GRC and PMO Compliance Officer
GRC and PMO Compliance Officer
Unlock your potential with Dassault Systèmes, a global leader in Scientific Software Engineering, as a GRC and PMO Compliance Officer in Bangalore, Karnataka!
Our compliance function is responsible for ensuring that the company meets its regulatory and market-driven compliance obligations efficiently, consistently, and at scale. Working under the direction of the Compliance Program Office, with key stakeholders from R&D, IT, Procurement, and Legal, this role is responsible defining and implementing a Third-Party Risk Management Program.
As the Third-Party Risk Program Manager, you will work collaboratively with R&D, IT, Procurement, Legal teams to assess current supplier risk practices and design and implement a common risk management framework that is integrated into our enterprise-wide Governance, Risk and Compliance program.
Role Description & Responsibilities:
• Define third-party risk management requirements based on applicable regulations, standards, and internal policies (e.g., ISO 9001, ISO 27x01, SOC 2, NIST, GDPR, NIS2, CRA, FedRAMP).
• Identify stakeholders and conduct a current-state assessment of existing third-party risk policies and practices
• Facilitate working groups to define a common risk management framework that is comprehensive without being overbearing driving consensus on policy, risk appetite, control ownership, and evidence collection
Program Management
• Build a program plan to manage objectives, scope, timeline, budget, workflow configuration, and integration with existing systems.
• Manage program status and progress and provide regular updates to key stakeholders and sponsors escalating issues and risks that threaten timeline, scope, or budget
• Identify and actively manage dependencies, risks, and conflicts across project workstreams and related projects
• Define and track program KPIs to measure status and progress and overall program value
• Serve as primary point of contact with workstream leaders, and other key stakeholders
• Manage the training and deployment TPRM program to operational teams
On-going program operations
• Monitor third-party risk metrics and report on program maturity, open findings, and remediation progress
• Track regulatory and industry changes and update the framework accordingly
• Support due diligence reviews, contract risk language, and escalations for high-risk vendors
• Provide training and guidance to stakeholders on third-party risk requirements and processes
• Serve as a point of contact for internal and external compliance audits
• Monitor and measure the value of the TPRM program and optimize it to achieve the greatest value
• Manage highly-matrixed program with senior-level stakeholders from across the globe
• Program deliverables and formal communication (kick-off, status, workshops) will be conducted in English
• Work as a quick problem-solver and critical thinker in a fast-paced environment.
• Work independently and within a global, collaborative team structure to solve complex problems.
• This position in on-site in our Paris HQ reporting into the Compliance Program Office
Qualifications:
• Bachelor's or Master's degree.
• 5+ years of relevant experience in compliance, risk management, or regulatory operations
• Experience working with a control framework tied to standards such as ISO 27001, SOC 2, ISO 42001
• Experience managing compliance requests or similar operational workflows end to end, including prioritization and cost-benefit analysis.
• Strong understanding of GRC frameworks and control models, and how new regulations map to existing controls.
• Process and operations management methodologies and best practices.
• Experience with: Process Management; Continuous Improvement / Process Improvement; Change Management; Stakeholder Management.
• Excellent English language communication skills, verbal and written.
• Proficient with Microsoft Office (PowerPoint, Word, Excel, Outlook, etc.).
• Familiarity with quality, security, privacy standards and their control requirements (e.g. ISO 9001, 27001, SOC 2, GDPR, FedRAMP, …)
• Relevant certifications (e.g. CRISC, CISA) — nice to have.
What is in it for you?
- Work for the one of the biggest software companies
- Work in a culture of collaboration and innovation
- Opportunities for personal development and career progression
- Chance to collaborate with various internal users of DASSAULT SYSTEMES and also stakeholders of various internal and partner projects
Inclusion statement
Dassault Systèmes è un catalizzatore del progresso umano. Forniamo alle aziende e alle persone ambienti collaborativi virtuali per immaginare innovazioni sostenibili. Creando gemelli virtuali del mondo reale con la nostra piattaforma e le nostre applicazioni 3DEXPERIENCE, creiamo esperienze e offriamo valore a più di 350.000 clienti di tutte le dimensioni, in tutti i settori, in oltre 150 paesi. Unisciti alla nostra comunità globale di oltre 23.800 persone appassionate!
Vuoi saperne di più?
Visita le altre sezioni del nostro sito per avere maggiori informazioni.
Studenti e laureati
Entra a far parte del futuro della nostra forza lavoro: scopri le nostre opportunità di stage e di lavoro.
Il tuo percorso di selezione
Scopri quale sarà il tuo percorso di selezione.
La nostra cultura e i nostri valori
Scopri la nostra cultura e i nostri valori.