Senior Manager, Cyber Governance & Risk Management at S&P Global
Gurugram, haryana, India -
Full Time


Start Date

Immediate

Expiry Date

11 Oct, 26

Salary

0.0

Posted On

13 Jul, 26

Experience

5 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Cybersecurity Governance, Risk Management, Compliance Frameworks, Third-Party Risk Management, ISO 27001, SOC 2, TISAX, NIST, Policy Development, Audit Readiness, Executive Reporting, Security Awareness Training, Stakeholder Management, Technology Risk Oversight, Vendor Security Assessments, Risk Remediation

Industry

Data Infrastructure and Analytics

Description
The Team: A global Cyber Governance, Risk & Compliance (GRC) team that is responsible for managing cyber risk, driving policy adherence, enabling compliance, supporting customer trust initiatives, and delivering enterprise-wide governance processes. The team partners across IT, Security, Legal, Risk, Privacy, Sales, and Business functions to deliver integrated risk management and assurance capabilities. The Role: The Senior Manager, Cyber Governance & Risk Management will lead enterprise-wide cybersecurity governance, policy management, technology risk oversight and third-party risk management. This role is responsible for ensuring alignment with regulatory, contractual, and internal security requirements while enabling business operations, supporting revenue growth, and maintaining customer trust. Responsibilities and Impact: Lead the development, maintenance, and enforcement of cybersecurity governance frameworks, policies, and standards aligned to ISO 27001, SOC 2, TISAX, and regulatory requirements. Oversee technology risk management activities, including identification, assessment, and mitigation of cyber risks across applications, infrastructure, and cloud environments. Manage third-party risk assessments, including vendor onboarding reviews, ongoing monitoring, and alignment to contractual, regulatory, and customer assurance requirements. Develop and deliver monthly cybersecurity governance, risk, compliance, third-party risk, and client assurance metrics and reports to leadership and governance forums (e.g., ISGC), providing insights on risk posture, trends, and remediation progress. Own enterprise security awareness and education programs, including phishing simulations and human firewall initiatives to reduce human risk exposure. Govern the lifecycle of cybersecurity risk exceptions, including intake, review, approval, tracking, and reporting to leadership and governance bodies. Prepare and coordinate materials for the Information Security Governance Committee (ISGC), including metrics, risk reporting, and executive-level insights. Support internal and external audit readiness, including evidence management and coordination for ISO 27001, SOC 2, and other certification activities, ensuring alignment with both regulatory and customer assurance requirements. Collaborate with stakeholders across Legal, Privacy, Risk, Sales, and business units to drive risk remediation, support client-facing assurance needs, and enable secure business operations. What We're Looking For: Required Skills 6-8 years working experience in one or more of areas of controls compliance, tech risk management and/or vendor risk management. Strong experience in cybersecurity governance, risk management, and compliance frameworks (ISO 27001, NIST, TISAX). Proven ability to manage third-party risk programs and vendor security assessments. Experience developing metrics, dashboards, and executive-level reporting for cyber risk and compliance programs. Experience with policy development, audit support, and regulatory compliance activities. Strong communication skills with ability to translate technical risks into business impact and customer-facing assurance messaging. Ability to lead cross-functional initiatives and influence senior stakeholders across Security, Legal, and commercial teams. Problem-solving mindset with strong organizational and analytical skills. If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us! It is the policy of Mobility to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Mobility will provide reasonable accommodations for qualified individuals with disabilities. Mobility delivers Essential Intelligence® that shapes decision making. We provide the world’s leading organizations with the right data, connected technologies and expertise they need to move ahead. As part of our team, you’ll help solve complex challenges that equip businesses, governments and individuals with the knowledge to adapt to a changing economic landscape.
Responsibilities
Lead enterprise-wide cybersecurity governance, policy management, and third-party risk assessments to ensure regulatory and contractual compliance. Develop risk metrics and reports for leadership while managing security awareness programs and audit readiness for certifications like ISO 27001 and SOC 2.
Loading...