17 Sep
|
Cybervahak Consultants
|
Mumbai
17 Sep
Cybervahak Consultants
Mumbai
ASSISTANT MANAGER - IT RISK AND CYBERSECURITY
Level: Assistant Manager
Location: Mumbai
Employment: Full-time
Experience: 2 to 4 years in IT risk, information security audit, or cybersecurity governance and compliance THE ROLE
We are looking for an Assistant Manager who can lead client engagements in IT risk and cybersecurity from scoping to sign-off. You will plan the work, run fieldwork with the client, review the evidence and the findings, write the report, and present it to the client's management. You will guide associates and interns on your engagements, own the quality of what they produce, and act as the client's day-to-day point of contact.
You will own a portfolio of clients and contribute to proposals and practice development.
WHAT YOU WILL DO
ENGAGEMENT LEADERSHIP
- Lead IT risk assessments, cybersecurity audits, ITGC reviews and regulatory compliance assessments end to end: scoping, planning, fieldwork, reporting and closure.
- Design the test approach for each control, judge design and operating effectiveness, set the evidence standard and sampling, and sign off on the working papers.
- Review controls across access management, change management, backup and recovery, incident management, asset and configuration management, patching, vulnerability management, logging and monitoring, and third-party risk.
- Write findings that hold up: clear root cause, business impact, risk rating and a practical recommendation, and track corrective actions with the client until closure.
- Present results to CISOs, CIOs, audit committees and senior management, and defend the findings.
REGULATORY AND FRAMEWORK WORK
- Run gap assessments and readiness reviews against RBI, SEBI, IRDAI and CERT-In requirements, ISO/IEC 27001, NIST CSF, CIS Controls and PCI DSS, and prepare clients for regulator inspections and certification audits.
- Advise on the Digital Personal Data Protection Act: data inventories, privacy impact assessments, consent and retention practices, and breach notification readiness.
- Build and maintain information security policies, standards, procedures and SOPs that fit the client's operating model rather than a template.
- Support business continuity and disaster recovery reviews, including recovery objective validation and DR test observation.
- Design and facilitate cyber crisis tabletop exercises and leadership awareness sessions with the senior team.
AI GOVERNANCE AND TECHNOLOGY-ENABLED ASSURANCE
- Lead AI risk and governance reviews against ISO/IEC 42001 and the NIST AI RMF: model inventories, use-case risk classification, privacy, security, bias, accuracy,
transparency and human oversight.
- Use approved AI and analytics tools to accelerate evidence review, log and configuration analysis, risk analysis and report drafting, and set the standard for their responsible use on engagements.
- Build reusable checklists, risk registers, dashboards and trackers that make the practice faster and more consistent.
PEOPLE AND PRACTICE
- Guide and review the work of associates and interns, give timely feedback, and develop them into independent auditors.
- Manage engagement timelines, client coordination and deliverable quality, and escalate risks to senior management early.
- Contribute to proposals, scoping calls and practice methodology, and keep current on threats, regulatory developments and security technologies.
WHAT YOU NEED TO KNOW
IT RISK AND AUDIT
- IT general controls in depth: access, change, operations, backup and recovery, and application controls including segregation of duties, across on-premise, cloud and outsourced environments.
- Risk assessment method: asset and process scoping, threat and vulnerability identification, likelihood and impact rating, risk registers, risk appetite and key risk indicators.
- Audit practice: planning, walkthroughs, test of design and operating effectiveness, sampling, evidence standards, working papers, reporting and follow-up, aligned to ISACA and IIA standards.
- Third-party and outsourcing risk: due diligence, contractual controls, SOC 1 and SOC 2 report review, and ongoing monitoring.
REGULATIONS AND FRAMEWORKS
- RBI Cyber Security Framework for banks, RBI Master Directions on IT Governance and outsourcing, guidelines for payment system operators and NBFCs.
- SEBI Cybersecurity and Cyber Resilience Framework for regulated entities, and SEBI system audit requirements.
- CERT-In directions on incident reporting and log retention, and the Digital Personal Data Protection Act and its rules.
- ISO/IEC 27001 and 27002, ISO/IEC 27701, ISO 22301, NIST CSF, CIS Controls, PCI DSS, and the shared responsibility model and CSA Cloud Controls Matrix for cloud.
- ISO/IEC 42001 and the NIST AI Risk Management Framework for AI governance.
TECHNICAL UNDERSTANDING
- Enough depth in networks, operating systems, identity and access, cloud platforms, encryption and security architecture to test controls credibly and to challenge a technical answer.
- Vulnerability and incident management: reading VAPT reports, judging remediation, and assessing detection, response and reporting readiness.
- Data analytics for audit: working with Excel at an advanced level, and with Python, Power BI or similar tools for evidence analysis and dashboards.
- AI concepts sufficient to assess an AI system: machine learning basics, large language models, prompt engineering, model risk, and responsible AI principles.
EXPERIENCE AND QUALIFICATIONS
- 2 to 4 years in IT audit, IT risk, information security governance or cybersecurity compliance, at a consulting firm, an internal audit function or a regulated entity.
- A track record of delivering engagements independently and of presenting findings to senior management.
- A degree in Engineering, Information Technology, Computer Science, Cybersecurity or a related discipline.
- At least one of CISA, CRISC, CISM, ISO/IEC 27001 Lead Auditor or Lead Implementer, or an equivalent certification, or the commitment to obtain one within the first year.
- Excellent written English: reports, policies and findings that are accurate and readable.
WHAT WE LOOK FOR IN YOU Cybervahak is a young and growing company. The person in this role will shape how the advisory practice works, so we care as much about how you work as what you know.
- Ownership of outcomes: you treat an engagement as yours to deliver, and you do not hand a client a report you would not sign.
- Judgement: you can tell a real risk from a paperwork gap, and you rate and write it accordingly.
- Independence with integrity: you hold a finding under pressure and you handle confidential information with care.
- Client presence: you build trust with security and business leaders and you are comfortable in front of senior management.
- A developer of people: you make the associates around you better through review and feedback.
- Curiosity: you keep up with threats, regulation and AI, and you bring what you learn back to the team.
WHAT WE OFFER
- Engagement leadership from the first month, with direct exposure to senior management at regulated clients.
- Breadth across audit, regulatory compliance, crisis simulation, AI governance and security engineering.
- Competitive compensation aligned to experience, with performance-linked increments and support for professional certifications.
📌 Assistant Manager (Mumbai)
🏢 Cybervahak Consultants
📍 Mumbai