TRCD-26-04850
GRC Consultant (Cyber & Digital Risk)
Contract GRC Consultant (3–5 years) to support Cyber & Digital Risk work across ISO 27001 ISMS implementation/sustenance and audit readiness, emerging AI governance via ISO 42001, privacy compliance (GDPR and India DPDPA), and third-party/vendor risk management. The role will maintain risk registers and exception workflows, produce ISMS KPI/KRI reporting for leadership, and coordinate closely with InfoSec, IT, Legal, Privacy, Procurement, and business stakeholders in Mumbai (Goregaon) / Gurgaon.
Position summary
- Location
- India
- Workplace
- On-site
- Employment
- Contract
- Experience
- Minimum 3 years and Maximum 5 years
Role overview
Why This Role Matters.
Contract GRC Consultant (3–5 years) to support Cyber & Digital Risk work across ISO 27001 ISMS implementation/sustenance and audit readiness, emerging AI governance via ISO 42001, privacy compliance (GDPR and India DPDPA), and third-party/vendor risk management. The role will maintain risk registers and exception workflows, produce ISMS KPI/KRI reporting for leadership, and coordinate closely with InfoSec, IT, Legal, Privacy, Procurement, and business stakeholders in Mumbai (Goregaon) / Gurgaon.
Your Impact
Deliver Enterprise Value
Help organisations solve complex business problems through modern technology, consulting expertise and measurable outcomes.
Collaboration
Work Across Teams
Collaborate with consultants, architects, engineers and client stakeholders throughout the project lifecycle.
Growth
Learn Continuously
Gain exposure to enterprise technologies, certifications, mentoring and real-world project experience.
Career Path
Grow With Ubique
Build a long-term consulting career with opportunities to take on greater responsibility and leadership over time.
Responsibilities
What You'll Be Doing.
Every role at Ubique contributes directly to solving meaningful business challenges for our clients.
Privacy & Vendor Risk Management: Oversee GDPR and DPDPA data privacy implementations alongside comprehensive third-party/vendor risk assessments.
Risk & Compliance Operations: Maintain enterprise risk registers, manage exception processes, track risk remediation, and govern ISMS Key Performance/Risk Indicators (KPIs/KRIs).
Cross-Functional Collaboration: Serve as a bridge between Information Security, IT, Legal, Privacy, Procurement, and business stakeholders.
ISMS & Compliance Implementation: Support end-to-end ISO 27001 ISMS lifecycle management, governance frameworks, and audit readiness.
AI Governance Support: Assist in implementing and operationalizing ISO 42001 (AI Management System) controls, risk assessments, and governance structures.
Third-Party Risk Management (TPRM): Conduct third-party and vendor risk assessments, security evaluations, and periodic vendor reviews.
Data Privacy Operations: Support GDPR and DPDPA compliance frameworks, privacy impact assessments, operations, and documentation.
Risk Register & Exception Management: Manage risk acceptance and exception workflows (review, approval, tracking) while actively maintaining and updating the enterprise risk register.
Metrics & Reporting: Collect, monitor, and report on ISMS KPIs/KRIs, preparing executive management reports.
Stakeholder Coordination: Act as a central point of contact, coordinating smoothly with InfoSec, Legal, Privacy, Procurement, and business teams.
Technology stack
Tools & Technologies.
The platforms and technologies you'll use to build modern, enterprise-grade solutions.
GRC
Cyber & Digital Risk
ISO 27001
ISMS
ISO 42001
AI Management System
AI governance
GDPR
DPDPA
data privacy
TPRM
third-party risk
vendor risk
risk register
risk remediation
exception management
risk acceptance
KPI
KRI
audit readiness
Requirements
Skills & Experience.
We value curiosity, collaboration and continuous learning. If you don't meet every requirement but believe you can make an impact, we'd still love to hear from you.
Essential
Required Qualifications
3–5 years experience in GRC / Information Security Risk / Compliance
ISO 27001 ISMS implementation and sustenance (end-to-end lifecycle)
Audit readiness support for ISO 27001
Working knowledge of ISO 42001 (AI Management System)
GDPR knowledge and implementation support
DPDPA (India) knowledge and implementation support
Third-party/vendor risk assessments (TPRM) and periodic vendor reviews
Risk management fundamentals: risk registers, risk remediation tracking
Exception/risk acceptance workflow management (review/approval/tracking)
ISMS KPI/KRI metrics collection, monitoring, and executive reporting
Strong documentation skills
Stakeholder management and cross-functional coordination
Communication skills
Preferred
Nice to Have
Familiarity with GRC platforms: Sprinto
Familiarity with GRC platforms: MetricStream
Familiarity with GRC platforms: ServiceNow (GRC)
Familiarity with GRC platforms: RSA Archer
Privacy Impact Assessments (PIA/DPIA) execution support
What you'll gain
More Than Just A Job.
We're committed to helping every team member grow professionally, personally and technically while working on meaningful projects.
Global Exposure
Collaborate with international clients and multicultural teams on enterprise programmes.
Continuous Learning
Expand your expertise through mentoring, certifications and hands-on project experience.
Career Growth
Take ownership, develop leadership skills and grow your consulting career over time.
Flexible Working
Hybrid and remote collaboration designed around trust and delivering exceptional outcomes.
People First
Join a supportive culture where collaboration, respect and long-term relationships come first.
Enterprise Projects
Work on meaningful technology initiatives for leading organisations across industries.
Apply
Apply for GRC Consultant (Cyber & Digital Risk)
One page, about two minutes. We only ask for what we actually need to have a first conversation.