Cyber GRC Manager
Bottomline · Greater Bengaluru Area
- Experience5–8 yrs
- SalaryNot disclosed
- Work modeonsite
- Posted28 Sept 2026
About Bottomline
Bottomline is hiring in Greater Bengaluru Area in financial services. This role looks for around 5+ years of experience.
Skills
- information security governance
- cyber risk management
- risk assessments
- compliance oversight
- client assurance
- NIST
- PCI DSS
- SWIFT
- NACHA
- GLBA
The role
A cyber GRC manager at a financial technology company develops information security governance, cyber risk management, and AI governance programs, guiding compliance and client assurance. The role applies NIST, PCI DSS, and CISSP to strengthen regulatory alignment and security posture.
Full job description
Job Summary : This role reports to the Information Security Governance, Risk, and Compliance (GRC) Senior Director and partners across Product, Technology, Operations, Legal, Compliance, and Business teams to strengthen and mature Bottomline's information security, risk, and compliance programs. As the Information Cyber GRC Manager, you will serve as a strategic leader responsible for driving governance, risk management, compliance oversight, and client assurance initiatives. You will build trust and confidence among customers, regulators, auditors, and executive leadership regarding Bottomline's security posture while leading a team of GRC professionals. This role requires a forward-looking mindset, including the ability to assess and manage emerging risks associated with Artificial Intelligence (AI) and support the responsible adoption of AI technologies across the organization.
Essential Functions and Responsibilities:
Governance: Lead the development, maintenance, and execution of the information security governance program, including policies, standards, and controls aligned with regulatory requirements and industry frameworks (e.g., SWIFT, NACHA, PCI DSS, NIST, GLBA). Risk Management: Own the cyber risk management program, including oversight of the risk register, risk assessments, risk treatment plans, and executive reporting. Review and approve risk acceptance decisions using a risk-based approach. Compliance & Regulatory Oversight: Lead compliance activities and assessments to ensure adherence to regulatory, contractual, and industry requirements. Drive audit readiness and remediation efforts across the organization. Client & Security Assurance: Oversee customer security and compliance engagements, including due diligence reviews, security questionnaires, contract reviews, and client assurance activities. Act as a trusted advisor on information security and risk matters. People Leadership: Lead, mentor, and develop a team of Cyber GRC professionals. Establish priorities, manage performance, allocate resources, and drive execution of strategic and operational objectives while fostering a high-performing team culture. AI Governance & Innovation: Lead the evaluation and governance of Artificial Intelligence (AI) technologies and associated risks across the organization. Establish AI risk assessment practices, support responsible AI adoption, and stay at the forefront of emerging AI capabilities, regulatory developments, and industry trends to enhance security, compliance, and operational effectiveness.
Required Experience & Qualifications
Bachelor’s degree in risk management, cybersecurity, technology, or equivalent
Preferred Experience & Qualifications Professional certifications such as CISSP, CISM, CRISC, CISA, CGRC, or equivalent. Strong knowledge of regulatory and industry frameworks, including SWIFT, NACHA, PCI DSS, NIST, and GLBA. Experience with AI governance frameworks, AI risk management, and emerging regulatory requirements related to artificial intelligence. Experience leveraging automation, analytics, and AI-driven capabilities within security, risk, and compliance programs.
Note: This job description is not intended to be an exhaustive list of all duties, responsibilities, or qualifications associated with the position.