Develop, implement, and maintain risk and governance frameworks
Guide teams/Handle client information security posture, identify the gaps/risks in the existing environment and develop solutions to mitigate the identified gaps/risk
Recommend security solutions and enhancements aligned with business goals and threat landscape
Conduct security risk assessments of third-party vendors and service providers
Define TPRM frameworks and integrate them into the overall risk management program
Perform cybersecurity maturity assessments using established frameworks such as NIST CSF, NIST-800-53, ISO 27001
Frontend teams for ISO 27001 based Information Security Management System implementation and sustenance-based projects
Lead risk identification, evaluation, mitigation, and monitoring activities
Deliver actionable insights and improvement roadmaps based on assessment results
Plan, execute, and report on comprehensive IT security audits
Manages security and cyber strategy projects, guides the team on a day-to-day basis and ensures that assigned tasks and responsibilities are fulfilled in a timely fashion
Responsible to assist client in review / implement Information Security controls in areas as mentioned, but not limited to: Change management process, Incident management process, Backup process, User identity and access management, Antivirus management, SLA performance and monitoring, Media handling & Exchange of information, Physical and environmental Security, and Media & Information Handling
Conduct and support PCI DSS assessments and gap analysis
Ensure compliance with cybersecurity guidelines and regulations issued by RBI, SEBI, IRDA, BCAS, NCIIPC, and other relevant bodies
Plan and execute ITGC control testing covering areas such as access management, change management, and operations controls
Identify control gaps and support remediation efforts
Desired qualifications
B
E/ B-Tech (Tier 1/2) or master s degree in information security, Computer Science, or a related field
Professional certifications such as ISO 27001 LA/LI
2 - 4 years of relevant experience in cybersecurity consulting, risk management, and compliance
In-depth knowledge of security frameworks and standards (eg NIST, ISO 27001, COBIT)
Strong analytical, communication, and stakeholder management skills
Location and way of working
Base location: Mumbai
Professional is required to work from office
Your role in the team
We expect our people to embrace and live our purpose by challenging themselves to identify issues that are most important for our clients, our people, and for society
Subject matter specialist in GRC and multiple security domains
Extensive experience in leveraging industry standards and frameworks such as ISO/IEC 17799, ISO/IEC 27001, COBIT, ITIL, etc
Establishing and maintaining risk governance frameworks, facilitating risk identification, evaluation, mitigation, and continuous monitoring
Experience in design, development, and roll-out of security programs, developing IT risk management strategies, compliance programs
Overseeing third-party risk assessments and managing compliance with regulatory frameworks such as RBI, SEBI, IRDA, PCI DSS, and others
Advising on secure cloud architecture and best practices across AWS, Azure, and Google Cloud platforms, ensuring cloud environments meet compliance and security standards
Planning and executing IT security audits alongside IT General Controls (ITGC) testing, identifying gaps, and collaborating with teams to remediate vulnerabilities
Assessing the organization s cybersecurity maturity (using frameworks like NIST CSF) and developing strategic roadmaps to strengthen security posture over time
Possesses certifications such as ISO27001 LA/ LI, ISO22301 LA/LI