Description:
We are seeking an experienced Senior Scrum Master with strong Governance, Risk, and Compliance expertise to drive agile delivery while ensuring robust governance, audit readiness, and risk remediation across programs. The role requires a unique blend of agile leadership, internal & external audit findings management, risk and vulnerability assessment, and executive-level reporting and documentation skills. The ideal candidate will act as a bridge between delivery teams, security, compliance, and senior leadership, ensuring regulatory adherence, risk mitigation, and continuous improvement.
Required Skills & Competencies
Core Skills
-
7–9 years of experience as a Scrum Master / Agile Lead with governance exposure.
-
Strong understanding of GRC frameworks, audit processes, and compliance controls.
-
Solid knowledge of risk management, vulnerability assessment, and remediation processes.
-
Excellent reporting, documentation, and writing skills.
-
Strong stakeholder management and communication skills.
-
Act as a single point of contact for auditors, ensuring timely responses and evidence submission.
-
Track audit findings, observations, and corrective action plans through closure.
-
Identify, assess, and track delivery, operational, and security risks.
-
Lead risk remediation plans, ensuring ownership, timelines, and closure.
-
Support vulnerability assessments (application, infrastructure, process-related).
-
Coordinate remediation activities with engineering, security, and infrastructure teams.
-
Prepare high-quality executive reports, dashboards, and presentations for leadership.
-
Develop clear and concise policies, procedures, SOPs, audit responses, and governance documents.
-
Provide regular status reporting on delivery health, risks, audits, and remediation activities.
-
Ensure accuracy, consistency, and professionalism in all written communication.
Technical & Process Knowledge
-
Agile frameworks: Scrum, Kanban
-
Cloud exposure (AWS)
-
Familiarity with security and risk concepts such as:
- Vulnerability management
-
Corrective and preventive actions
-
Experience with tools such as JIRA, Confluence, ServiceNow, or similar GRC tools.