VI
Issues & Exceptions Management (IT Security & GRC)
VARITE INDIA PRIVATE LIMITED
🌏 Worldwide
Remote
Mid level
11 months ago
- Salesforce
- Adobe
- AWS
- SOX
- ISO 27001
- NIST
- COBIT
- SOC2
- ServiceNow
- Archer
- CISA
- CRISC
- CISSP
- Azure
- GCP
11 months ago
About The Client:
Visionet is a premier digital technology solutions company built on the premise of disruptive innovation. For over 27 years, our innovation-centric and engineering-first approach has unlocked digital-driven success to over 350+ global enterprises across Client, Retail, Banking & Financial Services, Food & Beverage, Manufacturing & Distribution, and Life Sciences industries. Our strategic technological alliances with Microsoft, Google, Salesforce, Adobe and AWS, as well as accolades like Microsoft Partner of the Year 2021 and EY Entrepreneur of the Year 2021, are a testament to our expertise in delivering seamless digital transition. With a talent pool of more than 9,500 passionate engineers and digital consultants across 14 distinct locations around the world, we engineer agility and provide innovation-driven value to our clients.
About The Job:
- We are seeking an experienced Issues & Exceptions Management professional with a strong background in IT Security, Controls, and Governance Risk & Compliance (GRC).
- The ideal candidate will be responsible for managing risk exceptions, tracking control issues, and driving remediation activities across the IT security landscape.
- The candidate must be well-versed in strategic governance, program change initiatives, and cross-functional stakeholder management
- Lead the Issues & Exceptions Management lifecycle—including logging, tracking, reviewing, and closure of control deficiencies and risk acceptances across security, infrastructure, and application domains.
- Collaborate with Risk Owners, Control Owners, and Business Stakeholders to assess impact, define compensating controls, and ensure timely resolution.
- Serve as the governance lead for exception handling, supporting risk-based decision-making, and facilitating periodic risk reviews.
- Ensure audit readiness and alignment with internal and external compliance requirements (e.g., SOX, ISO 27001, NIST CSF).
- Work closely with the GRC team to enhance issue tracking platforms and improve reporting metrics and dashboards (Service Now GRC or similar).
- Facilitate root cause analysis, control redesign, and action plan definition for recurring issues.
- Drive strategic program improvements in the Issues & Exceptions process, integrating best practices, tooling automation, and data governance.
- Monitor and report key risk and compliance indicators (KRI/KCI) related to open exceptions, overdue issues, and policy deviations.
Core Experience & Skills:
- 7–12 years of professional experience in IT Risk, Information Security, or GRC functions with a focus on Issues and Exceptions Management.
- Proven expertise in governance processes, policy management, and risk treatment plans.
- Strong understanding of IT controls, risk assessment methodologies, and frameworks like NIST, ISO, COBIT, SOC 2, and SOX.
- Experience in managing strategic program changes, including exception governance models, stakeholder training, and communication plans.
- Hands-on experience with GRC platforms such as ServiceNow GRC, Archer, or MetricStream.
- Excellent communication skills with the ability to engage technical and non-technical stakeholders.
- Strong analytical skills and attention to detail in issue documentation and remediation tracking.
- Professional certifications such as CISA, CRISC, CISSP, CGEIT, or equivalent.
- Experience managing security exceptions and remediation in cloud environments (AWS, Azure, GCP).
- Familiarity with automated issue tracking and reporting mechanisms, including KRIs and control metrics.
- Background in regulated industries (e.g., Financial Services, Healthcare, Insurance, or Energy).
- Prior experience in audit response, control testing, or internal audit coordination.
- Strategic mind-set with the ability to align exception handling and risk mitigation programs to broader business and compliance objectives.
- Exceptional communication and stakeholder management skills, including experience presenting risk posture and remediation strategies to C-level and audit committees.
- Strong leadership and influencing capabilities—able to drive cross-functional collaboration across risk, audit, IT, and security functions.
- Highly analytical and detail-oriented, with a strong sense of accountability for issue closure, tracking metrics, and regulatory readiness.
- Adept at navigating complex regulatory and control frameworks, balancing business enablement with compliance requirements.
- Change agent mentality, with demonstrated ability to implement program enhancements, drive governance improvements, and manage competing priorities.
Unlock Rewards: Refer Candidates and Earn.
If you're not available or interested in this opportunity, please pass this along to anyone in your network who might be a good fit and interested in our open positions. VARITE offers a Candidate Referral program, where you'll receive a one-time referral bonus based on the following scale if the referred candidate completes a three-month assignment with VARITE.
Experience Level Bonus Referral:
| 0-2 years | INR 5,000 |
| 2-6 years | INR 7,500 |
| 6+ years | INR 10,000 |
About VARITE: VARITE is a global staffing and IT consulting company providing technical consulting and team augmentation services to Fortune 500 Companies in USA, UK, CANADA and INDIA. VARITE is currently a primary and direct vendor to the leading corporations in the verticals of Networking, Cloud Infrastructure, Hardware and Software, Digital Marketing and Media Solutions, Clinical Diagnostics, Utilities, Gaming and Entertainment, and Financial Services.
Equal Opportunity Employer:
VARITE is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, marital status, veteran status, or disability status.
Issues & Exceptions Management (IT Security & GRC) · VARITE INDIA PRIVATE LIMITED