Senior Cybersecurity Specialist
$150,000–$200,000 year
On-siteNanakramguda, State of Telangāna, Republic of India
Job Summary
Define requirements for business continuity, operations security, cryptography, forensics, regulatory compliance, internal counter-espionage, and physical security analysis to protect company assets. Assess and mitigate system security threats throughout the program life cycle, validate security designs in hardware, software, data, and procedures, and perform system certification and accreditation planning. Collaborate with cross-functional teams to identify, assess, and mitigate cybersecurity risks across products and services, ensuring adherence to HIPAA, GDPR, FDA, and NIST standards. Lead the design of process flows and drive GRC platform improvements through automation and workflow optimization.
Required Qualifications
- 7+ years of IT experience
- Bachelor's Degree in Engineering, MCA, or MSc
- 7+ years of experience in cybersecurity GRC (Governance, Risk, & Compliance), or external/internal audit, preferably within the medical device or healthcare industry
- Strong understanding of cybersecurity frameworks, regulatory requirements, risk management, and industry best practices (e.g., HIPAA, NIST, ISO 27001, GDPR, etc.)
- Minimum 5 years of experience executing key risk management activities, including conducting risk assessments using various quantitative and qualitative methodologies, such as the FAIR model (Factor Analysis of Information Risk)
- At least 3 years of active participation in the design and implementation of at least 2 comprehensive risk management programs (e.g., risk assessments, regulatory assessments) within a large, complex organization, including hands-on experience with program execution and improvement
- Proven expertise in process design and improvement related to risk management frameworks and methodologies, ensuring effective risk mitigation strategies are incorporated into operational processes
- Experience conducting NIST risk assessments (e.g., NIST CSF, NIST 800-53) and applying their standards and recommendations to improve organizational cybersecurity postures
- Strong knowledge of regulatory changes and trends impacting IT risk assessments, including compliance requirements such as GDPR, HIPAA, and others, ensuring risk management strategies align with the latest regulatory standards
- Minimum 3 years of experience evaluating technical design documents for systems or environments to assess associated risks, including reviewing architectural, infrastructure, and application designs for security and operational risk vulnerabilities
- Certified Information Systems Security Professional (CISSP)
- Certified in Risk and Information Systems Control (CRISC)
- Certified Information Security Auditor (CISA)
Desired Qualifications
- Knowledge of Operational Technology (OT) risk management, with the ability to assess risks related to OT environments and integrate them into overall IT risk strategies
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.