Cybersecurity Control Gap Validator Lead
Department: Information Security
Location: India (Multiple Locations)
Experience: 12+ Years
Job Summary
We are seeking an experienced Cybersecurity Control Gap Validator Lead to independently assess, validate, and challenge cybersecurity control remediation activities across the organization. The role will be responsible for evaluating control gaps, remediation plans, control effectiveness, risk treatment strategies, and residual risk to ensure alignment with internal security requirements and industry frameworks.
The ideal candidate will have a strong background in Information Security GRC, Technology Risk, IT Audit, Cybersecurity Control Assurance, and Risk Management, preferably within the Banking, Financial Services, Consulting, or Global Capability Center environment.
Key Responsibilities
- Lead independent validation of cybersecurity control gaps and remediation activities.
- Assess control design and operating effectiveness across security domains.
- Review remediation evidence and challenge control owners where required.
- Evaluate residual risks, compensating controls, and risk acceptance requests.
- Conduct control-assurance reviews and validate audit observations closure.
- Support regulatory, internal audit, and compliance initiatives.
- Perform risk-based assessments against security frameworks and standards.
- Drive governance and reporting of remediation programs and control improvements.
- Identify systemic control weaknesses and recommend sustainable remediation strategies.
- Collaborate with stakeholders across Information Security, Risk, Compliance, Audit, and Technology teams.
Required Skills & Experience
- 12+ years of experience in:
- Information Security
- Cybersecurity GRC
- Technology Risk
- IT Audit
- Cyber Risk Management
- Control Assurance
- Audit Remediation
- Robust experience in
- Control Gap Assessment
- Control Testing & Validation
- Risk Assessments
- Audit Issue Management
- Remediation Validation
- Security Governance
- Strong knowledge of
- ISO 27001
- NIST Cybersecurity Framework
- Risk Management Frameworks
- Operational Risk Management (ORM)
- RCSA
- Regulatory Compliance Requirements
Preferred Qualifications
- Bachelor's Degree in Computer Science, Information Technology, Information Security, or related field.
- Professional certifications preferred
- CISSP
- CISM
- CISA
- CRISC
- ISO 27001 Lead Implementer/Auditor
Desired Competencies
- Excellent stakeholder management and communication skills.
- Strong analytical and risk-based decision-making ability.
- Experience managing multiple priorities and cross-functional programs.
- Ability to challenge remediation plans and provide independent assurance.
- High level of integrity, professionalism, leadership, and attention to detail.
Apply here: https://lnkd.in/g4VMMSTr For more information, contact:
[email protected]
📌 Cybersecurity Control Gap Validator Lead (Bengaluru)
🏢 protiviti india
📍 Bengaluru