
Cybersecurity Risk & Governance Expert
Hyderabad, India Permanent Posted on Mar. 06, 2025 Closing on Mar. 21, 2025Role : Cybersecurity risk & governance expert
Location : Hyderabad
Hiring manager : Naveen Agarwal
Our Team:
Our Governance, Risk & Compliance team, reporting directly to the CISO alongside the Security Architecture and Security Operations & SOC teams, plays a pivotal role in safeguarding the organization's assets and ensuring regulatory compliance. Under the leadership of the Governance, Risk & Compliance Lead, this team ensures our organization's technological infrastructure is secure, compliant, and resilient against evolving cyber threats.
Main responsibilities:
The Governance & Risk FTE, reporting to the GRC Lead, will play a pivotal role in ensuring robust risk management and governance within the Governance, Risk & Compliance team. This role focuses on orchestrating risk appetite decisions, conducting thorough risk assessments and penetration testing, managing third-party risks, supporting governance-driven activities, and overseeing data privacy initiatives. Key responsibilities include:
- Risk appetite & management
- Orchestrate decisions on cyber risk appetite for the organisation in collaboration with the broader business
- Define and deliver risk reporting plans and key indicators
- Assess risk and govern the process of updating risk appetite at least every 12 months in coordination with other teams
- Monitor compliance to cyber policies across the organisation (incl. policies & tech standards, DLP, IAM)
- Risk assessment & pen testing
- Conduct risk assessments at least every 6 months across all environments
- Conduct penetration testing at least every 3-6 months across most (>75%) on-premise and cloud environments
- Prepare vulnerability disclosure reports on outward facing systems (in the future)
- Third party management support
- Design, review and update supplier risk assessment frameworks (incl. criteria for tiering of vendors)
- Communicate cyber policies to strategic vendors, assess their cybersecurity risk and compliance at least every 12 months and based on need, and drive remediation/mitigation of risks
- Review the cybersecurity risk posed by the supply chain of all strategic vendors at least every 12 months
- Monitor deployed 3rd party HW/SW for vulnerabilities and ensure compliance
- Support GRC-driven activities
- Support the definition of cybersecurity-related enterprise standards, policies and controls
- Support audits covering risk-centric assessments (incl. follow up findings with corrective measures), provide inputs to regulatory and compliance teams on cybersecurity risk; support the deployment of corporate compliance programs
- Data privacy
- Define data privacy policies and standards and monitor compliance across the organisation from legal/regulatory perspective
- Support of Global Data Privacy program (e.g., managing requests across regions, mapping of data and specific regulations, coordination with Global GBS)
- Management of data process agreements (incl. review of contracts, annual assessment re-evaluation)
About you
- Experience:
- 5-10 years of professional experience (equivalent combination of experience and education accepted)
- Previous experience in implementing ISO27001 and NIS-2
- Previous work in an international environment.
- Demonstrated experience in working within cybersecurity teams, particularly in governance and risk.
- Proven track record of contributing to the design and implementation of governance and risk solutions aligned with organizational goals and regulatory requirements.
- Experience collaborating with Security Architect and Operations teams in a feedback loop.
- Ability to develop and communicate policies based on feedback from the Security Architect team.
- Soft skills:
- Broad experience in working in large digital teams, with an understanding of how digital and business processes are linked.
- Stakeholder management and communication skills, especially when interacting with senior leadership.
- Skilled problem solver and self-starter.
- A hands-on pragmatic attitude to driving change.
- Positive, "can-do" attitude.
- Technical skills:
- Experience with AGILE or similar project management frameworks.
- Working knowledge of common information security management frameworks (ISO/IEC 27001, ITIL, NIST, NISD, CISSP/CCSP, QxP, CIS20).
- Education:
- Bachelor’s and master’s degree (preferred) in any of the following fields of study: Information Technology, Computer Science, Cybersecurity or Information Security
- Languages:
- English
Pursue progress. Discover extraordinary.
Progress doesn’t happen without people – people from different backgrounds, in different locations, doing different roles, all united by one thing: a desire to make miracles happen. You can be one of those people. Chasing change, embracing new ideas and exploring all the opportunities we have to offer. Let’s pursue progress. And let’s discover extraordinary together.
At Sanofi, we provide equal opportunities to all regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, or gender identity.
