28 Sep
|
NuSummit
|
Mumbai
Job Role: Senior Manager - GRC (Cybersecurity)
- Lead and maintain ISO 27001, ISO 14001 and support SOC 2 and other compliance frameworks.
- Drive information security risk assessments, risk treatment, control effectiveness, and compliance monitoring.
- Lead internal, external, surveillance, customer, and third-party security audits and ensure timely closure of findings.
- Manage customer security assessments, due diligence questionnaires, and contractual security requirements.
- Govern Third-Party Risk Management (TPRM), including vendor security assessments, contractual controls, and remediation.
- Provide governance oversight for SOC, SIEM, EDR, DLP, Vulnerability management and security monitoring.
- Drive data protection and DLP governance, including information classification and prevention of data leakage.
- Oversee asset inventory and security monitoring coverage for critical IT and cloud assets.
- Govern VAPT, vulnerability remediation, access reviews, privileged access, and security control assessments.
- Support cloud security and emerging technology/AI governance, including security and data protection risks.
- Develop and maintain security policies, procedures, standards, controls, and management reporting.
- Lead cybersecurity awareness and training programs across employees and stakeholders.
- Support incident management, business continuity, disaster recovery, and security improvement initiatives.
- Partner with IT, SOC, HR, Legal, Procurement, Business teams, customers, vendors, and auditors to strengthen the organization's overall security posture.
📌 Senior Manager Information Security (Mumbai)
🏢 NuSummit
📍 Mumbai