26 Aug
|
Good Co India
|
India
26 Aug
Good Co India
India
Role & responsibilities
- Lead information security consulting and advisory engagements for enterprise clients across governance, risk, compliance, architecture, and security transformation.
- Assess clients' security posture, identify control gaps, and develop risk-based recommendations and remediation roadmaps.
- Conduct security assessments against frameworks and standards such as ISO 27001, NIST, SOC 2, PCI DSS, and applicable regulatory requirements.
- Develop and review security policies, standards, procedures, control frameworks, and governance models.
- Perform cybersecurity risk assessments, control assessments, third-party/vendor risk assessments, and compliance reviews.
- Advise clients on security architecture, cloud security, IAM, data security, application security, and network security.
- Support security transformation programs, including security operating models, target-state architecture, control implementation, and maturity improvement.
- Identify, assess, and prioritize cybersecurity risks and translate technical findings into business-oriented recommendations.
- Lead client workshops, stakeholder interviews, security reviews, and executive presentations.
- Prepare high-quality assessment reports, risk registers, gap analyses, remediation plans, dashboards, and executive-level presentations.
- Manage project scope, timelines, deliverables, risks, and client expectations across multiple engagements.
- Mentor junior consultants and review their analysis, documentation, and client deliverables.
- Support business development, proposals, RFP responses, solution development, and client account growth.
- Track evolving cybersecurity threats, regulations, technologies, and industry practices to enhance consulting offerings.
Preferred candidate profile
- 5 to 10 years of experience in information security,
cybersecurity consulting, GRC, security architecture, risk advisory, or a related domain.
- Proven experience delivering client-facing information security assessments, advisory projects, and cybersecurity transformation initiatives.
- Robust understanding of ISO 27001, NIST CSF, SOC 2, PCI DSS, GDPR, and enterprise security governance.
- Hands-on experience with cybersecurity risk assessments, control testing, gap assessments, security audits, and remediation planning.
- Good understanding of cloud security, IAM, network security, application security, data protection, vulnerability management, and incident response.
- Ability to translate complex technical security issues into clear business risks and actionable recommendations for senior stakeholders.
- Strong analytical, problem-solving, report-writing, presentation, and communication skills.
- Proven ability to independently manage client engagements, workstreams, timelines, and deliverables.
- Strong stakeholder-management skills with experience interacting with CISOs, CIOs, IT leaders, risk teams, auditors, and business stakeholders.
- Experience with GRC platforms, SIEM solutions, cloud-security tools, vulnerability-management platforms, or security assessment tools is an advantage.
- Experience in third-party risk management, regulatory compliance, security maturity assessments, and security operating models is preferred.
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Security, Electronics, or a related discipline.
- Relevant certifications such as CISSP, CISM, CISA, CRISC, CCSP, ISO 27001 Lead Auditor/Implementer, or CEH are preferred.
- Strong consulting mindset with commercial awareness, client orientation, ownership, attention to detail, and the ability to work effectively in ambiguous and fast-paced environments.
📌 Information Security Consultant (India)
🏢 Good Co India
📍 India