Operational Risk Manager at Pluginlive · Mumbai · 4 - 20 years · ₹20L - ₹40L / yr · Bootstrapped · Posted 30 Sep 2024

Role/ Job Title: Specialist-IT Governance & Compliance (IT Operational Risk Management)
Function/ Department: Information Technology
Roles & Responsibilities:
- Review of Policies, Product Notes, Product notes / Standard Operating Procedures from Operational Risk perspective and documentation of risk register for banking channels/products for e.g. Internet banking, Mobile Banking, UPI, Corporate Internet Banking, ENACH, E-Toll, SMS, IVR Banking etc. and IT & ISG
- Control Self testing to be conducted, to evaluate efficiency of controls claimed as per the Risk and Control Matrix.
- Identification and monitoring of Key Risk Indicators (KRI’s) for units ensuring that deteriorating KRIs are tracked for resolution and remedial measures for getting back to acceptable levels.
- Tracking & Monitoring of Incidents reported, corrective/preventive actions taken in timely manner by assigned units for e.g. Digital banking units, IT and ISG. Investigating the same and assuring that necessary corrective action and preventive action are provided by the unit before finalizing the same with the ORM team.
- Review of the action points implemented and leading the remediation of the Audit observations to closure whereby the controls implemented stand the test of review and avoidance of recurrence.
- Defining, implementing and functionalizing a Risk Management Frameworks and Programs in collaboration with various stake holders.
- Strengthen Operational Risk Framework and ensure implementation and governance process through periodic MIS and engagements with stake holders on remedial plans.
- Help and train stakeholders in ensuring adherence to Operational Risk Frameworks.
- Senior Management reporting work such as preparation of presentations, minutes of meeting etc.
- Excellent written and verbal communications skills.
Required Skills:
- Technical, functional knowledge and experience of working in risk team and have relevant experience of working in Banking channels for e.g. Internet Banking & Mobile banking, UPI etc and IT and ISG areas.
- Shall have good knowledge and experience of Information Technology (IT) applications and IT/Information Security risks and controls review.
- Shall have good knowledge and understanding of Third party/vendor involvement and various fintech models involved in digital banking space.
- Ability to drive periodic updates to senior management and remediation programs in line with Risk Management Practices
- Ability to Drive Remediation Programs on corrective Action plans in a timely manner through effective governance.
Education Qualification (Fulltime):
Certified Chartered Accountant (CA)
Preferred Certifications: CISA, ISO27001/002 (ISMS), ISO22301(BCMS), CISM, CRISC.
Experience:
Minimum of 5+ Years in IT ORM, IT applications risks and controls reviews.

About Pluginlive
About
Connect with the team
Company social profiles
Similar jobs (7)
This role is focused on Cyber Security Risk, Governance, Risk & Compliance (GRC), IT Controls, and Security Audits, with strong emphasis on Backup, Disaster Recovery (DR), and Business Continuity (BCP).
Key responsibilities:
- Perform security control assessments against organizational policies, security standards, and regulatory requirements.
- Identify control gaps, risks, audit findings, and compliance issues, and monitor remediation until closure.
- Assess Backup, Disaster Recovery, and Business Continuity processes and controls.
- Validate backup availability, restoration/recovery procedures, DR readiness, and evidence of periodic DR/BCP testing.
- Conduct control testing and risk assessments and support internal/external security audits.
- Review security policies, procedures, standards, and governance frameworks for compliance.
- Maintain audit evidence, track findings, and coordinate with stakeholders for remediation.
- Support overall security governance, regulatory compliance, and IT risk management activities.
Required Skills
- Cyber Security Risk & Compliance / GRC
- IT Risk & Controls
- Security Control Assessment & Testing
- Security Audits
- Backup & Disaster Recovery
- BCP / DR
- Risk Assessment
- Compliance & Governance
- Security Policies & Standards
- Audit Finding & Remediation Management
IT Compliance Manager – Web3 & Digital Assets
📍 Location: Dubai, UAE
💼 Employment Type: Full-Time
🏢 Department: Technology / Compliance
📊 Experience: 5+ Years
🌐 Industry: FinTech / Web3 / Digital Assets
About the Role
We are looking for an experienced IT Compliance Manager – Web3 & Digital Assets to lead technology compliance, IT governance, risk management, and cybersecurity controls within a regulated FinTech and digital-asset environment.
