Talent.com
TC - CS - SRCR - Cyber Risk And Compliance - Manager - E

TC - CS - SRCR - Cyber Risk And Compliance - Manager - E

ConfidentialIndia
4 days ago
Job description

At EY, we're all in to shape your future with confidence.

We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.

Join EY and help to build a better working world.

Consultant / Senior Consultant / Assistant Manager / Manager - Cyber Security- GRC Specialist

As part of our Cyber Technology Consulting team, you will handle leading and managing Cyber Governance, Risk, and Compliance (GRC) engagements for clients across the MENA region. You will collaborate closely with stakeholders to assess, develop, and enhance cybersecurity governance frameworks, risk management practices, and compliance programs in line with global standards and regulatory requirements. The client base spans diverse sectors and includes collaboration with other teams across Advisory services.

The opportunity

We're looking for consultant / senior consultant / assistant manager / manager with strong consulting background and hands-on expertise in implementing enterprise cyber risk and governance programs. This is an exceptional opportunity to work with senior leadership across industries and influence strategic cybersecurity decision-making at the highest levels.

Your Key Responsibilities

  • Lead and deliver end-to-end cyber GRC engagements, including policy and framework development, control assessments, regulatory compliance, and cyber risk assessments.
  • Design and implement cybersecurity governance models, risk management processes, and third-party risk programs aligned with leading standards (e.g., ISO 27001, NIST CSF, COBIT, CSA).
  • Assess client readiness for local and global regulations such as NCA ECC, SAMA, UAE IA, GDPR, and sector-specific guidelines.
  • Manage enterprise cyber risk assessments, maturity assessments, and business impact analyses (BIAs).
  • Advise on the implementation and enhancement of GRC tools and technologies (e.g., eGRC platforms).
  • Support business development by identifying client needs, preparing proposals, and managing relationships.
  • Mentor and coach team members, ensuring professional growth and knowledge sharing across the practice.
  • Develop detailed reports, articulate technical findings, and deliver actionable recommendations to both technical teams and executive stakeholders.
  • Manage multiple engagements, ensuring timely delivery, quality assurance, and adherence to industry best practices.
  • Stay updated with emerging cyber threats, vulnerabilities, and offensive security techniques, and incorporate these insights into client engagements

Skills And Attributes For Success

  • Strong understanding of cybersecurity and risk governance principles, regulatory landscapes, and compliance obligations.
  • Experience designing and implementing enterprise-wide GRC programs and policies.
  • In-depth knowledge of control frameworks (e.g., ISO 27001 / 2, NIST CSF, NIST 800-53, COBIT, PCI DSS, SWIFT CSCF).
  • Familiarity with sector-specific standards (e.g., NCA ECC / SAMA CSF for KSA, UAE IA / NESA, or energy and financial sector mandates).
  • Ability to conduct technology and cybersecurity risk assessments for applications, infrastructure and network assets
  • Collaborating with other members of the engagement team to plan the engagement and develop work program timelines, risk assessments and other documents / templates.
  • Mentor and coach team members, ensuring professional growth and knowledge sharing across the practice.
  • Ability to interpret complex technical results and present insights to business stakeholders.
  • Strong analytical, problem-solving, and critical-thinking skills.
  • Excellent communication and collaboration skills
  • To qualify for the role, you must have

  • A bachelor's or master's degree in information technology, cyber security etc.
  • Excellent communication skills with a consulting mindset.
  • 2-8 years of experience in GRC and cyber security assessments
  • A valid passport for travel.
  • Excellent communication skills with a consulting mindset.
  • Ideally, you'll also have

  • Industry-recognized certifications such as CISSP, CISM, CRISC, ISO 27001 LA
  • Experience working with GRC platforms (e.g., Archer, ServiceNow GRC etc.).
  • Familiarity with data privacy regulations (e.g., GDPR, DPD, PDPL).
  • Understanding of cyber risk quantification methods (e.g., FAIR, Monte Carlo simulations).
  • What We Offer

    We offer a competitive compensation package where you'll be rewarded based on performance and recognized for the value you bring to our business. Plus, we offer :

  • Continuous learning : You'll develop the mindset and skills to navigate whatever comes next.
  • Success as defined by you : We'll provide the tools and flexibility, so you can make a meaningful impact, your way.
  • Transformative leadership : We'll give you the insights, coaching and confidence to be the leader the world needs.
  • Diverse and inclusive culture : You'll be embraced for who you are and empowered to use your voice to help others find theirs.
  • EY | Building a better working world

    EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

    Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

    EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

    Skills Required

    Pci Dss, Gdpr, Archer, Fair, Ecc, Swift, Iso 27001, Cobit

    Create a job alert for this search

    Cs • India

    Related jobs
    • Promoted
    • New!
    Manager - BAS Cyber - VAPT - Gurgaon - 5+ years of experience

    Manager - BAS Cyber - VAPT - Gurgaon - 5+ years of experience

    BDO IndiaBas, India
    Perform Vulnerability Assessment and Penetration Testing (VAPT) for web applications, mobile applications, and APIs to identify potential security risks. Conduct Web Application Testing including st...Show moreLast updated: 13 hours ago
    • Promoted
    Cybersecurity Director

    Cybersecurity Director

    Vriba SolutionsIndia, India
    The Cybersecurity Director is responsible for the strategic vision and scaling of the cybersecurity practice to serve external clients. This leader will ensure robust security governance, risk manag...Show moreLast updated: 3 days ago
    • Promoted
    • New!
    GRC Manager

