Role : Cyber Risk Management Lead
- Experience : 5 to 10 Years
- Office location-Sector-125, Noida
- Required Qualification : Bachelor of Engineering - Bachelor of Technology (B.E. / B.Tech.)
Additional Information :
There are 2-3 rounds in the interview process.This is 5 days work from office role (No Hybrid / Remote options available)Final round will be F2F (Mandatory)About role :
We are seeking a Cyber Risk Management Lead to identify and remediate or mitigate risks. Candidate should have effective task management skills and the ability to communicate effectively. The individual must be able to rapidly respond to security incidents and should have at least 5 years of relevant experience in Cyber security Risk management.
Candidates Should have deeper understanding with some hands-on experience on enterprise IT infra components such as O365 suite, advanced firewalls, IPS / IDS / HIPS, routers / switches, VPN, proxy, AV / EDR, DNS, DHCP, multi factor authentication, virtualization, Email systems / security, Web Proxy, WAF, DLP etc. along with cloud environments like AWS (Must), Azure etc.
Job Description :
Understanding applicable regulations, guidelines, and industry best practices to manage risk and ensure complianceDeveloping, maintaining, or auditing security documentation such as policies, standards, and proceduresMonitoring security internal control effectiveness for EDR, Email Security, Server security, Cloud security etcConducting internal security assessments to ensure continued complianceExplaining roles in managing risk to cross team functions and getting buy-in to improve the organizational risk postureManaging SOC 2 Type 2 assessment and provide adequate support for collecting relevant evidence for all relevant controlsShould be able to review RFPs (request for proposal) and provide responses for Cyber security related itemsManage Risk GovernanceImplement / govern AWS Cloud and Office 365 SecurityManage and support internal and external auditsFollow up till closure on audit findings if anyManage dashboards and reports to keep track of priority events for IT and ISCreate MOM for Board MeetingsVendor Evaluation for cyber security controlsFirewall rules review for On-premises and AWS firewallSecurity Awareness : Create materials PPT / e-mailers and provide training as neededIncident management and Business continuityCISO dashboard and success reportsMeet with business team to understand their business requirements from cyber security perspectiveHas basic knowledge of audit requirements (SOC2, HIPPA, ISO27001, etc.)Understanding of respective industry best practices (e.g., NIST, ISO, OWASP, ITIL)At least one security certification is strongly preferred, such as Certified Information Security Management (CISM), Certified Risk Information Security Control (CRISC), or Certified Information Systems Security Professional (CISSP)Prior experience of management of technology infrastructure is preferredref : hirist.tech)