Watch 'One day at Sanofi' and check out our Diversity Equity and Inclusion initiatives at sanofi.com
You have not viewed any jobs yet.
You have not saved any jobs yet.

Hubs
From Bogota to Budapest, Kuala Lumpur to Hyderabad – it’s your skills that help the Sanofi world go round. With a role in one of our Hubs, you’re right at the heart of our global transformation, as we fearlessly work together to cut the time it gets new treatments to patients. By making the most of your creativity and bringing your unique self you’re supportingyou’ll help others to perform at their best. Let’s make the discoveries that’ll change lives.
Find out more about this location
Experience possibility
-
-
Cambridge Crossing
We're bringing together 2,500 people from across our organization — R&D, Medical, Commercial and Global colleagues all working to realize the power of collaboration.
-
Innovation in Action
Our flexible lab of the future will transform how we conduct research, while our innovation center will be fully integrated with existing R&D locations.
-
Sustainable and Green
Our new facility was built to minimize the environmental impact — helping protect our planet and people. Using resources efficiently, we're providing greener, healthier workspaces.
-
Sanofi’s AI Centre of Excellence in Toronto
The Centre is focused on using leading technologies to develop world-class data and artificial intelligence (AI) products to create value for the health sector.
-
Ama
Ama puts her project management techniques and ServiceNow knowledge to use to help advance Sanofi’s Digital Data operating model. Learn how our team connects data and AI to do what’s never been done before.
-
Sanofi Canada's Philanthropic Efforts
By chasing the miracles of science to improve people’s lives, we surprise ourselves with what we can achieve. Our team is humbled by the impact our efforts make.
-
Emmanuel
Emmanuel, Head of the Sanofi Digital Accelerator, shares how his team builds digital solutions that enable patients to receive new treatments to help improve their lives.
-
Dimitrije
Dimitrije shares insights into the work carried out by the AI Centre of Excellence in Toronto.
-
Ziv
Read Ziv's first-hand account describing the reasons he chose to join Sanofi – and many of the reasons why he now chooses to stay.
-
When you grow, we all grow
We strive to support your whole self with thoughtfully crafted rewards that benefit you physically, financially, mentally and socially. Whatever your role, you'll thrive in our inclusive teams.
-
Build a career with purpose
Bring your passion to your role and impact millions of people around the world. You're in the driver's seat – just set your goals, and we'll provide the training and support that will get you there.
-
Bolder, better futures
Change your life. And the lives of millions around the globe. How? By starting a career where you're supported to grow, while having a tangible impact and learning from the best.
-
Our locations
We're in 60+ countries, all pulling together to define the future of healthcare. Wherever you work, you'll develop your career alongside experts, using technology to chase bigger breakthroughs.
-
Sanofi Stories
At Sanofi every voice matters. Get to know the talented Sanofians shaping our future and pushing us toward our ambitious goals.
-
Sanofi at Cambridge Crossing
Dubbed Sanofi at Cambridge Crossing, our new state-of-the-art facility will create an innovation hub promoting close collaboration and integration among business units. Join us and become part of a team dedicated to chasing the miracles of science that improve people’s lives.
-
Why Sanofi
Get access to the tools, training, and support to reach your goals. By fulfilling your potential, you’ll help us achieve our aim of halving the time from discovery to therapy.
-
Our people & culture
We're the first in Pharma to have a DE&I board. We also have Employee Resource Groups that create spaces for every Sanofian to be heard. Your voice matters – use it to shape our future.
-
Sanofi's Postdoctoral Program
Designed for high-caliber Ph.D. graduates, Sanofi's Postdoctoral Program helps you advance your scientific career in a state-of-the-art environment.
-
Physician Careers at Sanofi
At Sanofi, physicians like you have the opportunity to collaborate on new ideas and challenge established thinking. Learn about Physician careers here.
-
AI Centre of Excellence
The AI Centre of Excellence at Sanofi is a unique data-driven team based in Downtown Toronto. We pride ourselves on being data-obsessed and highly focused on using state-of-the-art technologies to drive global impact.
-

Join our
talent community
What could we achieve together? Every Sanofian works on projects that truly make a difference to people’s lives.
Sign up today and discover our latest opportunities as soon as they’re available.