06 Aug
|
3i Infotech
|
Noida
Cybersecurity Governance, Risk, and Compliance Offshore Consultant
The Cybersecurity Governance, Risk, and Compliance Offshore Consultant will support Teachers Cyber GRC program across IT risk management, third-party risk reviews, audit readiness, business continuity and disaster recovery governance, access review support, and cybersecurity maturity initiatives. This role requires strong GRC experience, disciplined follow-through, clear communication, and the ability to coordinate effectively with stakeholders, technology teams, vendors, and enterprise risk partners.
Key Responsibilities
- Maintain the IT risk register, including risk identification, documentation, ownership, treatment plans, acceptance decisions, and status reporting.
- Work with risk owners to drive mitigation, closure, or formal acceptance of identified risks within agreed timelines.
- Support cybersecurity risk assessments including artificial intelligence, cloud services, and other emerging technology areas.
- Prepare recurring cybersecurity risk metrics, dashboards, and leadership updates.
- Perform vendor security reviews, including assessment of SOC reports, security questionnaires, control gaps, and remediation plans.
- Support business continuity and disaster recovery governance by tracking DR test completeness, runbook validation, readiness metrics, and open gaps.
- Manage Cyber GRC operational requests and ServiceNow tickets in alignment with response, escalation, documentation, and closure expectations.
- Support user access review expansion by assisting with application onboarding, entitlement data collection, access model preparation, stakeholder coordination, and modification tracking.
- Support audit readiness by coordinating evidence collection, analyzing prior audit requests, tracking deliverables, and preparing audit evidence packages.
- Contribute to cybersecurity maturity improvement initiatives aligned to NIST-based benchmark and roadmap activities,
including MFA, account lifecycle, segregation of duties, file integrity monitoring, disaster recovery, encryption, patch governance, CMDB maturity, and standards updates.
Expected Deliverables and Success Measures
- Maintain accurate and current risk records, including ownership, treatment approach, due dates, supporting documentation, and status.
- Drive timely closure or formal acceptance of high-moderate and moderate risks, including justification for overdue items.
- Complete assigned major risk assessments within agreed timeframes
- Respond to new vendor security review requests within five business days after receipt of required evidence.
- Complete recurring Tier 1 and Tier 2 vendor reviews, with an expected average of five reviews per month, subject to review complexity and annual schedules.
- Submit weekly GRC status reports covering action items, blockers, key risk updates, vendor review progress, BC/DR metrics, audit readiness, and access review activity.
- Support onboarding of two to five additional applications per month into the user access review process, where dependencies and readiness allow.
- Contribute to cybersecurity maturity uplift activities by providing clear status, dependencies, risks, and completion evidence.
Required Qualifications
- Three or more years of experience in cybersecurity governance, risk management, compliance, IT audit, third-party risk management, or a related information security role.
- Working knowledge of cybersecurity risk management, control assessment, risk treatment, issue tracking,
and metrics reporting practices.
- Experience reviewing vendor security documentation, including SOC reports, security questionnaires, control narratives, and remediation plans.
- Familiarity with cybersecurity frameworks and regulatory expectations such as NIST Cybersecurity Framework, NIST 800-53, ISO 27001, PCI DSS, GLBA, ITGC, SOC reporting, and privacy or financial services compliance requirements.
- Experience supporting audits, evidence collection, control validation, and audit readiness activities.
- Solid documentation, analytical, follow-up, stakeholder coordination, and professional communication skills.
- Ability to work independently in an offshore delivery model while maintaining timely escalation and accurate reporting.
- Proficiency with Microsoft Office and collaboration tools for tracking, reporting, presentations, and stakeholder communication.
Preferred Qualifications
- Experience with GRC, workflow, or identity governance platforms such as Quantivate, ServiceNow, Saviynt, or equivalent tools.
- Experience supporting business continuity, disaster recovery, vulnerability management, patch governance, CMDB improvement, or cybersecurity maturity programs.
- Relevant certifications such as CISA, CRISC, CISSP, CISM, Security+, ISO 27001 Lead Implementer, or similar credentials.
- Prior experience supporting financial services, credit union, banking, or other regulated environments.
Engagement Expectations
- Operate as part of an offshore Cyber GRC support model with regular coordination across U.S.-based stakeholders and internal technology teams.
- Provide timely updates and escalate risks, blockers, dependencies, and overdue items.
- Handle sensitive security, vendor, audit, risk, and access review information with appropriate confidentiality.
- Demonstrate ownership of assigned deliverables from intake through closure.
📌 Cybersecurity Governance, Risk, and Compliance (Noida)
🏢 3i Infotech
📍 Noida