The ideal candidate will have strong experience in IT GRC, technology risk, cybersecurity governance, Web3/blockchain, digital assets, and regulatory compliance, with UAE regulatory experience being highly preferred.
Key Responsibilities
- Manage IT governance, compliance frameworks, policies, procedures, and technology risk assessments.
- Support compliance with UAE virtual asset and financial-services regulations, including VARA, DFSA, FSRA, and UAE Central Bank requirements, where applicable.
- Assess technology risks across blockchain infrastructure, crypto wallets, custody, APIs, cloud platforms, databases, smart contracts, and dApps.
- Review controls related to crypto deposits, withdrawals, transfers, wallet operations, and transaction monitoring.
- Develop and monitor controls aligned with ISO 27001, SOC 2, NIST, PCI DSS, and relevant regulatory requirements.
- Coordinate IT audits, regulatory audits, compliance assessments, evidence collection, and remediation activities.
- Maintain technology risk registers, control assessments, compliance reports, and management dashboards.
- Partner with Engineering, Product, Security, Legal, Risk, AML/KYC, Finance, and Operations teams.
- Embed compliance and technology-risk requirements into product development, system changes, and technology architecture.
- Support regulatory licensing, assessments, and ongoing compliance requirements for digital-asset services.
Requirements
- Bachelor's degree in IT, Computer Science, Cybersecurity, Finance, Risk Management, or a related discipline.
- 5+ years of experience in IT Compliance, IT GRC, Technology Risk, Cybersecurity Governance, or a related field.
- Experience in FinTech, banking, payments, cryptocurrency, blockchain, digital assets, or financial services.
- Strong understanding of Web3, blockchain networks, crypto wallets, digital-asset transactions, custody, and smart-contract risks.
- Hands-on experience with IT governance, risk assessments, control testing, audits, and compliance frameworks.
- Strong knowledge of ISO 27001, SOC 2, NIST, PCI DSS, ITGC, or similar frameworks.
- Experience working with auditors, regulators, and cross-functional technology teams.
- Strong analytical, documentation, communication, and stakeholder-management skills.
UAE / Web3 Experience – Preferred
- Experience with VARA, DFSA, FSRA, UAE Central Bank, or other UAE financial regulators.
- Experience supporting VASP licensing or regulatory approvals.
- Previous experience in crypto exchanges, digital-asset platforms, blockchain companies, Web3 startups, or FinTech organizations.
- Understanding of AML/KYC, transaction monitoring, custody, wallet security, and digital-asset controls.
Preferred Certifications
- CISA
- CISM
- CISSP
- CRISC
- ISO 27001 Lead Auditor / Lead Implementer
- CAMS
Key Skills
IT GRC | IT Compliance | Technology Risk | Web3 Governance | Blockchain Risk | Digital Asset Compliance | VASP Licensing | UAE Regulatory Compliance | ITGC | Cybersecurity Governance | ISO 27001 | SOC 2 | NIST | PCI DSS | IT Audit | Risk Assessment | Crypto Transaction Monitoring | Stakeholder Management
Job title Sox Compliance Officer
Reporting to Potentiam company background (The Employer) Potentiam is a global provider of highly qualified professionals to European SMEs from our offices in Romania, South Africa and India. Potentiam works with clients in finance, energy, leisure, marketing, business services and technology industries, providing technical, professional multi- lingual highly motivated staff, most of whom have had experience of working for international companies. Staff cover a wide range of roles from accounting, marketing, data management, HR, sales/account management, engineering, technology, and operations. Potentiam manages our staff’s career development and personal development training, all infrastructure, HR and payroll with our clients directly managing day-to-day staff responsibilities and role training and development. Company website - https://potentiam.co.uk/
Potentiam’s client: It is a leading provider of independent medical examinations, peer reviews, bill reviews, Medicare compliance, record retrieval, document management and related services. It provide IME services through their medical panel of credentialed physicians and allied medical professionals. Their independent medical review process is fully contained within their private cloud network. Custom portals, applications, workflow enhancements and systems integration are part and parcel of their service. Their clients include property and casualty insurance carriers, law firms, third-party claim administrators and government agencies that use independent services to confirm the veracity of claims by sick or injured individuals under automotive, disability, liability and workers' compensation insurance coverages. They help clients in the U.S., Canada, the United Kingdom and Australia manage costs and enhance their risk management processes by verifying the validity of claims, identifying fraud and providing fast, efficient and quality IME services.
Industry: legal, insurance, and healthcare services.
