Technology Risk Hiring for Banking GCCs in India
If there is one function where every banking GCC in India is fishing in the same small pond, it is technology risk. Information security, IT general controls, technology audit, third-party risk, resilience. Demand has been compounding for years as regulators sharpened expectations and centres took on more of the second line, while the supply of people who genuinely understand both technology and risk has grown far more slowly. This guide is what we tell clients before opening a technology risk search.
Why the pond is small
The role sits at an awkward intersection. Strong engineers rarely choose control functions early in their careers, and career risk professionals often lack the technical depth to challenge an engineering organisation credibly. The people who combine both usually arrived by accident: an engineer pulled into an audit remediation who discovered they liked it, a security operations analyst who moved up into governance. There is no degree pipeline that produces them at volume, and every large centre in Bengaluru, Hyderabad, Pune and Chennai wants the same profiles at the same time.
The consequence shows up in our search data. Technology risk shortlists take longer to build than adjacent engineering shortlists, response rates to cold approaches are lower because these candidates are approached constantly, and counteroffer rates at resignation are among the highest of any function we work.
What candidates in this market actually weigh
Three factors decide most moves, and compensation is only the third. First, mandate scope: whether the India role owns judgement or executes checklists written elsewhere. Candidates ask this directly and can smell a hedged answer. Second, reporting line: a role reporting into a local head of technology risk with real standing reads very differently from one dotted-lined into a regional function four time zones away. Third, compensation, where the premium over equivalent engineering roles has narrowed but the expectation of a meaningful hike on movement has not.
What works in practice
A few patterns from mandates that closed well. Write the specification around the mandate, not the framework list; naming every standard the team touches attracts checklist candidates and repels the ones you want. Involve the global function head early in the process for senior roles, because candidates discount promises the India interviewers cannot personally keep. Move fast between final interview and offer, since in this function a two-week approval cycle routinely costs the candidate. And design the offer for the 60-to-90-day notice period reality: engagement between offer and joining is not a courtesy, it is where searches are lost.
Retention, briefly
The same scarcity that makes hiring hard makes retention economics unusual. Replacing a strong technology risk manager typically costs more than the increment that would have kept them, before counting the six months of ramp. Centres that run honest annual calibration of these roles against the market, rather than waiting for resignation data, hire less often. We supply that calibration as part of our talent intelligence work when asked.
Where we fit
We run technology risk searches for banking GCCs continuously across Bengaluru, Hyderabad, Pune and Chennai, from manager through director level. Because we work only in financial services, our map of this candidate pool is current, not rebuilt per mandate. If you have a technology risk role open longer than sixty days, the problem is usually the role design or the process, not the market, and we can generally tell you which within a week.