15 Aug
|
We Search
|
Mumbai
Role Overview We are seeking a Cyber Strategy, Risk, Governance & Compliance professional with 3–4 years of experience in cybersecurity risk management, IT governance, controls assessment, compliance, and audit support. The candidate will work closely with business and technology stakeholders to assess cybersecurity risks, evaluate controls, support regulatory compliance initiatives, and strengthen governance frameworks across the organization. Key Responsibilities Cyber Risk & Controls Assessment Conduct cybersecurity, IT risk, and control assessments aligned with industry frameworks such as ISO 27001, NIST CSF, COBIT, CIS Controls, and regulatory requirements. Perform risk assessments to identify control gaps, security weaknesses, and compliance deficiencies across technology environments. Evaluate the design and operating effectiveness of security controls through Test of Design (ToD) and Test of Effectiveness (ToE) reviews. Facilitate control walkthroughs with process and control owners to understand control implementation and maturity. Governance, Risk & Compliance (GRC) Support the implementation and enhancement of Cybersecurity Governance, Risk, and Compliance (GRC) programs. Develop, review, and maintain information security policies, standards, procedures, guidelines, and governance documentation. Assist in establishing risk management processes, control frameworks, risk registers, and governance reporting mechanisms. Support compliance assessments against organizational policies, industry standards, and regulatory requirements. Audit & Compliance Support Support internal and external audits by coordinating evidence collection, control validation, and auditor interactions. Track audit observations, risk findings, and remediation plans to ensure timely closure. Conduct compliance reviews and control gap assessments, providing practical recommendations for risk mitigation and control improvement. Assist organizations in preparing for certification and regulatory compliance initiatives.
Risk Monitoring & Remediation Collaborate with business and technology teams to define corrective action plans for identified findings and risks. Monitor remediation progress, validate closure evidence, and report risk status to stakeholders. Support enterprise risk management activities through risk identification, assessment, reporting, and tracking. Program Governance & PMO Support Provide governance and PMO support for cybersecurity transformation and compliance programs. Maintain RAID logs (Risks, Assumptions, Issues, and Dependencies) and track project risks and actions. Prepare management reports, dashboards, status updates, and steering committee presentations. Coordinate stakeholder communications and governance meetings to ensure effective program delivery. Required Qualifications Bachelor's degree in Engineering, Computer Science, Information Technology, Cybersecurity, or related field. 3–4 years of experience in Cyber Risk, IT Risk Management, ITGC, Internal Audit, Cybersecurity Governance, or Compliance roles. Solid understanding of cybersecurity frameworks and standards such as ISO 27001, NIST CSF, COBIT, CIS Controls, SOC 2, and ITGC concepts. Experience performing control assessments, risk assessments, compliance reviews, and audit support activities. Knowledge of risk registers, issue management, remediation tracking, and governance reporting. Excellent stakeholder management, documentation, analytical, and communication skills. Preferred Certifications ISO 27001 Lead Implementer/Lead Auditor CISA CRISC CGEIT CISSP (preferred) Security+, CEH, or equivalent certifications Key Skills Cyber Risk Management IT Governance & Compliance Information Security Management Systems (ISMS) Regulatory & Compliance Assessments ITGC Reviews Control Testing (ToD/ToE) Risk Assessment & Gap Analysis Audit Management Policy & Standards Development PMO Governance & Reporting Stakeholder Management Project Coordination This role is ideal for professionals looking to build expertise across Cyber Strategy, Risk, Governance, Compliance, Audit, and Security Transformation initiatives. Location - Mumbai/Pune/Gurugram/Kolkata
📌 GRC Consultant (2152) (Mumbai)
🏢 We Search
📍 Mumbai