Why MizuhoAt Mizuho, we provide the stability of an international industry leader with the career trajectory of a growing business. Our steady, strategic growth gives our people at all levels rewarding degrees of responsibility and richer work experience than a boutique firm or an established giant could offer alone.
It’s the local expertise of our employees that makes our global network so powerful. By collaborating with colleagues and clients who share the same ambition and drive, you can amplify your sphere of influence and base of knowledge as part of one of the largest banks in the world.
Summary:
The Cybersecurity Controls Testing Lead will be part of the CISO Security Risk & Assurance (SRA) organization and play a key role in establishing and maturing a centralized Cybersecurity Controls Testing function.
The role will lead independent control testing engagements across cybersecurity domains, assess control design and operating effectiveness, identify deficiencies, and provide objective assurance over cybersecurity control execution. The AVP will partner with cybersecurity leaders, challenge control effectiveness where appropriate, and help drive continuous improvement of the Controls Testing program.The role operates independently from control owners and provides assurance to Cybersecurity leadership regarding the effectiveness of key security controls.
Key Responsibilities:
Cybersecurity Control TestingLead testing engagements across Identity & Access Management, Cyber Defense, Vulnerability Management, Security Monitoring, Endpoint Security, Infrastructure Security, and related cybersecurity domains.Assess design effectiveness and operating effectiveness of cybersecurity controls.Develop testing approaches, sampling methodologies, and evidence requirements.Evaluate control documentation, process walkthroughs, system configurations, and supporting evidence.Identify control deficiencies, compliance gaps,
and control design weaknesses.Perform root-cause analysis and evaluate potential risk impacts.Present testing results and recommendations to management.Stakeholder Engagement & ChallengeServe as a primary point of contact for cybersecurity control testing engagements.Challenge evidence, control execution, and remediation plans where deficiencies are identified.Facilitate walkthroughs with cybersecurity and technology stakeholders.Maintain an independent and objective testing posture.Build strong relationships across Cybersecurity, Technology, Audit, Risk, and Compliance teams.Reporting, Remediation & AssurancePrepare high-quality testing workpapers, deficiency reports, management summaries, and assurance reporting.Review and validate remediation plans for identified issues.Perform follow-up testing and remediation validation activities.Track testing results, issue trends, and remediation status.Identify recurring themes and emerging risks requiring management attention.Program Development & Continuous ImprovementContribute to the design, maturity, and governance of the Cybersecurity Controls Testing program.Enhance testing standards, methodologies, evidence requirements, and documentation practices.Identify opportunities to automate testing activities and improve operational efficiency.Support annual testing planning, control scoping, and risk-based testing activities.Mentor junior analysts and review testing deliverables for quality and consistency.
Required Qualifications:
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, or related discipline.8+ years of experience in Cybersecurity Controls Testing, IT Audit, Technology Risk, Cybersecurity GRC, Internal Audit, or Information Security.Experience leading cybersecurity or technology control assessments.Strong understanding of control design, operating effectiveness testing, and evidence evaluation.Experience assessing cybersecurity controls across IAM,
Security Operations, Vulnerability Management, Endpoint Security, Infrastructure Security, or related domains.Excellent analytical, communication, stakeholder management, and reporting skills.Ability to challenge stakeholders and influence outcomes without direct authority.
Preferred Qualifications:
Experience building or operating cybersecurity controls testing, assurance, or technology risk programs.Experience with Archer, ServiceNow GRC, AuditBoard, MetricStream, or similar GRC platforms.Familiarity with security technologies such as Microsoft Defender, Sentinel, CrowdStrike, CyberArk, SailPoint, Tenable, Qualys, Wiz, or similar platforms.Strong understanding of NIST, ISO 27001, CIS Controls, COBIT, and related frameworks.Certifications such as CISA, CRISC, Security+, SSCP, CySA+, CISSP, or equivalent
Company Overview:
Mizuho Pune is an integral part of Mizuho Financial Group, one of the world’s leading financial institutions with a strong global presence across the Americas, EMEA, and Asia. Based in India, Mizuho Pune supports Mizuho’s international businesses by delivering high-quality, scalable, and resilient services across multiple functions.
Mizuho Pune plays a critical role in driving operational excellence, standardization, and innovation for Mizuho Americas. By combining deep domain expertise with solid process, technology, and analytical capabilities, it partners closely with regional and global teams to support corporate and investment banking, capital markets, and corporate services functions, while adhering to the highest standards of risk management, regulatory compliance, and control.
Mizuho Pune offers competitive compensation and benefits package aligned with industry standards and local market practices.
Mizuho Pune is an equal opportunity employer and is committed to fostering an inclusive and diverse workplace.
Employment is subject to applicable background verification checks in accordance with Indian laws and company policies.
https://www.mizuhogroup.com/asia-pacific/mizuho-global-services/careers
📌 Cybersecurity Controls Testing Lead (Mumbai)
🏢 Mizuho
📍 Mumbai