Cybersecurity Lead - Governance, Risk & Compliance
On-siteBengaluru, Karnataka, India
Job Summary
Implement cybersecurity frameworks such as ISO 27001, SOC 2, and NIST from a technical GRC perspective for clients. Conduct risk assessments, gap analyses, and security audits to identify vulnerabilities and recommend actionable mitigation strategies. Assist clients in securing cloud environments by providing guidance on best practices and supporting secure solution design. Deliver GRC advisory services, develop security policies, and lead internal and external audits while maintaining defensible documentation. Manage third-party risk assessments and deliver security awareness training to client teams. Collaborate with IT, Security, Legal, and Business stakeholders to align GRC initiatives with organizational goals. Stay informed about evolving threats and regulations to enhance advisory services. Mentor junior team members in GRC practices.
Required Qualifications
- Bachelor's or Master's degree in Cybersecurity, Information Technology, or related field
- 4 - 6 years of experience in cybersecurity consulting, implementation, or GRC advisory
- Solid knowledge of ISO 27001, SOC 2, NIST CSF, PCI DSS, GDPR, and other regulatory frameworks
- Hands-on experience in cloud security (AWS/Azure/ GCP) and implementation of security controls
- Strong understanding of risk assessment, control implementation, and compliance validation processes
- Effective communicator with the ability to engage both technical and business stakeholders
- Strong organizational and documentation skills
Desired Qualifications
- CISSP, CISA, ISO 27001 LI/LA, CRISC, or equivalent (at least one is highly desirable)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.