Manager - Governance, Risk & Compliance
Legal
Pune, Maharashtra, India
ZS is a place where passion changes lives. As a management consulting and technology firm focused on improving life and how we live it, we transform ideas into impact by bringing together data, science, technology and human ingenuity to deliver better outcomes for all. Here you’ll work side-by-side with a powerful collective of thinkers and experts shaping life-changing solutions for patients, caregivers and consumers, worldwide. ZSers drive impact by bringing a client-first mentality to each and every engagement. We partner collaboratively with our clients to develop custom solutions and technology products that create value and deliver company results across critical areas of their business. Bring your curiosity for learning, bold ideas, courage and passion to drive life-changing impact to ZS.
Manager — GRC
Technical Audit & Assurance · AI Risk Governance · Project Risk
About ZS
ZS is a professional services firm that works side by side with companies to help develop and deliver products that drive customer value and company results. From R&D to portfolio strategy, customer insights, marketing and sales, operations, and technology, we leverage data, science, and technology to enable higher-impact decisions, sharper execution, and more transformative outcomes. ZS has more than 15,000 employees worldwide, operating from 40+ offices across the Americas, Europe, and Asia-Pacific, and is trusted by the world's leading pharmaceutical, biotech, medtech, and technology companies.
About the GRC Function
Governance, Risk & Compliance (GRC) is ZS's enterprise-wide second-line governance function — governing the integrity of the firm's control environment, managing the certification and assurance portfolio, and providing the independent risk signal that enables leadership to make informed decisions with confidence.
The function operates alongside ERM and Legal/Compliance within ZS's governance structure and works closely with the ZS's Delivery Excellence (DEX) organization for delivery governance and audit. GRC's four accountability areas span control environment integrity, regulatory and certification compliance, risk intelligence and oversight, and delivery and operational assurance. The function is midway through a deliberate expansion of its assurance capabilities, and this role is central to that growth.
The Role
The Manager – GRC (Technical Audit & Assurance) is a senior individual contributor and program leader responsible for GRC's technical audit and assurance capabilities. The role leads client security audits, owns GRC's AI risk governance workstream, and strengthens the Project Risk Assessment (PRA) program through technical depth and independent oversight.
The Manager works closely with three peer leads — Certifications & Compliance, Risk Operations, and Third-Party Risk & Data Compliance — and is a key partner to the Delivery Excellence organization and ZS's Technology, Platform Services and Client Service organizations. The role reports to the Head of GRC.
Key Responsibilities
Client & Delivery Security Audit Program
Lead GRC's client and delivery security audit program — independent, evidence-based reviews of security and governance controls in live client engagements and across ZS's delivery organization.
- Manage end-to-end audit execution: scoping, walkthroughs, evidence review, observation validation, management response, remediation tracking, and governance reporting
- Design and evolve the audit methodology, observation framework, and risk-based intake model — ensuring rigor, consistency, and scalability across engagements
- Execute with genuine technical depth across key control domains: SDLC governance, CI/CD security, access management, change control, secrets management, endpoint security, data protection, and logging
- Coordinate audit logistics with Client Service Teams, ISBP, Information Security, and project leadership — presenting a coordinated assurance response to clients
- Aggregate cross-client and cross-program findings into thematic insights; report recurring patterns to GRC leadership, DEX governance forums, and relevant steering groups
AI Risk Governance
Own GRC's AI risk and compliance governance workstream — building the assessment methodology, control framework, and assurance infrastructure that enables ZS to scale AI-enabled delivery responsibly and credibly.
- Design and operationalize AI risk assessments for projects using AI and agentic tools — evaluating model risk, data governance, human review controls, security validation, output monitoring, and client data protection
- Develop the AI controls framework: approved tool governance, risk acceptance standards, monitoring requirements, and privacy alignment
- Lead GRC's evaluation and adoption of AI assurance credentials — including AIUC-1, ISO 42001, NIST AI RMF, and EU AI Act requirements — and advise leadership on appropriate adoption
- Translate AI adoption signals from across ZS's delivery organization into governance insights for Leadership Steering Committees
- Partner with Information Security, Cloud Centre of Excellcne, Legal, and Privacy to ensure ZS's AI governance framework is coherent across technology, security, regulatory, and delivery dimensions
Project Assurance — PRA and Special Interventions
Strengthen the Project Risk Assessment (PRA) program — GRC's unified governance gate for client-facing projects — through technical rigor, assurance quality, and hands-on intervention capability.
- Bring technical depth to PRA scoping and risk identification — ensuring AI, security, privacy, GxP, and regulatory dimensions are correctly flagged and governed from project outset
- Lead rapid diagnostic assessments and special assurance interventions for high-risk, complex, or escalated projects — providing in-flight control reviews and targeted remediation planning
- Partner with the Delivery Excellence team to ensure project governance and delivery assurance operate as a single, integrated view rather than parallel tracks
- Support the continuous improvement of PRA methodology — incorporating learnings from audit findings, client engagement patterns, and evolving risk themes
GxP and Life Sciences Compliance (specialization valued)
ZS serves leading life sciences organizations across pharma, biotech, payer, and healthcare sectors. Candidates with GxP, CSV, or 21 CFR Part 11 experience will find an active need in this role — providing specialist assurance coverage on life sciences client engagements, contributing to GxP audit frameworks, and advising CSTs and project teams on regulatory compliance requirements within GRC's scope.
Stakeholder Engagement and Reporting
- Build trusted relationships with Technology and Platforms Practice, Client Service Teams, Information Security, Legal, and Delivery Excellence leadership — positioning GRC's assurance capabilities as a business enabler
- Prepare and present findings, governance updates, and program insights for GRC leadership, and senior stakeholder / leadership committees and groups.
