02 Oct
|
RMV Workforce
|
Mumbai Suburban
02 Oct
RMV Workforce
Mumbai Suburban
Role – Cyber Security GRC Manager
Job Location: Navi Mumbai
Experience: 6-8 years in Cyber Security / Information Security / GRC / Cyber Risk
Department: Information Security / IT
Reporting To: Head – IT
Position Overview
We are looking for an experienced Cyber Security Manager to lead and manage the organization's cyber security, information security governance, risk and compliance framework. The role will have a robust focus on GRC, ISO 27001/NIST frameworks, security policies and documentation, along with oversight of incident response, security technologies, IAM/PAM, VAPT and OT security.
Key Responsibilities
1. Governance, Risk & Compliance
- Lead and manage the organization's Information Security Governance, Risk & Compliance (GRC) framework.
- Develop, implement and maintain security controls aligned with ISO 27001, NIST Cybersecurity Framework and other applicable standards.
- Drive information security risk assessments, control assessments and risk treatment plans.
- Manage internal and external ISO 27001 audits, compliance assessments and closure of audit observations.
- Identify cyber security gaps and recommend appropriate remediation plans.
- Maintain risk registers, compliance trackers, control matrices and security dashboards.
- Coordinate with business and IT teams to ensure compliance with defined security policies and controls.
- Monitor regulatory and industry requirements relevant to information and cyber security.
- Support management in preparing cyber security governance reports and risk updates.
2. Documentation
- Develop,
review and maintain Information Security Policies, Standards, SOPs, Guidelines and Procedures.
- Prepare security frameworks, process documents, control documents and implementation guidelines.
- Create management presentations, MIS reports, security dashboards and audit-related documentation.
- Ensure security documentation is current, accurate and aligned with organizational requirements.
- Maintain evidence and documentation required for audits and compliance assessments.
6. Communication & Stakeholder Management
- Act as a key point of contact for cyber security matters across IT and business functions.
- Communicate cyber security risks, incidents and compliance requirements effectively to senior management.
- Conduct security awareness sessions and communicate information security policies across the organization.
- Coordinate with internal stakeholders, auditors, consultants and external security vendors.
- Prepare and present security updates, risk reports and compliance status to management.
3. SOC/SIEM & Incident Response
- Oversee security monitoring and incident response,
- including SOC operations and continuous improvements.
4. IAM / PAM / VAPT & Security Technologies
- Provide governance and oversight for
- IAM, PAM, VAPT, SSE, DLP, Endpoint Security, Data Privacy and Data Security
- Evaluate and provide recommendations on relevant cyber security technologies and solutions.
5. OT Security
- Support the implementation of OT/ICS security controls and identify cybersecurity risks in operational technology environments.
- Coordinate with OT, Engineering, and IT teams to implement security assessments, access controls, monitoring, and risk mitigation measures.
Required Skills & Competencies
- Strong knowledge of GRC and security documentation.
- Good understanding of cybersecurity and information security principles.
- Hands-on experience implementing ISO/IEC 27001 and NIST frameworks.
- Experience in security risk assessments, compliance, and audit management.
- Expertise in developing Policies, SOPs, and Presentations.
- Understanding of SOC operations and incident response processes.
- Understanding of IAM, PAM, VAPT, SSE, DLP, Endpoint Security, Data Privacy and Data Security.
- Familiarity with OT/ICS security concepts is an added advantage.
- Strong analytical, problem-solving, and risk management skills.
- Excellent written and verbal communication skills.
- bility to work independently and manage multiple security initiatives simultaneously.
Preferred Certifications
One or more of the following certifications would be preferred:
- CISM
- ISO 27001 Lead Implementer / Lead Auditor
- CISA
- CEH / Security+ or other relevant cyber security certifications
📌 Cyber Security GRC Manager (Mumbai Suburban)
🏢 RMV Workforce
📍 Mumbai Suburban