Manager - GRC (Cybersecurity)

7 - 8 years

30 - 35 Lacs

Posted:3 hours ago| Platform: Naukri logo

Apply

Work Mode

Work from Office

Job Type

Full Time

Job Description

We are seeking a motivated and skilled Information Security Risk Manager with a strong background in information security Risk management willing to take on challenging assignments. The successful candidate will play an essential role in executing and optimizing Risk management framework, focusing on identifying, assessing, and mitigating information security Risks. This mid-level role requires both technical knowledge and effective communication skills to articulate complex security and Risk concepts to varied stakeholders. The role demands an understanding of regulatory requirements (e.g., UAE Information Assurance) and industry standards (e.g., NIST Risk Management Framework (RMF), ISO 31000, ISO 27001) along with practical experience in information security and Risk management. The candidate should have relevant experience, knowledge and skills to take up the below mentioned roles and responsibilities.

Role Description

  • Conduct Information Security Governance, Risk & Compliance (GRC) consulting projects for customers globally using various International, National and Sectoral standards like PCI-DSS, ISO 27001, NIST CSF, RBI CSF, IRDA, NPCI, UIDAI etc.
  • Define, document, implement, and refine information security management frameworks within client organizations. This includes Information security strategy, policies, procedures, standards, guidelines, SOPs, forms, templates, etc.
  • Document/update Risk management methodology supported by a threat-vulnerability assessment in collaboration with key stakeholders within the organization.
  • Assist in the implementation/maintenance of information security policies and procedures in compliance with governance, legal, contractual, or internal requirements.
  • Conduct comprehensive Risk assessments in close coordination with internal and external stakeholders to enable informed decision-making by stakeholders while keeping business objectives paramount.
  • Provide expert guidance to stakeholders in other departments for appropriate Risk treatment, monitoring and review.
  • Review Cybersecurity and Risk aspects of business cases, IT application/infrastructure changes, project proposals, requirements, solution designs, and system architectures.
  • Create and promote security awareness campaigns and conduct information security awareness programs to enhance the information security knowledge of staff and management on the latest threats and vulnerabilities.
  • Effectively handling Project management, Team management and delivery management.
  • Train the internal team on GRC & Risk assessment.
  • Participate in presales meetings with prospective customers and offer specialized GRC and Risk management consulting services.
  • Monitor and review information security compliance.
    o Coordinate with the customer IT project management department, vendors, and consultants to

build an effective security program.

  • Lead annual planning, information security architecture, and governance reviews for customer organizations.

2. Key Responsibilities:

  1. Knowledge of Risk management principles and conducting end-to-end Risk Management.
  2. Identify, assess, and prioritize information security Risks across the organization.
  3. Develop and maintain Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) to monitor and measure Risk levels and the effectiveness of Risk management efforts.
  4. Recommend and track the implementation of Risk mitigation strategies and controls.
  5. Conduct frequent Risk assessments and reviews to ensure the effectiveness of controls.
  6. Monitor and report on the status of Risk management activities and initiatives.
  7. Recommend enhancements to Risk assessment methodology.
  8. Maintain the Risk register within the GRC platform, ensuring it is updated with high- quality, relevant content.
  9. Experience with information security architectures and security assessments.
  10. Familiarity with systems, database, network, and application security will be an added advantage.
  • Governance

    :
  1. Strong knowledge of GRC/Risk Management standards/frameworks such as ISO 27001,ISO 31000,ISO 27005, NIST RMF, CSF and regulatory frameworks like UAEs Information Assurance Standard, RBI CSF, etc.
  2. Assist in enforcing information security policies, procedures, and standards.
  3. Contribute to the maintenance of a governance framework for managing information security Risks.
  • Collaboration

    :
  1. Provide expertise and guidance on information security matters to key stakeholders,
    fostering strong working relationships across departments.
  2. Serve as a liaison and advisor to customer IT project management, vendors, and consultants.
  • Continuous Improvement

    :
  1. Stay informed on emerging trends, threats, and technologies in information security.
  2. Recommend and implement improvements to the Risk management framework, tools, and methodologies.
  • Compliance & Risk Assessments

    :
  1. Conduct independent security Risk assessments to support informed decision-making
    aligned with business objectives.
  2. Review the security aspects of business cases, IT applications, infrastructure changes, project proposals, requirements, solution designs, and system architectures.
  3. Conduct ISO 27001, PCI-DSS, and other compliance assessments as needed, especially for banking information security audits.
  • Security Awareness

    :
  1. Design and conduct innovative information security awareness programs to educate
    employees and management about current threats and security best practices.
  2. Train and mentor the internal team and clients on GRC, Risk assessment, and information security frameworks.
  • Project & Delivery Management

    :

1. Oversee project management and delivery for assigned teams, ensuring alignment with client requirements and quality standards.

3. Required Certifications:

  • Required: Any of the following certifications: CISSP, CISA, CISM, CRISC, CGEIT, GRCP, or GRCA. o Good to have: ISO 27001 Lead Auditor, ISO 27001 Lead Implementer, IAPP Certified, CDPSE,

CCSK, CCSP, CCAK, ISO 27701 privacy, ISO 20000, PCI QSA, ISO22301.

4. Other Skills:

  1. a)  Strong analytical and strategic mindset in Cybersecurity Governance, Risk and Compliance domain.
  2. b)  Strong acumen to communicate complex Cybersecurity concepts concisely and in a business context.
  3. c)  Ability to collaborate with a broad range of business and technology stakeholders including top management representatives.
  4. d)  Exceptional interpersonal relationship management and influencing skills.
  5. e)  Should possess very good communication skills (strong written/spoken English language skills &
    presentation skills).
  6. f)  Positive attitude, problem solving skills and attention to detail.
  7. g)  Should be results-oriented and able to deliver within preset deadlines.
  8. h)  Excellent Presentation & Internal as well as External Customer Facing skills.
  9. i)  Should value quality and client satisfaction.
  10. j)  Project Management skills and experience.
  11. k)  Skilled to work with minimal supervision.

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now
CIEL HR logo
CIEL HR

Human Resources

Noida

RecommendedJobs for You