**Job Title:** Principal - Cyber Risk and Assurance
**Position Summary:** The Principal - Cyber Risk and Assurance role at GSK is an exciting opportunity to lead efforts in safeguarding our business, customers, and patients from cyber risks. This position involves partnering with global teams to embed "secure by design" principles across projects and operations, ensuring robust cyber security coverage throughout the development lifecycle. The role requires collaboration with cross-functional teams, including Cyber Security Operations, Governance Risk and Compliance, and Architecture and Engineering, to address business needs effectively. We value candidates who are proactive, analytical, and possess strong communication skills to influence and drive a culture of cyber resilience. **Responsibilities:** 1. Identify, document, and report business cyber risks to senior stakeholders, positively influencing the cyber security posture. 2. Provide subject matter expertise in managing risks across key areas such as data, applications, cloud, and identity access management (IAM). 3. Conduct formal cyber security risk assessments for business projects, ensuring compliance with GSK policies, controls, and regulatory requirements while meeting business objectives. 4. Collaborate with internal and external stakeholders to recommend security and privacy controls that mitigate risks effectively. 5. Guide business owners and stakeholders throughout the delivery lifecycle, ensuring tailored and proportionate information security measures. 6. Partner with global teams to align cyber risk management frameworks, metrics, and reporting with GSK s strategy and initiatives. **Qualifications/Skills:** **Basic Qualifications:**
10+ years of cyber security risk assessments experience.
1. Bachelor s degree in Cyber Security, Information Technology, Computer Science, or a related field. 2. Demonstrated experience in cyber security principles, IT security controls, and related technologies. 3. Experience conducting cyber security risk assessments and third-party security and data privacy evaluations. 4. Strong verbal and written communication skills in English, with the ability to interact effectively with professionals at all levels. 5. Knowledge of frameworks and standards such as ISO 27001, NIST, and CIS. 6. Ability to work with virtual teams across different countries, adapting to diverse work cultures and communication styles. **Preferred Qualifications:** 1. Professional certifications such as CISSP, CISM, or equivalent. 2. Experience with Governance, Risk, and Compliance (GRC) technologies for cyber risk management. 3. Proven ability to prioritize, delegate, and foster high-performance teams in a customer-focused environment. 4. Experience working with outsourced providers to drive positive organizational changes. 5. Familiarity with automation initiatives to enhance efficiency in cyber risk management processes. **Work Arrangement:** This role is based in India and follows a hybrid work model, combining on-site and remote work flexibility. --- *This Position Description is to provide a framework for job understanding between employee and manager. It may not cover or contain the full listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice and at the discretion of the management of the Company. .