This role has closed. Awfis has taken the posting down.
hirly last saw it live on 29 September 2026. See similar open roles below, or browse all jobs in Pune.
Awfis
Senior General Manager
Bengaluru, India · Pune, India
Similar open jobs
- General Manager - Project ExecutionPSP Projects Limited · Ahmedabad, Gujarat, IndiaFirst seen today
- Head/Associate General Manager – Production (F/M/D)Freudenberg · MysoreFirst seen today
- General Manager - Finance and Accounts (F/M/D)Freudenberg · PuneFirst seen today
- Deputy General Manager - Methods and ProductionSchneider Electric · Chennai, Tamil Nadu, IndiaFirst seen today
- Senior General Manager, PurchaseAmneal Pharmaceuticals · Ahmedabad, Gujarat, IndiaFirst seen today
- Deputy General Manager - Cyber SecuritySchneider Electric · Chennai, Tamil Nadu, IndiaFirst seen today
- Associate General Manager Mechanical Maintenance - HYCOLinde · IndiaFirst seen today
- Associate General Manager Instrumentation & Control System - HYCOLinde · IndiaFirst seen today
- Associate General Manager, Project & EngineeringAmneal · IndiaFirst seen today
- Deputy General Manager - Interior DesignerK Raheja Corp · Mumbai, INFirst seen yesterday
- Assistant General Manager - Service & QualityK Raheja Corp · Mumbai, INFirst seen yesterday
- General Manager of Manufacturing Atit IndiaCopeland · Atit, IndiaFirst seen yesterday
- General Manager - Novotel New Delhi City CentreNOVOTEL · New Delhi, Delhi, IndiaFirst seen 2d ago
- General Manager - Park Inn By Radisson, Electronic City, BengaluruRadisson Hotel Group · Bangalore, Karnataka, IndiaFirst seen 2d ago
- Associate General Manager, ManufacturingAmneal India · Ahmedabad City, Gujarat, IndiaFirst seen 2d ago
hirly's read of this role
- Seniority
- Lead / management
- Country
- IN
- Work mode
- On-site / unstated
- First seen by hirly
- 23 Sept 2026
Derived automatically from the posting.
the posting
Position Purpose
This position is critical to centralizing ownership for driving enterprise-wide governance and compliance programs, ensuring proactive risk management, audit readiness, and alignment with international standards and local data protection laws. The GRC Lead will work directly with the HOD on multiple GRC initiatives including ISO 27001 certification for Awfis, alignment with the Digital Personal Data Protection (DPDP) Act, Captive Risk Profiling, Third-Party Risk Management (TPRM), and related programs.
Key Responsibilities
Governance & Compliance Program Ownership
- Establish, lead, and continuously mature the enterprise GRC framework across Awfis and Awliv business units.
- Drive end-to-end ownership of ISO 27001 certification for Awfis, including gap assessment, control implementation, internal audits, and external certification readiness.
- Develop, publish, and maintain information security policies, standards, procedures, and guidelines aligned with industry best practices.
- Ensure organizational alignment with the DPDP Act and other applicable data protection and privacy regulations.
Risk Management
- Lead Captive Risk Profiling exercises, including identification, assessment, treatment, and continuous monitoring of enterprise risks.
- Maintain the enterprise risk register and drive periodic risk review cadence with business and IT stakeholders.
- Define and track key risk indicators (KRIs) and key control indicators (KCIs); report risk posture to leadership.
- Recommend and oversee implementation of risk mitigation strategies across functions.
Third-Party Risk Management (TPRM)
- Design and operationalize the TPRM program covering vendor onboarding, due diligence, periodic reassessment, and offboarding.
- Evaluate third-party security, privacy, and contractual compliance posture; track remediation of identified gaps.
- Collaborate with Procurement, Legal, and business owners to embed security and privacy clauses into contracts.
Audit & Assurance
- Plan and execute internal audits; coordinate external audits, certifications, and client/regulatory assessments.
- Track audit findings to closure, drive root cause analysis, and reduce repeat non-conformities.
- Improve audit closure timelines through structured tracking, accountability, and reporting mechanisms.
- Serve as the single point of contact for client security and compliance assessments.
Data Protection & Privacy
- Drive DPDP Act readiness, including data mapping, consent management, data subject rights handling, and breach response.
- Coordinate with Legal and business teams on data processing agreements, privacy notices, and cross-border data transfer requirements.
- Support the Data Protection Officer (DPO) function as required.
Stakeholder Engagement & Reporting
- Partner with IT, Legal, HR, Operations, Finance, and business units to embed GRC practices into day-to-day operations.
- Prepare and present GRC dashboards, metrics, and reports to senior leadership, the HOD, and relevant committees.
- Conduct awareness and training programs to build a culture of compliance and security accountability.
Required Qualifications
Education
Bachelor's degree in Computer Science, Information Technology, Information Security, or a related discipline. A Master's degree or MBA is a plus.
Experience
- 7 to 12 years of progressive experience in Information Security, IT Governance, Risk, and Compliance, with at least 3 years in a GRC leadership or program ownership role.
- Demonstrated experience driving ISO 27001 certification end-to-end (preparation through certification and surveillance audits).
- Hands-on experience with DPDP, GDPR, or comparable data protection regimes.
- Proven track record running TPRM, internal audit, and enterprise risk programs.
Certifications (one or more strongly preferred)
- ISO 27001 Lead Auditor or Lead Implementer
- CISA, CISM, CRISC, or CISSP
- DCPP, DCPLA, CIPP/E, or CIPM (for privacy)
Technical & Functional Skills
- Strong working knowledge of ISO 27001, NIST CSF, SOC 2, PCI DSS, and similar frameworks.
- Deep understanding of Indian data protection law (DPDP Act) and global privacy regulations.
- Familiarity with GRC tools, risk assessment methodologies, and control testing approaches.
- Sound understanding of IT and cloud infrastructure, application security concepts, and common threat landscapes.
Behavioural Competencies
- Strong ownership mindset with the ability to operate independently and drive programs to closure.
- Excellent stakeholder management and influencing skills across technical and non-technical audiences.
- Strong analytical, problem-solving, and decision-making abilities.
- Clear written and verbal communication, including the ability to present to executive leadership.
- High integrity, attention to detail, and a structured approach to complex problems.
Key Deliverables (First 12 Months)
- Establish a baseline IT compliance practice and operating model across Awfis and Awliv.
- Achieve ISO 27001 certification for Awfis.
- Deliver DPDP readiness and operationalize ongoing compliance.
- Stand up a functional TPRM program with defined SLAs and a vendor risk register.
- Reduce open audit findings and repeat non-conformities through structured remediation tracking.
- Publish a quarterly enterprise risk and compliance dashboard for leadership.