Cyber GRC Lead (Kerala)

Cyber GRC Lead (Kerala)

17 Sep
|
Cyber Forte
|
Kerala

17 Sep

Cyber Forte

Kerala

Remote: Hybrid

About Cyber ForteCyber Forte is an Australian cybersecurity and compliance consultancy helping organisations improve their security posture, achieve and maintain compliance, and prepare for independent certification and assurance.We work with organisations across a range of industries on frameworks and standards including ISO/IEC 27001, SOC 2, Essential Eight, ISM, PCI DSS and broader cybersecurity governance and risk requirements.We are looking for an experienced GRC Lead to join our growing delivery team and take responsibility for delivering high-quality governance, risk and compliance engagements for our clients.About the RoleAs a GRC Lead, you will work directly with clients to assess their current security and compliance maturity, identify gaps, develop practical remediation plans and support them through implementation and certification/assessment activities.You will be involved across the full engagement lifecycle — from initial discovery and gap assessments through to policy and control development, evidence collection, remediation tracking, internal audits and certification readiness.This is a client-facing, hands-on consulting role. We are looking for someone who can work independently, communicate confidently with stakeholders and translate compliance requirements into practical security outcomes.Key ResponsibilitiesGovernance, Risk & ComplianceConduct security and compliance gap assessments against ISO 27001, SOC 2 and other relevant frameworks.Develop and maintain Statements of Applicability, control mappings, risk treatment plans and compliance roadmaps.Review client policies, procedures, standards and supporting documentation.Identify control gaps and provide practical, risk-based recommendations.Support clients with remediation planning and tracking.Perform information security risk assessments and support clients in developing and maintaining risk registers.Assist clients in preparing evidence and maintaining audit readiness.Conduct internal audits and control effectiveness assessments.Support clients through certification and external audit activities.Monitor changes to applicable standards, regulations and security requirements.ISO 27001Conduct ISO/IEC 27001:2022 gap assessments.Assist with ISMS implementation and ongoing improvement.Develop and review ISO 27001 policies,



procedures and supporting documentation.Support risk assessment and risk treatment activities.Develop and maintain Statements of Applicability.Support internal audit and management review activities.Prepare clients for Stage 1 and Stage 2 certification audits.Support surveillance and recertification activities.Essential EightConduct Essential Eight maturity assessments.Assess client environments against ML1, ML2 and ML3 requirements.Identify technical and governance gaps.Develop remediation roadmaps.Work with technical teams to validate evidence and control implementation.Support clients preparing for Essential Eight assessments and related security requirements.Client & Project ManagementLead client workshops and stakeholder meetings.Gather and analyse technical and business information.Translate technical security issues into clear business and risk language.Maintain project actions, risks, issues and deliverables.Manage multiple client engagements concurrently.Prepare high-quality assessment reports, remediation plans and executive summaries.Work closely with Cyber Forte's senior consultants and leadership team.Ensure engagements are delivered on time, within scope and to a consistently high standard.What We're Looking ForWe are looking for someone who combines strong GRC knowledge with practical consulting experience.Essential3+ years' experience in cybersecurity, GRC, information security or compliance consulting.Solid working knowledge of ISO/IEC 27001:2022 and cloud security controls. Experience conducting ISO 27001 gap assessments, risk assessments and/or internal audits.Experience developing information security policies,



procedures and control frameworks.Strong understanding of information security risk management.Experience working directly with clients and senior stakeholders.Excellent written and verbal communication skills.Strong report writing and documentation skills.Ability to manage multiple projects and deadlines.Ability to work independently and take ownership of client deliverables.Strong attention to detail.Early start at 6 AM IST to meet Australia time zone DesirableExperience with one or more of:ISO 27001 Essential Eight / Essential Eight Maturity ModelSOC 2PCI DSSNIST Cybersecurity FrameworkCIS ControlsSecurity governance and assuranceCybersecurity maturity assessmentsCertificationsOne or more of the following would be highly regarded:ISO 27001 Lead AuditorISO 27001 Lead ImplementerCISACISMCISSPCRISCIRAP-related experience or qualificationsEssential Eight assessment experienceRelevant practical experience will be considered alongside formal certifications.Technical UnderstandingYou do not need to be a hands-on engineer, but you should be comfortable understanding and discussing common security technologies and environments, including:Microsoft 365Entra ID / AzureIntuneEndpoint security / EDRIdentity and access managementMFA and privileged accessNetwork security and firewallsVulnerability managementLogging and SIEMBackup and disaster recoveryCloud environments including Azure, AWS and GCPSecurity awarenessAsset and configuration managementYou should be able to understand technical evidence and determine whether it adequately supports the relevant security control or requirement.What Success Looks LikeYou will be expected to:Independently manage assigned GRC engagements.Conduct client gap assessments with limited supervision.Produce high-quality assessment reports and remediation roadmaps.Confidently facilitate client workshops.Maintain strong client relationships.Deliver projects within agreed timelines and scope.Contribute to improving Cyber Forte's GRC methodologies, templates and delivery processes.Support the broader Cyber Forte team across multiple compliance frameworks.Why Join Cyber Forte?Work directly with a growing Australian cybersecurity consultancy.Exposure to a broad range of industries and security frameworks.Work closely with senior cybersecurity professionals and leadership.Opportunity to develop expertise across ISO 27001, Essential Eight, SOC 2, ISM, PCI DSS and other frameworks.Client-facing role with genuine ownership and responsibility.Remote/hybrid working environment.Opportunity to grow with the business and take on increasing responsibility.

📌 Cyber GRC Lead (Kerala)
🏢 Cyber Forte
📍 Kerala

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: cyber grc lead (kerala) / kerala

Subscribe to this job alert:

Get the latest job offers by email for: cyber grc lead (kerala) / kerala