VI
GRC & Risk Management Architect
VARITE INDIA PRIVATE LIMITED
🇮🇳 India
On-site
Manager or above
11 months ago
- Salesforce
- Adobe
- AWS
- Risk Management
- ServiceNow
- Archer
- ISO 27001
- COBIT
- SOC2
- PCI DSS
- HIPAA
- GDPR
- CCPA
- SOX
- AI
- IAM
- SIEM
- NIST
- RMF
- COSO
- OneTrust
- CISSP
- CISM
- CRISC
11 months ago
About The Client:
Visionet is a premier digital technology solutions company built on the premise of disruptive innovation. For over 27 years, our innovation-centric and engineering-first approach has unlocked digital-driven success to over 350+ global enterprises across Client, Retail, Banking & Financial Services, Food & Beverage, Manufacturing & Distribution, and Life Sciences industries. Our strategic technological alliances with Microsoft, Google, Salesforce, Adobe and AWS, as well as accolades like Microsoft Partner of the Year 2021 and EY Entrepreneur of the Year 2021, are a testament to our expertise in delivering seamless digital transition. With a talent pool of more than 9,500 passionate engineers and digital consultants across 14 distinct locations around the world, we engineer agility and provide innovation-driven value to our clients.
About The Job:
- The GRC & Risk Management Architect will be responsible for designing, implementing, and optimizing the organization’s Governance, Risk, and Compliance (GRC) framework.
- This includes defining risk management strategies, establishing enterprise-wide policies and control frameworks, enabling technology alignment (e.g., ServiceNow GRC, MetricStream, Archer, Hyperproof), and ensuring compliance with international standards and regulatory requirements.
- This position combines strategic oversight, risk and control design, technology-driven enablement, and cross-functional governance leadership
Governance & Framework Development
- Design and maintain the enterprise GRC architecture, aligning business objectives with compliance and risk frameworks.
- Establish and maintain governance structures, policies, and operating models.
- Integrate global frameworks such as ISO 27001:2022, NIST CSF 2.0, NIST SP 800-53, COBIT, SOC 2, PCI DSS, HIPAA, DORA, and ISO 42001 into organizational processes.
- Lead enterprise risk identification, assessment, and quantification processes.
- Define and operationalize risk appetite, tolerance, and KRIs (Key Risk Indicators).
- Oversee risk remediation planning, continuous risk monitoring, and reporting to senior leadership.
- Implement risk automation workflows and dashboards for real-time insights.
- Design and oversee the common control framework (CCF) mapping across multiple standards.
- Drive periodic control testing, evidence collection, and audit readiness programs.
- Ensure compliance to regulatory and contractual obligations (e.g., GDPR, CCPA, SOX, NYDFS 500).
- Collaborate with Internal Audit, Legal, and Security Operations for coordinated assurance.
- Design and implement the GRC tool architecture (e.g., ServiceNow GRC, Archer, MetricStream, Hyperproof).
- Define automation and AI-driven capabilities for risk scoring, evidence collection, and compliance monitoring.
- Provide architectural guidance for integration with IAM, SIEM, CMDB, and asset inventory systems.
- Lead vendor evaluations, proof-of-concepts, and deployment of GRC platforms.
- Partner with CISO and IT Security teams to assess technology and operational risks across IT, OT, and Cloud environments.
- Develop and maintain security risk registers and treatment plans.
- Conduct third-party risk assessments and manage the Vendor Risk Management (VRM) program.
- Oversee periodic penetration test reviews, vulnerability risk scoring, and control maturity assessments.
- Prepare executive-level risk dashboards, compliance scorecards, and audit committee presentations.
- Influence senior management decisions through data-driven risk insights.
- Serve as a trusted advisor to leadership on emerging risks, regulatory changes, and assurance trends.
- Bachelor’s/Master’s degree in Information Security, Computer Science, Risk Management, or related field.
- 12–15 years of experience in GRC architecture, Risk & Compliance management, or Cybersecurity Governance.
- Risk frameworks: ISO 27005, NIST RMF, COSO ERM
- Security frameworks: NIST CSF, ISO 27001, SOC 2
- Data privacy: GDPR, CCPA, HIPAA
- Strong experience implementing or managing GRC tools (ServiceNow, Archer, MetricStream, Hyperproof, OneTrust, etc.).
- Expertise in developing policy frameworks, control libraries, and risk quantification models.
- Excellent communication, leadership, and stakeholder management skills.
- CISSP / CISM / CRISC / CGEIT
- ISO 27001 Lead Implementer or Auditor
- Certified Risk Manager (IRM / GRCI / FAIR)
- ServiceNow GRC or Archer Certified Professional (Preferred)
- Strategic thinker with the ability to translate complex compliance requirements into practical architecture.
- Proactive, analytical, and collaborative with a strong business acumen.
- Passionate about GRC automation, AI-enabled risk intelligence, and continuous control monitoring.
Unlock Rewards: Refer Candidates and Earn.
If you're not available or interested in this opportunity, please pass this along to anyone in your network who might be a good fit and interested in our open positions. VARITE offers a Candidate Referral program, where you'll receive a one-time referral bonus based on the following scale if the referred candidate completes a three-month assignment with VARITE.
Experience Level Bonus Referral:
| 0-2 years | INR 5,000 |
| 2-6 years | INR 7,500 |
| 6+ years | INR 10,000 |
About VARITE: VARITE is a global staffing and IT consulting company providing technical consulting and team augmentation services to Fortune 500 Companies in USA, UK, CANADA and INDIA. VARITE is currently a primary and direct vendor to the leading corporations in the verticals of Networking, Cloud Infrastructure, Hardware and Software, Digital Marketing and Media Solutions, Clinical Diagnostics, Utilities, Gaming and Entertainment, and Financial Services.
Equal Opportunity Employer:
VARITE is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, marital status, veteran status, or disability status.
GRC & Risk Management Architect · VARITE INDIA PRIVATE LIMITED