
Manager - Information Security (Governance, Risk and Compliance)
18 hours ago
About the Team
At Navi, the InfoSec team safeguards our digital ecosystem - ensuring the confidentiality, integrity, and availability of critical systems and data. We lead the charge on cyber risk management, regulatory compliance, and data protection, while championing a security-first culture across all teams.
Our mission: Protect what powers Navi - securely, compliantly, and confidently.
About the Role
Navi is looking for an Associate Manager II – Information Security to pilot key aspects of its group-wide information security and regulatory compliance program. This role involves interpreting and implementing information security and technology risks mandates from regulators such as RBI, IRDAI, SEBI, and NPCI, ensuring continuous tech compliance across all business units. You will collaborate closely with engineering, infrastructure, legal, and IT teams to establish and maintain robust security policies, frameworks, and controls. Additionally, the role includes conducting risk assessments, enabling audit readiness, managing third-party/vendor security audits, and driving awareness initiatives across the organization, while also representing Navi in internal and external forums when needed.
What We Expect From You
- As Navi operates in the regulatory space, this role requires interpreting and helping implement regulations related to cyber security by Reserve Bank of India (RBI), IRDAI and SEBI, as well as any other applicable regulatory guidance related to the service offerings issued by relevant institutions.
- Further to the point above, ensure on-going monitoring and tech-compliance with existing regulatory expectations across these dimensions
- Lead the Information security - GRC practice for Navi group level.
- Ensuring that information security principles, policies, frameworks, standards and controls are defined, implemented and managed effectively.
- Partner and collaborate extensively with cross-functional teams, such as Engineering, Infrastructure, IT, Legal, and help minimize information security risks
- Architect and deliberate on the solutions that are compliant with relevant regulatory cybersecurity requirements
- Conduct and review results of Technology Risk Assessment, recommending mitigation strategies to bring the Risk to appropriate levels Nav is looking for a Senior Manager Information Security (GRC) to be part of the information security
- Ensure readiness of the organization for internal and external audits by keeping all documents, evidences, ready
- If required, represent Navi in Board and Board Committee meetings, as well as in discussions with regulators
- Conduct Security awareness programs, train personnel on data security & privacy related processes and responsibilities
- Review / conduct Third Party Risk Assessments & Vendor assessments before onboarding
- Review security solutions / controls implemented by Tech / Engineering teams, controls at data center,
- cyber / information security incidents, IT BCP and DR drills, cloud security controls
- Identify and define Security KPIs including weekly, monthly reports and update Security Dashboards
Must Haves
- Minimum 7
+ years of experience
working in information security GRC - Prior experience in the
Fintech/Startup industry
and knowledge of one of the regulatory compliances like
PCI DSS, RBI Master Directives, IRDA, SEBI cyber security guideline
is preferred. - Hands-on approach in solving complex security problems
- Experience with
Information Security & Risk Management frameworks
like ISO27001, NIST SP 800-37, etc Cyber Kill Chain, MITRE ATT&CK, or other relevant frameworks - Working knowledge of Cloud environments like
AWS, GCP, Oracle cloud
is beneficial - Exposure to
Agile methodologies, DevOps, Cloud technologies
is beneficial
Soft Skills
- Ability to multitask and meet deadlines, and to prioritize in a highly dynamic work environment
- Ability to balance risk, potential impact, resourcing, business drivers, and timelines
- Excellent verbal and written communication skills
- Strong Product Thinking
- Strong problem solving
- Business acumen
- Technology grounding
- Strategic thinking
- Strong written and verbal communication skills with a talent for articulating.
Inside Navi
We are shaping the future of financial services for a billion Indians through products that are simple, accessible, and affordable. From Personal & Home Loans to UPI, Insurance, Mutual Funds, and Gold - we're building tech-first solutions that work at scale, with a strong customer-first approach.
Founded by
Sachin Bansal & Ankit Agarwal
in 2018, we are one of India's fastest-growing financial services organisations. But we're just getting started
Our Culture
The Navi DNA
Ambition. Perseverance. Self-awareness. Ownership. Integrity.
We're looking for people who dream big when it comes to innovation. At Navi, you'll be empowered with the right mechanisms to work in a dynamic team that builds and improves innovative solutions. If you're driven to deliver real value to customers, no matter the challenge, this is the place for you.
We chase excellence by uplifting each other and that starts with every one of us.
Why You'll Thrive at Navi
At Navi, it's about how you think, build, and grow. You'll thrive here if:
- You're impact-driven :
You take ownership, build boldly, and care about making a real difference. - You strive for excellence :
Good isn't good enough. You bring focus, precision, and a passion for quality. - You embrace change :
You adapt quickly, move fast, and always put the customer first.