    GRC Manager

    Kotak Mutual FundRepublic Of India, IN
    Position : Governance, Risk & Compliance (GRC) Specialist.We’re seeking a skilled GRC professional to lead governance, risk management, and compliance initiatives across IT and cybersecurity domains...Show moreLast updated: 15 hours ago
    • Promoted
    • New!
    Assistant Manager, Cybersecurity Compliance

    Assistant Manager, Cybersecurity Compliance

    Accedere LimitedRepublic Of India, IN
    Max 5 years) of experience with InfoSec Certification of min ISO 27001 LA / CISA.Kindly read the entire JD before applying. Accedere is a CERT-In Empanelled Audit firm, a CPA Firm as well as a Certifi...Show moreLast updated: 15 hours ago
    • Promoted
    • New!
    Cybersecurity Engineering Manager

    Cybersecurity Engineering Manager

    TransUnionChennai, Republic Of India, IN
    TransUnion’s Global Information Security organization is seeking a passionate and experienced leader to join our Global Insider Threat Program as Manager – Insider Threat Engineering.In this role, ...Show moreLast updated: 15 hours ago
    • Promoted
    Hardening Compliance Specialist / Cyber Security Risk & Compliance Specialist

    Hardening Compliance Specialist / Cyber Security Risk & Compliance Specialist

    VOISPune, Republic Of India, IN
    We're seeking a dynamic professional for "Hardening Compliance Specialist" role based in Pune.If you're ready to make an impact, this could be the perfect fit!. Working Persona : Hybrid (8 days in a ...Show moreLast updated: 1 day ago
    • Promoted
    • New!
    Technology Risk Management Lead

    Technology Risk Management Lead

    Smart IMS Inc.Republic Of India, IN
    Singapore to join our team, supporting a global investment bank.The role will sit within the APAC Risk & Controls function of the bank, which works with Application Managers, Enterprise Control fun...Show moreLast updated: 15 hours ago
    • Promoted
    Risk Consulting - Senior - Digital Risk - OT Risk

    Risk Consulting - Senior - Digital Risk - OT Risk

    ConfidentialIndia
    At EY, we're all in to shape your future with confidence.We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.Join EY and help ...Show moreLast updated: 22 days ago
    • Promoted
    • New!
    Manager - Bas Cyber - Vapt - Gurgaon - 5+ Years Of Experience

    Manager - Bas Cyber - Vapt - Gurgaon - 5+ Years Of Experience

    BDO IndiaBās, Republic Of India, IN
    Perform Vulnerability Assessment and Penetration Testing (VAPT) for web applications, mobile applications, and APIs to identify potential security risks. Conduct Web Application Testing including st...Show moreLast updated: 9 hours ago
    • Promoted
    Risk And Compliance It Cyber Lead

    Risk And Compliance It Cyber Lead

    CSI GLOBAL LTDPune, Republic Of India, IN
    The Cybersecurity function is responsible for enabling businesses and functions to.Cybersecurity Lead for Risk and Compliance IT is a role supporting the Chief Information.Security Officer for Ente...Show moreLast updated: 1 day ago
    • Promoted
    Soc Manager

    Soc Manager

    Network IntelligenceRepublic Of India, IN
    The SOC Manager will lead and mature the Security Operations Center (SOC), overseeing threat monitoring, detection, incident response, and overall security operations. This role requires strong lead...Show moreLast updated: 9 days ago
    • Promoted
    Cyber Security Manager

    Cyber Security Manager

    ConfidentialIndia
    The Cyber Security Manager is responsible for.The Cyber Security Manager also leads a team of security professionals and collaborates across departments to strengthen the company's overall.Develop,...Show moreLast updated: 16 days ago
    • Promoted
    Risk Manager

    Risk Manager

    ConfidentialIndia
    Come build community, explore your passions and grow your career.If you join the Microsoft Business Operations team, you will join an organization that strives to make doing business with Microsoft...Show moreLast updated: 21 days ago
    • Promoted
    Senior Manager IS Cyber Culture & Awareness

    Senior Manager IS Cyber Culture & Awareness

    MashreqIndia, India
    The Cyber Security Awareness Specialist plays a critical role in maturing Mashreq Bank’s cyber security awareness program. The specialist is responsible for fostering a culture where Cybersecurity i...Show moreLast updated: 18 days ago
    • Promoted
    • New!
    Asst. Manager-Cyber Compliance

    Asst. Manager-Cyber Compliance

    Accedere LimitedRepublic Of India, IN
    Max 5 years) of experience with InfoSec Certification of min ISO 27001 LA / CISA.Kindly read the entire JD before applying. Accedere is a CERT-In Empanelled Audit firm, a CPA Firm as well as a Certifi...Show moreLast updated: 15 hours ago
    • Promoted
    Lead Risk Manager

    Lead Risk Manager

    ConfidentialIndia
    FairMoney is a pioneering mobile banking institution specializing in extending credit to emerging markets.Established in 2017, the company currently operates primarily within Nigeria, and it has se...Show moreLast updated: 22 days ago
    • Promoted
    BCP / DR - Technical Lead-Cybersecurity

    BCP / DR - Technical Lead-Cybersecurity

    ConfidentialIndia
    Design, implement, and maintain Business Continuity Plans (BCP) and Disaster Recovery (DR) strategies aligned with organisational policies and ISO standards (ISO 22301, ISO 27031).Collaborate with ...Show moreLast updated: 18 days ago
    • Promoted
    Head - Cyber Security Domain

    Head - Cyber Security Domain

    Timus Consulting servicesIndia
    Description : Job Title : Head of Cybersecurity Practice (Global) Location : Flexible / Global Job Type : Full-TimeShow moreLast updated: 30+ days ago