Purpose of role:
We are seeking a Compliance Officer to join our compliance team. This role is responsible for auditing IT control activities, ensuring adherence to Sarbanes Oxley (SOx) requirements, and maintaining governance standards. The ideal candidate will work closely with external auditors, perform Entity-Level Controls (ELCs), and document narratives, processes, and procedures in a fast paced environment. Potentiam | Job Specification 2 of 2
Duties and responsibilities: Compliance & Audit Activities • Audit IT control operations performed by IT Controls Analysts to ensure compliance with SOx requirements. • Perform walkthroughs and testing of ITGCs and ELCs to validate control design and operating effectiveness. • Develop, maintain, and update SOx narratives, process flows, and control documentation. • Coordinate and liaise with external auditors during SOx audits and provide requested evidence. • Identify control gaps and recommend remediation plans in collaboration with stakeholders. • Experience with ISO 27001 and NIST CSF, including understanding of information security controls, risk management, control assessments, compliance requirements, and security governance practices. • Familiarity with Cyber Essentials Plus (CE+) and related security/compliance requirements, along with knowledge or experience using Vanta or similar GRC/compliance management platforms, is a strong plus. Governance & Reporting • Prepare compliance reports and dashboards for management review. • Ensure timely completion of SOx testing cycles and documentation updates. • Support risk assessments and contribute to strengthening the overall control environment. Collaboration & Communication • Work closely with IT, Finance, and Compliance teams to align SOx requirements with business processes. • Act as a point of contact for external auditors and internal stakeholders. • Provide training and guidance on SOx compliance and control documentation standards.
Skills/Experience • Experience in SOx compliance, auditing, and governance processes. • Strong knowledge of Entity-Level Controls (ELCs), ITGCs, and SOx documentation standards. • Experience with ISO 27001 and NIST CSF, including security controls, risk assessment, and compliance. • Familiarity with CE+ and Vanta or similar GRC/compliance platforms is a strong plus. • Ability to create and maintain narratives, process flows, and control matrices. • Excellent communication and stakeholder management skills. • Detail-oriented with strong analytical and problem-solving capabilities. Why Join Us? • Opportunity to play a critical role in compliance and governance initiatives. • Collaborative team environment with exposure to senior leadership and external auditors. • Professional growth in a dynamic, fast-paced environment.
Additional benefits • Health Insurance • Referral Bonus • Performance Bonus • Flexible Working options
Location and hours Bangalore Office / UK hours
Read less

We are seeking an experienced Governance, Risk & Compliance (GRC) Lead to spearhead the
design, implementation, and maintenance of our ISO 27001 Information Security Management
System (ISMS). This is a hands-on leadership role responsible for establishing a robust security
governance framework, achieving ISO 27001 certification, and embedding a culture of
continuous security improvement across the organization.
Key Responsibilities
● ISMS Implementation & Certification: Lead end-to-end ISO 27001 implementation
from gap analysis through to successful Stage 1 and Stage 2 certification audits;
manage external auditor relationships
● Risk Management: Develop and operationalize the information security risk
management framework; conduct risk assessments, treatment planning, and risk
acceptance processes.
● Policy & Governance : Author, approve, and maintain the Statement of Applicability
(SoA), information security policies, standards, and procedures aligned with ISO 27001
Annex A controls.
● Control Implementation: Translate ISO 27001 Annex A controls into operational
security measures; coordinate with IT, Accounts, HR, Backoffice, and business units to
implement and validate controls.
● Compliance Monitoring: Establish continuous monitoring, internal audit programs, and
KPIs/KRIs to measure ISMS effectiveness; manage non-conformities and corrective
actions.
● Third-Party Risk: Oversee vendor security assessments and ensure supply chain
security controls meet organizational and ISO 27001 standards.
● Stakeholder Management: Report ISMS performance, risks, and compliance status to
senior leadership and the board; act as primary liaison for external auditors and
regulators.