- Support GRC's broader stakeholder engagement — contributing to how GRC communicates its mandate, capabilities, and value across the firm
Skills, Experience & Qualifications
Professional Experience
- 10–12 years of professional experience in IT audit, technology risk, cyber assurance, or technical GRC — with significant experience at a Big 4, Big 3, or specialist assurance firm, or in a technically deep GRC / compliance leadership role within a regulated industry
- Demonstrated track record of leading and executing technical security audits — hands-on experience conducting walkthroughs, reviewing evidence, and making independent control assessments
- Strong technical foundation across SDLC governance, CI/CD pipeline security, cloud security controls, access and identity management, application security, and secrets management
- Experience designing and building assurance program from concept through to operational delivery — not solely inheriting established frameworks
- Proven ability to engage confidently with senior stakeholders — client service leaders, C-suite, and cross-functional enterprise teams — and translate technical findings into clear leadership communication
- GxP, CSV, or 21 CFR Part 11 experience is a strong differentiator for this role, given ZS's active life sciences client base
Core Technical Expertise
- Security standards and frameworks: ISO 27001/27017/27701, SOC 2 Type II, HITRUST CSF, NIST CSF — strong working familiarity and audit experience
- SDLC and application security: code review governance, CI/CD pipeline security controls, vulnerability management, SAST/DAST, release governance, and traceability
- Cloud security: cloud control frameworks, container security, secrets management, infrastructure-as-code governance
- AI governance and risk frameworks: NIST AI RMF, ISO 42001, EU AI Act — awareness and growing expertise valued; prior experience with AI/ML assurance is a strong advantage
- GxP / life sciences: 21 CFR Part 11, GCP/GMP/GLP, CSV / computer systems validation — valued, not required
Leadership and Behavioral Competencies
- Technically credible and precise — able to interpret a CI/CD configuration, assess access governance control, and make an independent judgement on whether a finding is material
- Clear and structured communicator — translates complex technical findings into leadership-ready observations and actionable guidance for delivery teams
- Self-directed and accountable — comfortable owning a program end-to-end with a high degree of independence
- Collaborative across functions — builds working relationships with delivery, product, legal, infosec, and client-facing teams without relying on formal authority
- Composed and professional in high-stakes contexts — client security audits and project assurance reviews involve commercial sensitivity and senior stakeholder scrutiny
Education & Certifications
Education
- Bachelor's degree required — Computer Science, Information Systems, Engineering, or a related technical discipline
- Master's degree preferred — technical discipline, MBA, or equivalent
Certifications (preferred — not all required)
- CISA (Certified Information Systems Auditor) — highest value for this role
- CISSP or CISM — for technical security depth
- ISO 27001 Lead Auditor
- GIAC certifications — GSNA, GPEN, or equivalent security audit and assessment credentials
- NIST AI RMF Practitioner or equivalent AI governance credential — or actively pursuing
- GxP / CSV / 21 CFR Part 11 specialist accreditation — valued where applicable
What Makes This Role Unique
- GRC at ZS has direct access to various internal ZS Leadership Steering Committee and Forums (e.g., Risk, Compliance & Professionalism Committee, Audit Committee, Information Security Working Group, etc.) the visibility and impact for a manager are meaningful and early
- The technical audit and AI risk governance program are actively scaling — this is an opportunity to shape methodology and grow capability, not maintain an inherited framework
- The role sits at the intersection of technical assurance, enterprise governance, and AI risk — a combination that is increasingly rare and commercially relevant
- ZS's global delivery footprint and 15,000+ person scale create a complex, high-interest assurance environment across Technology, I&A, and Strategy & Transformation practices
ZS is committed to building an inclusive and diverse workforce and welcomes applications from all qualified candidates. We are an equal opportunity employer.
How you’ll grow:
- Cross-functional skills development & custom learning pathways
- Milestone training programs aligned to career progression opportunities
- Internal mobility paths that empower growth via s-curves, individual contribution and role expansions
Perks & Benefits:
At ZS, your growth matters. We offer a comprehensive total rewards package that supports your health and well‑being, financial future, time away, and professional development. With robust skills‑building programs, multiple career progression paths, internal mobility, and a deeply collaborative culture, you’ll have the opportunity to do meaningful work, expand your capabilities, and thrive as part of a global community. For details on total rewards in India, visit ZS India office locations | Where we work | ZS.
Hybrid working model:
We are committed to giving our employees a flexible and connected way of working. A flexible and connected ZS allows us to combine work from home and on-site presence at clients/ZS offices for the majority of our week. The magic of ZS culture and innovation thrives in both planned and spontaneous face-to-face connections.
Travel:
Travel is a requirement at ZS for client facing ZSers; business needs of your project and client are the priority. While some projects may be local, all client-facing ZSers should be prepared to travel as needed. Travel provides opportunities to strengthen client relationships, gain diverse experiences, and enhance professional growth by working in different environments and cultures.
Considering applying?
At ZS, we honor the visible and invisible elements of our identities, personal experiences, and belief systems—the ones that comprise us as individuals, shape who we are, and make us unique. We believe your personal interests, identities, and desire to learn are integral to your success here. We are committed to building a team that reflects a broad variety of backgrounds, perspectives, and experiences. Learn more about our inclusion and belonging efforts and the networks ZS supports to assist our ZSers in cultivating community spaces and obtaining the resources they need to thrive.
If you’re eager to grow, contribute, and bring your unique self to our work, we encourage you to apply.
ZS is an equal opportunity employer and is committed to providing equal employment and advancement opportunities without regard to any class protected by applicable law.
To complete your application:
Candidates must possess or be able to obtain work authorization for their intended country of employment. An on-line application, including a full set of transcripts (official or unofficial), is required to be considered.
NO AGENCY CALLS, PLEASE.
Find Out More At:
www.zs.com