02 Aug
|
Bct Consulting
|
Mumbai
02 Aug
Bct Consulting
Mumbai
Role & responsibilities
Key Responsibilities
Governance & Policy Management
- Develop, review, and maintain information security, IT governance, and compliance policies, standards, procedures, and control frameworks.
- Ensure governance structures align with organizational objectives, regulatory requirements, and customer contractual obligations.
- Support definition and enforcement of roles, responsibilities, and accountability models (RACI) for security and compliance controls.
- Drive policy awareness, exception handling, and periodic policy attestation exercises.
Risk Management
- Identify, assess, and document IT, cyber, cloud, operational, and thirdparty risks using approved risk assessment methodologies.
- Maintain enterprise risk registers, including risk ratings, treatment plans, owners, and remediation timelines.
- Facilitate risk treatment decisions including mitigation, acceptance, transfer, or avoidance.
- Track risk remediation activities and provide periodic risk posture updates to leadership and stakeholders.
- Support Segregation of Duties (SoD) and accessrelated risk assessments in coordination with IAM / PAM teams.
Compliance & Regulatory Management
- Ensure compliance with applicable frameworks and regulations such as ISO 27001, ISO 22301, PCI DSS, DPDP Act, SOC 1/2, RBI, and customerspecific security requirements.
- Map regulatory and contractual requirements to internal controls and operational processes.
- Monitor compliance status and address gaps through corrective and preventive action plans.
- Support compliance attestations, certifications, and regulatory reporting obligations.
Audit Management (Internal & External)
- Act as a primary point of contact for internal audits, external audits, and customer audits.
- Coordinate audit planning, evidence collection, walkthroughs, and closure activities.
- Ensure timely remediation and closure of audit observations, nonconformities, and management action plans.
- Maintain audit trails, evidence repositories, and compliance documentation.
Control Design & Effectiveness Monitoring
- Design, review, and validate security and compliance controls across IT infrastructure, cloud platforms, applications, and security tools.
- Perform periodic control testing, effectiveness assessments, and gap analysis.
- Support continuous control monitoring using GRC tools and dashboards where applicable.
- Drive improvements in control automation and standardization.
ThirdParty & Vendor Risk Management
- Conduct risk assessments for thirdparty vendors, service providers, and partners.
- Review vendor security posture, compliance certifications, and contractual risk clauses.
- Track remediation actions for identified thirdparty risks.
- Support onboarding and periodic reassessment of critical vendors.
Incident, Issue & Exception Management
- Support security incident postincident reviews from a governance and compliance perspective.
- Ensure incidents, risks, and control failures are properly documented and tracked.
- Manage policy exceptions, risk acceptances, and deviation approvals with appropriate governance.
- Support root cause analysis (RCA)
and corrective action tracking.
Reporting & Stakeholder Communication
- Prepare governance, risk, and compliance dashboards and executivelevel reports.
- Provide regular updates on risk posture, compliance status, audit findings, and remediation progress.
- Support leadership, legal, and customer teams with compliancerelated inputs for proposals, SOWs, and renewals.
Tools & Platforms (Typical Exposure)
- GRC platforms (e.g., ServiceNow GRC, SAP GRC, OpenPages or equivalent)
- Risk registers, audit management systems, and compliance tracking tools
- IAM / PAM, CSPM, SIEM, and security tooling for control validation
- Document management and evidence repositories
Required Skills & Experience Technical & Functional Skills
- Solid understanding of GRC frameworks, risk assessment methodologies, and compliance management
- Handson experience with ISO, PCI, SOC, DPDP, and regulatory compliance
- Knowledge of cloud security, IAM, PAM, CSPM, and security operations concepts
- Ability to interpret regulatory requirements and translate them into actionable controls
- Experience supporting audits and customer security assessments
Behavioral & Professional Skills
- Strong stakeholder management and communication skills
- High attention to detail and documentation rigor
- Ability to work across multiple teams and manage competing priorities
- Analytical mindset with riskbased decisionmaking approach
Preferred Qualifications
- Certifications such as CISA, CRISC, CISSP, ISO 27001 LA/LI, PCI QSA (or equivalent exposure)
- Experience in regulated enterprise, or managed services environments
- Exposure to multicloud or hybrid IT environments
Preferred candidate profile
📌 GRC (Mumbai)
🏢 Bct Consulting
📍 Mumbai