LTIMindtree

Senior GRC Consultant with AI skills(Onsite)

LTIMindtree$110K — $130K *
Finance & Insurance
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in cybersecurity and governance, risk, and compliance (GRC) roles
  • Proven expertise in leading and maturing GRC teams in a technology-focused environment
  • Hands-on experience with cybersecurity frameworks like SOC 1, SOC 2, and ISO 27001
  • Strong understanding of regulatory requirements for financial institutions
  • Familiarity with AI technologies, security, and emerging threats in SaaS and financial services
  • Excellent communication skills for stakeholder engagement at all levels

Responsibilities

  • Lead and develop a team of GRC professionals, establishing clear roles and performance metrics
  • Maintain and execute a multi-year GRC roadmap aligned with business and regulatory priorities
  • Steer GRC practices in alignment with Corporate CISO organization while addressing specific client needs
  • Provide tactical support to teams, remove obstacles, and ensure actions are completed effectively
  • Own the GRC framework, managing risk registers, control libraries, and audit processes
  • Lead various internal and external audits, ensuring compliance with security and regulatory standards
  • Serve as the primary lead during security incidents, managing all related communications and actions

Benefits

  • Opportunity to work in a hands-on leadership role within a growing cybersecurity team
  • Engagement with multiple stakeholders, including product managers and engineering teams
  • Be part of an evolving and proactive approach to AI security and risk management
  • Access to ongoing training and development within the field of cybersecurity
  • Potential to influence the security posture at a financial technology firm
Full Job Description
Role description

Senior GRC Consultant with AI skills

Mississauga, ON(Onsite)

The Senior Leader Cybersecurity is the accountable cybersecurity and GRC leader .

This handson role sets direction and drives execution across information security governance risk compliance privacy resilience and security incident response for a platform product and SaaS business serving financial institutions .

The leader will translate regulatory contractual and emerging threat requirements into a prioritized roadmap measurable actions and sustainable operating practices

The role leads the GRC team of three aligns with the Corporate CISO organization and works directly with all levels of clients auditors product managers architects engineering testing delivery and support teams.

The successful candidate must be comfortable moving between strategic leadership client engagement operational decisionmaking and detailed follow through

Primary Outcomes

An integrated riskbased cybersecurity and GRC roadmap aligned to FSTI business priorities and the Corporate CISO strategy.

Clear ownership prioritization and closure of security risk audit privacy resilience and compliance actions.

Decisive leadership of security incidents including coordination stakeholder communication remediation lessons learned and closure.

A mature GRC team structure and operating model that scales as FSTI products clients regulations technologies and delivery patterns evolve.

Client confidence through transparent monthly GRC and security cadences evidencebased reporting and timely responses to security and compliance requests.

Practical controls for AI enabled products AI use thirdparty AI services and emerging cyber threats.

Key Responsibilities

Leadership Strategy Operating Model.

Lead coach and mature the FSTI GRC team of three establishing clear roles objectives decision rights governance forums and performance measures.

Own and maintain a multiyear cybersecurity and GRC roadmap translating business regulatory client audit and threat priorities into funded and sequenced initiatives.

Align FSTI security practices standards exceptions and reporting with the Corporate LTM CISO organization while addressing FSTIspecific product SaaS and client requirements.

Operate effectively across a global delivery model partnering with primarily onshore leaders and product managers and predominantly offshore engineering testing support and delivery teams including teams in offshore.

Provide handson guidance remove roadblocks escalate material risks and drive actions to measurable completion.

Governance Risk Compliance Assurance.

Own the FSTI GRC framework risk register control library policy and standards lifecycle exception process issue management and executive reporting.

Lead internal and external audits and assessments including SOC 1 SOC 2 ISO 27001 NISTaligned reviews client audits and other applicable assurance activities.

Interpret regulatory contractual and privacy obligations applicable to financial institutions and technology service providers and map them to FSTI controls evidence and accountable owners.

Drive vulnerability penetration testing access governance thirdparty risk security awareness business continuity disaster recovery and remediation governance to closure.

Partner with legal privacy procurement architecture product engineering and operations teams to embed Security and Privacy by Design across the product lifecycle.

Security Incident Emerging Threat Leadership.

Serve as the FSTI lead for confirmed or suspected security incidents coordinating triage containment investigation recovery communications required notifications corrective actions and lessons learned with Corporate CISO and business stakeholders.

Establish clear incident roles escalation criteria decision paths communications protocols and exercise schedules for cyber privacy thirdparty cloud and product related scenarios.

Monitor threat intelligence and emerging risks assess applicability to FSTI prioritize response actions assign owners track progress and report residual risk.

Anticipate threats affecting financialservices technology and SaaS environments including identity compromise software supplychain risk ransomware cloud misconfiguration API abuse data leakage third party concentration risk and AI enabled attacks.

AI Security Responsible AI Risk.

Develop and operationalize governance for approved AI use AIenabled product capabilities generative AI machine learning and thirdparty AI services in alignment with enterprise requirements.

Assess AIspecific threats and control needs including sensitivedata exposure prompt injection insecure model or plugin integration model and data supplychain risk excessive agency unreliable output abuse privacy intellectualproperty and regulatory risk

About LTIMindtree

LTIMindtree is a global technology consulting and digital solutions company that enables enterprises across industries to reimagine business models, accelerate innovation, and maximize growth by harnessing digital technologies. As a digital transformation partner to more than 700+ clients, LTIMindtree brings extensive domain and technology expertise to help drive superior competitive differentiation, customer experiences, and business outcomes in a converging world. Powered by nearly 90,000 talented and entrepreneurial professionals across 30+ countries, LTIMindtree — a Larsen & Toubro Group company — combines the industry-acclaimed strengths of erstwhile Larsen and Toubro Infotech and Mindtree in solving the most complex business challenges and delivering transformation at scale.
Learn more about LTIMindtree

Similar Jobs

More Jobs at LTIMindtree

More Finance & Insurance Jobs

Find similar Senior GRC Consultant with AI skills(Onsite) jobs: