Z

Manager - Governance, Risk & Compliance

ZS Associates · State of Mahārāshtra, India

~₹25L (est.)7–15 yrs experienceRemotePosted 6 days ago

Job description

: **ZS** is a place where passion changes lives. As a management consulting and technology firm focused on improving life and how we live it, we transform ideas into impact by **bringing together data, science, technology** and **human ingenuity** to deliver better outcomes for all. Here you’ll work side-by-side with a powerful collective of thinkers and experts shaping life-changing solutions for patients, caregivers and consumers, worldwide. ZSers drive impact by bringing a **client-first mentality** to each and every engagement. We partner collaboratively with our clients to develop custom solutions and technology products that create value and deliver company results across critical areas of their business. Bring your curiosity for learning, bold ideas, courage and passion to drive life-changing impact to ZS. : **Manager — GRC** Technical Audit & Assurance · AI Risk Governance · Project Risk **About ZS** ZS is a professional services firm that works side by side with companies to help develop and deliver products that drive customer value and company results. From R&D to portfolio strategy, customer insights, marketing and sales, operations, and technology, we leverage data, science, and technology to enable higher-impact decisions, sharper execution, and more transformative outcomes. ZS has more than 15,000 employees worldwide, operating from 40+ offices across the Americas, Europe, and Asia-Pacific, and is trusted by the world's leading pharmaceutical, biotech, medtech, and technology companies. **About the GRC Function** Governance, Risk & Compliance (GRC) is ZS's enterprise-wide second-line governance function — governing the integrity of the firm's control environment, managing the certification and assurance portfolio, and providing the independent risk signal that enables leadership to make informed decisions with confidence. The function operates alongside ERM and Legal/Compliance within ZS's governance structure and works closely with the ZS's Delivery Excellence (DEX) organization for delivery governance and audit. GRC's four accountability areas span control environment integrity, regulatory and certification compliance, risk intelligence and oversight, and delivery and operational assurance. The function is midway through a deliberate expansion of its assurance capabilities, and this role is central to that growth. **The Role** The Manager – GRC (Technical Audit & Assurance) is a senior individual contributor and program leader responsible for GRC's technical audit and assurance capabilities. The role leads client security audits, owns GRC's AI risk governance workstream, and strengthens the Project Risk Assessment (PRA) program through technical depth and independent oversight. The Manager works closely with three peer leads — Certifications & Compliance, Risk Operations, and Third-Party Risk & Data Compliance — and is a key partner to the Delivery Excellence organization and ZS's Technology, Platform Services and Client Service organizations. The role reports to the Head of GRC. **Key Responsibilities** **Client & Delivery Security Audit Program** Lead GRC's client and delivery security audit program — independent, evidence-based reviews of security and governance controls in live client engagements and across ZS's delivery organization. - Manage end-to-end audit execution: scoping, walkthroughs, evidence review, observation validation, management response, remediation tracking, and governance reporting - Design and evolve the audit methodology, observation framework, and risk-based intake model — ensuring rigor, consistency, and scalability across engagements - Execute with genuine technical depth across key control domains: SDLC governance, CI/CD security, access management, change control, secrets management, endpoint security, data protection, and logging - Coordinate audit logistics with Client Service Teams, ISBP, Information Security, and project leadership — presenting a coordinated assurance response to clients - Aggregate cross-client and cross-program findings into thematic insights; report recurring patterns to GRC leadership, DEX governance forums, and relevant steering groups **AI Risk Governance** Own GRC's AI risk and compliance governance workstream — building the assessment methodology, control framework, and assurance infrastructure that enables ZS to scale AI-enabled delivery responsibly and credibly. - Design and operationalize AI risk assessments for projects using AI and agentic tools — evaluating model risk, data governance, human review controls, security validation, output monitoring, and client data protection - Develop the AI controls framework: approved tool governance, risk acceptance standards, monitoring requirements, and privacy alignment - Lead GRC's evaluation and adoption of AI assurance credentials — including AIUC-1, ISO 42001, NIST AI RMF, and EU AI Act requirements — and advise leadership on appropriate adoption - Translate AI adoption signals from across ZS's delivery organization into governance insights for Leadership Steering Committees - Partner with Information Security, Cloud Centre of Excellcne, Legal, and Privacy to ensure ZS's AI governance framework is coherent across technology, security, regulatory, and delivery dimensions **Project Assurance — PRA and Special Interventions** Strengthen the Project Risk Assessment (PRA) program — GRC's unified governance gate for client-facing projects — through technical rigor, assurance quality, and hands-on intervention capability. - Bring technical depth to PRA scoping and risk identification — ensuring AI, security, privacy, GxP, and regulatory dimensions are correctly flagged and governed from project outset - Lead rapid diagnostic assessments and special assurance interventions for high-risk, complex, or escalated projects — providing in-flight control reviews and targeted remediation planning - Partner with the Delivery Excellence team to ensure projec