09 Aug
|
ACG World
|
Mumbai
Position Title : Manager, Risk Management, Cyber Security, ACG Group
Department: Corporate Information Technology
Location: Jogeshwari West, Mumbai
Reports to: Head, Cyber Security, ACG Group
1. Job Objective
- Strengthen enterprise cyber risk governance
- Drive proactive risk identification & mitigation
- Enhance risk monitoring & reporting
- Improve cyber resilience & compliance
- Strengthen third party / supply chain cyber risk management
- Improve cyber risk awareness
- Advance AI enabled cyber risk intelligence & analytics
1. Primary responsibilities
- Conduct enterprise-wide cyber risk assessments covering IT, cloud, OT, applications, and third-party environments to identify and evaluate security risks.
- Maintain and update the cyber risk register, ensuring risks are documented, prioritized, tracked, and periodically reviewed with relevant stakeholders.
- Monitor implementation of risk mitigation and remediation actions, and coordinate with technology and business teams to ensure timely closure of identified gaps.
- Develop and present cyber risk dashboards, KRIs, compliance reports, and management updates for leadership and governance forums.
- Review cybersecurity policies, standards, and control frameworks to ensure alignment with regulatory requirements, industry best practices, and organizational objectives.
- Support cyber incident response, business continuity, audit activities, and vendor risk assessments by providing risk analysis, impact evaluation, and recommendations for resilience improvement.
1. Key Result Areas
- Effectiveness of enterprise cyber risk identification, assessment, prioritization, and governance processes
- Timely closure of identified cyber risks, vulnerabilities, audit findings, and control gaps
- Accuracy, timeliness, and quality of cyber risk dashboards, KRIs, executive reports, and risk insights
- Adherence to cybersecurity policies, standards, and internal control frameworks, including audit readiness and compliance tracking.
- Assessment and ongoing monitoring of cybersecurity risks associated with vendors, service providers, and external partners.
- Contribution to incident response preparedness, business continuity planning, crisis coordination, and post-incident risk evaluation activities.
- Adoption of automation, threat intelligence, AI-enabled analysis, and process improvements to enhance cyber risk visibility and operational efficiency.
1. Key Interfaces
Internal Interfaces:
- ACG IT Team
- ACG Businesses
External Interfaces:
- Security Vendors
- Security Consultants
Key Competencies: Decision Making, Security frameworks, Problem Solving, Risk & Threat Management, Cross functional teamwork, Security tools & technologies, Communications, Compliance management, Deliver consistent results, Vendor Management
Educational and Experience Requirements
Minimum Requirement
- Bachelors + InfoSec certs such as ISO 27001 Lead Auditor or ISO 27001 Lead Implementer
- Or Masters + InfoSec certs such as CRISC, CISSP, CISA / CISM.
Experience
- Minimum prior 10-12 years of relevant experience in manufacturing industry.
📌 Manager, Risk Management, Cyber security, ACG Group (Mumbai)
🏢 ACG World
📍 Mumbai