12 Sep
|
NCS Group
|
Pune
The Cyber GRC Analyst supports the organization s cybersecurity governance, risk, and compliance program. The analyst is responsible for managing third-party risk assessments, cybersecurity risk assessments, deviations, and GRC-related consultations and requests. The role strengthens cybersecurity governance through effective management of cybersecurity risks across the organization.
Conduct and manage third-party cybersecurity risk assessments to evaluate vendor security posture, track assessment progress, and coordinate follow-up with relevant stakeholders.
Conduct and manage cybersecurity deviation assessments, including risk assessment, tracking, approval coordination, and monitoring of expiry and renewal requirements.
Maintain accurate GRC records, documentation, and reporting to support cybersecurity governance and compliance activities.
Support the maintenance of the cybersecurity risk register, including tracking of identified risks and risk treatment plans.
Support the review and enhancement of third-party risk assessment and cybersecurity deviation management processes to align with evolving cybersecurity requirements and organizational needs.
Provide GRC-related consultation and support by managing cybersecurity queries, requests, and communications, and collaborating with business units to provide guidance on cybersecurity requirements and promote secure business practices.
Managing different LOBs stakeholders who often have different set of concerns
Embed the process of cyber risk assessment into LOBs.
Facing resistance to instil cybersecurity culture.
Education and Qualifications
1) Degree/Diploma or higher in Computer Science, Information Systems or equivalent
2) At least one security certification is preferred, such as Certified Information Security Management (CISM), Certified Risk Information Security Control (CRISC), Certified Information Systems Auditor (CISA) or Certified Information Systems Security Professional (CISSP)
Work Experience
At least 5 years of experience in IT Risk Management, Governance or Compliance.
Technical / Qualified Skills
1. Understanding of cybersecurity risk and control management concepts including risk assessments, risk treatment and third-party risk management.
2. Knowledge of risk management policies, methodologies, standards, processes, governance models, and quantitative and qualitative risk analysis approaches.
3. Knowledge of common information security management frameworks, such as ISO 27001-5, COBIT and NIST, including 800-53 and Cyber security Framework.
Non-Technical / Soft Skills
1. Customer-focused with good interpersonal skills
2. Team player and able to work independently
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Cyber Analyst (Pune)
🏢 NCS Group
📍 Pune