- Bachelors degree in information technology or related field
- 8+ years information security experience with 3+ years of experience in technology risk management
- Excellent verbal and written communication
- Understanding and knowledge of industry standards and industry frameworks (e.g., COBIT, COSO, ISO 27001, PCI, NIST)
- Experience of implementing and operationalizing technology risk management programs.
- Understanding of security requirements, contributions to security design and hands-on implementation of multiple security technologies and capabilities
- Hands on experience working with stakeholders in identifying, prioritizing and developing plans and roadmaps for cyber security programs
- Broad domain knowledge and robust understanding of three or more cyber security domains including (but not limited to):
- Cyber risk strategy
- Cyber risk program management and delivery
- Cyber security operations
- Security architecture
- Data protection
- Application security/SDLC
- Third party risk management
- Cloud security
- Cyber Threat Intelligence
- Security Operations Center
- Incident Response
- Cyber Resilience
Preferred:
- B.E. / B.Tech + MBA (Preferred)
- CISSP / CRISC (or equivalent)