TymblHub

© 2026 TymblHub

AVP - Technology Governance, Risk, and Compliance

Oaktree Capital Management
Posted on
Oaktree Capital Management logo

Experience
10 - 15 yrs
Job Location
Hyderabad, India
Vacancy
1
Designation
Assistant Vice President Risk Management
Job Type
ONSITE

Job Description

Role Summary

Oaktree is seeking a motivated and detail-oriented candidate for the role of AVP, Governance, Risk Compliance within our cybersecurity program. This individual will report to the Vice President of Governance, Risk Compliance and play an integral role in supporting the firms security posture, regulatory obligations, and risk management activities across all business lines. The ideal candidate brings a foundational understanding of GRC principles, experience developing and tracking metrics, and a keen interest in applying risk-based thinking within a financial services environment.

Responsibilities

Governance

  • Support the maintenance and continuous improvement of cybersecurity governance frameworks aligned with industry standards such as NIST CSF and ISO 27001.
  • Assist in the drafting, updating, and organization of IT security policies, standards, and procedures to ensure alignment with regulatory and business requirements.
  • Maintain and organize governance documentation within the firms centralized platform to support audits, exams, and internal reviews.
  • Coordinate control ownership tracking across business units to support visibility, accountability, and reporting consistency.
  • Prepare materials for senior management, Legal, Compliance, and Audit stakeholders as needed.

Risk Management

  • Support enterprise-wide cyber risk assessments, including data gathering, inherent and residual risk scoring, and documentation of control gaps and remediation activities.
  • Maintain the IT Risk Register, ensuring it accurately reflects current threats, regulatory changes, and business priorities.
  • Contribute to the third-party technology risk management program by assisting with vendor due diligence questionnaires, risk scoring, and ongoing monitoring activities.
  • Develop, maintain, and enhance Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) to track control effectiveness, program health, and trend reporting for leadership.
  • Produce regular metrics reports and dashboards that communicate risk posture in a clear and actionable format.

Compliance

  • Support the firms compliance activities across relevant regulatory frameworks, including MAS, CSCRF, IFSCA, GDPR, DORA, and CCPA.
  • Assist in the preparation and response for internal and external audits, regulatory exams, and client due diligence requests.
  • Contribute to SOC 1/2 audit readiness by supporting control validation, evidence collection, and documentation efforts.
  • Assist in coordinating responses to external auditor requests, walkthroughs, and follow-up items.
  • Support the control testing and self-assessment process to validate control effectiveness and maintain audit readiness.
  • Track and process policy exception requests, ensuring compensating controls are properly documented and monitored.
  • Monitor audit findings, track remediation progress, and assist in driving open items to closure.

Qualifications

  • 10-15 years of experience in a GRC, risk, audit, or compliance-related role, preferably within financial services or a regulated industry.
  • Demonstrated experience developing and maintaining risk or compliance metrics, KRIs, KPIs, or dashboards.
  • Familiarity with common frameworks such as NIST CSF, NIST RMF, NIST 800 series, ISO 27001, or CIS Controls.
  • Understanding of regulatory requirements applicable to financial services (e.g., GLBA, SEBI CSCRF, IFSCA, MAS).
  • Strong problem-solving and organizational skills with a high attention to detail.
  • Ability to analyze complex regulatory guidance and correlate it to operational controls and processes
  • Effective written and verbal communication skills, with the ability to present findings clearly to both technical and non-technical audiences.
  • Proficiency in Microsoft Office (Excel, PowerPoint, Word); experience with GRC platforms (e.g., AuditBoard, ServiceNow GRC) or data visualization tools is a plus.
  • Bachelors degree in Information Security, Business, Finance, or a related field preferred.
  • Relevant certifications (e.g., CompTIA Security+, CISA, CRISC, or equivalent) are a plus but not required.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.