-
Governance, Risk Management, And Compliance
2 weeks ago
Bengaluru, Karnataka, India InnoWave360 Full timeJob DescriptionJob Title: Governance, Risk & Compliance (GRC) Associate/Assistant Manager/ Dy. ManagerLocation: BangaloreEmployment Type: Full-timeRole Overview:We are seeking a seasoned Governance, Risk & Compliance (GRC) professional with deep expertise in Business Audit, ERM, IFC, investigations, process transformation, and cost optimization. The ideal...
-
Information Security Manager
1 week ago
Bengaluru, Karnataka, India beBeeGovernance Full time ₹ 15,00,000 - ₹ 25,00,000Job DescriptionAs a key member of our organization, you will play a vital role in supporting and advising on Information Security Management System (ISMS) and associated controls.Provide guidance on the management of risk and offer a transparent view of risk posture to stakeholders.Support compliance with relevant control standards, regulation, and audit...
-
Manager - IT Security Governance
2 weeks ago
Bengaluru, Karnataka, India PracticeSuite, Inc. Full timeOverview:PracticeSuite, Inc. is an innovative platform to enable medical practices and other healthcare facilities to create an amazing patient experience. As a single platform, PracticeSuite has diverse features to modernize practices and take them to the next level.We are currently recruiting for a Manager, IT Security Governance. This position will be...
-
IT Governance and Risk Management Professional
2 weeks ago
Bengaluru, Karnataka, India beBeeRisk Full time US$ 10,00,000 - US$ 12,00,000Job Title: IT Governance and Risk Management SpecialistAbout the Role:This position plays a critical role in ensuring the effective management of IT risks within the Asia Pacific region.The ideal candidate will possess a strong understanding of IT Governance, Risk and Compliance principles, as well as experience in managing technology and information...
-
Governance Risk and Compliance Specialist
1 week ago
Bengaluru, Karnataka, India beBeeCompliance Full time ₹ 21,00,000 - ₹ 42,00,000Job SummaryWe are seeking an experienced professional to join our team as a Governance Risk and Compliance Officer. In this role, you will be responsible for establishing and maintaining first-line governance and oversight on the management of IT risks within the bank. You will work closely with various stakeholders to ensure effective implementation of IT...
-
Chief Information Security Governance Specialist
2 weeks ago
Bengaluru, Karnataka, India beBeeGovernance Full time ₹ 2,00,00,000 - ₹ 2,50,00,000Job OverviewDeveloping a robust IT security governance program is crucial for modernizing business operations and ensuring regulatory compliance.As an innovative platform, PracticeSuite enables medical practices and healthcare facilities to deliver exceptional patient experiences through diverse features and services.We are recruiting a Manager, responsible...
-
Bengaluru, Karnataka, India MillerKnoll Full timeWhy join us Our purpose is to design for the good of humankind It s the ideal we strive toward each day in everything we do Being a part of MillerKnoll means being a part of something larger than your work team or even your brand We are redefining modern for the 21st century And our success allows MillerKnoll to support causes that align with our...
-
Lead - Governance/Risk & Compliance
2 weeks ago
Bengaluru, Karnataka, India Smarsh Full timeWho are we?. Smarsh empowers its customers to manage risk and unleash intelligence in their digital communications. Our growing community of over 6500 organizations in regulated industries counts on Smarsh every day to help them spot compliance, legal or reputational risks in 80+ communication channels before those risks become regulatory fines or headlines....
-
Chief Information Governance Officer
2 weeks ago
Bengaluru, Karnataka, India beBeeCyber Full time ₹ 1,50,00,000 - ₹ 2,50,00,000Information Governance Specialist Job We are seeking a highly skilled Manager to join our team in Bengaluru, India. This role is responsible for assisting with the Information Security Risk and Compliance (ISRC) function and supporting governance initiatives.Key Responsibilities:Lead and/or manage ISRC employees in Bengaluru, IndiaRecords and Information...
-
Governance Risk and Compliance
15 hours ago
Bengaluru, Karnataka, India KPMG Global Services Full time ₹ 5,00,000 - ₹ 15,00,000 per yearAs a GRC Analyst, you will support the organization's Governance, Risk, and Compliance initiatives by performing risk assessments, control testing, and ensuring adherence to NIST Cybersecurity Framework (CSF) and ISO 27001standards •Conduct risk assessments for systems, applications, and third-party vendors aligned with ISO 27001 and NIST...