Required Qualifications
● 5+ years of experience in information security governance, risk, and compliance
● Proven track record of leading at least one full ISO 27001:2022 certification cycle (gap
analysis → certification)
● Deep expertise in ISO 27001:2022 standard, Annex A controls, and ISMS
documentation requirements
● Strong understanding of risk assessment methodologies (e.g., ISO 27005, NIST RMF,
OCTAVE, FAIR)
● Familiarity with internal audit practices and managing external certification bodies
● Excellent stakeholder management and ability to influence across technical and non-
technical teams
● Strong documentation and communication skills — able to translate complex standards
into actionable guidance
Preferred Qualifications
● Experience implementing ISMS in fintech, healthcare, or regulated industries
● Experience with SOC 2, GDPR, NIST CSF, PCI-DSS, or other compliance frameworks
● Background in cloud security (AWS, Azure, GCP) and DevSecOps environments
● Knowledge of automation for compliance evidence collection and control testing
● Certifications: CISM, CRISC, CISA, ISO 27001 Lead Auditor, or ISO 27001 Lead
Implementer
Why Join Us
● Opportunity to build the security governance function from the ground up
● High-visibility role with direct impact on customer trust and market differentiation
● Collaborative environment that values security as a business enabler, not a blocker
Company Profile:
We are a one-stop financial services shop, widely known for quality of its advice, personalized
service and cutting-edge technology. We started our journey in 2008. Currently we are serving
more than 50,000 investors with a team of 100 members. Our core product offering is mutual
fund, FD, Govt. Bonds, Debenture, etc.
Company Name: Money Honey Financial Services Pvt Ltd Company Profile: We are a one-stop financial services shop, widely known for quality of its advice, personalized service and cutting-edge technology. We started our journey in 2008. Currently we are serving more than 50,000 investors with a team of 100 members. Our core product offering is mutual fund, FD, Govt. Bonds, Debenture, etc. Role Description: This role directs the entire IT infrastructure, software engineering, and digital transformation strategy to support secure, scalable, and compliant technology and business operations.
Skills and Experience Required: 15+ years in IT delivery, application development, and enterprise architecture, with leadership tenure in regulated financial environments. Strong background in enterprise application architecture, cloud migrations (AWS/Azure/GCP), API integrations, and scalable database management using Microsoft and open source technology stack AI / ML Strategy: identifying and implementing high-impact use cases for Generative AI, Agentic AI, predictive analytics, and process automation Domain Expertise: Deep understanding of financial services (mutual fund, corporate fixed deposits, bonds etc.) and critical financial workflows
Responsibilities:
Strategic Technology Leadership: Define and execute the long-term technology vision, digital transformation roadmaps, and engineering strategies aligned with business growth.
Application Development & Delivery: Oversee IT development functions, software product engineering, and core transaction platforms ensuring high availability and minimal downtime
Infrastructure & Operations Management: Manage robust cloud and on premise infrastructure, network architecture, and 24/7 production support systems
Governance, Risk & Compliance (GRC):Ensure adherence to ISO standards, regulatory frameworks, data privacy laws, and stringent cybersecurity standards Location: Goregaon (W), Ram Mandir road, Mumbai Work Model:
Work from office (all working days)
We are hiring a Senior Data Governance Manager with 5+ years of data-management experience to define and run enterprise data governance policy, quality, metadata, lineage, and cataloging so the business can trust and safely use its data.
Key Responsibilities
• Define and enforce data governance policies and standards
• Own data quality frameworks, monitoring, and remediation
• Manage metadata, data lineage, and cataloging
• Drive master data management (MDM) practices
• Ensure compliance with privacy/regulatory requirements
• Align business and technical stakeholders on standards
Mandatory Skills
• 5+ years in data management with governance ownership
• Data governance frameworks and policy
• Data quality and master data management
• Metadata management and data cataloging
• Strong SQL and data-platform understanding
• Stakeholder alignment and compliance
Nice to Have: Collibra/Informatica/Alation; cloud data platforms (Snowflake, Azure, GCP)

Client Reporting Specialist (Immediate Joiners Only) C2C Position
Business Intelligence & Client Reporting
.Hands-on experience in Request Intake, Triage & Prioritization, and SLA-driven delivery management.
• Experience in a Business Intelligence, data analytics, or enterprise/client reporting
environment.
• Familiarity with Agile/Scrum delivery and daily standup routines.
• Exposure to data visualization or reporting tools (e.g., Qlik, Power BI, Tableau, Looker).
• Prior experience in a contract or staff-augmentation capacity supporting an established
internal team.
Mandatory skills and experience:
- Hands-on experience working in an ITIL-aligned application support or service management environment.
- Strong experience in:
- Request intake and management
- Ticket triage and prioritization
- SLA monitoring and tracking
- Escalation management
- Stakeholder communication and coordination
- Ability to work closely with business users, support teams, and reporting stakeholders to ensure timely resolution of issues and requests.
- ITIL Foundation certification is preferred.






