gurugram, India Tsaaro Consulting Full timeJob Description Join Tsaaro as a Director Privacy & GRC Lead with Vision. Drive Transformation. Shape Global Privacy & Governance. Are you a seasoned privacy, security, and governance professional looking to take the next major step in your leadership journey At Tsaaro, we don't just deliver compliance we redefine how organizations implement privacy,...