Senior Principal Information Security Risk Specialist
On-sitePune, Maharashtra, India
Job Summary
Lead enterprise cybersecurity, technology, cloud, data, and AI risk assessments to identify, evaluate, prioritize, and monitor information security risks. Maintain risk methodologies, scoring models, risk taxonomies, and the enterprise information security risk register. Partner with risk owners to evaluate risk exposure, develop treatment strategies, document mitigation activities, and monitor remediation efforts. Provide independent challenge and oversight of risk assessments, treatment plans, mitigation strategies, and risk acceptance recommendations. Support continuous improvement of enterprise information security risk management processes, governance standards, and program maturity. Develop and maintain risk metrics, key risk indicators, dashboards, and governance reports to support leadership decision-making. Partner with Information Security, IT, Privacy, Compliance, Internal Audit, Legal, and Enterprise Risk Management stakeholders to facilitate risk workshops, reviews, and governance discussions. Serve as a trusted advisor regarding information security risk management, cybersecurity governance, and emerging technology risk.
Required Qualifications
- Bachelor's degree and a minimum of 10 years of relevant experience, or an advanced degree with a minimum of 8 years of relevant experience, or an equivalent combination of education and experience
- Expertise in Information Security Risk Management, cybersecurity governance, technology risk management, Governance, Risk & Compliance (GRC), information assurance, enterprise risk management, audit, or related disciplines
- Experience executing risk assessments, maintaining risk registers, administering risk methodologies, evaluating mitigation effectiveness, and supporting governance processes
- Strong understanding of cybersecurity, cloud computing, artificial intelligence, privacy, data governance, regulatory compliance, and emerging technology risks
- Experience facilitating risk workshops and translating complex technical findings into business-focused risk recommendations
- Experience supporting risk quantification, business impact analysis, and risk treatment decision-making processes
- Strong analytical, communication, facilitation, and stakeholder management skills
Desired Qualifications
- Experience supporting enterprise Information Security Risk Management Programs within large, complex, or global organizations
- Experience developing risk dashboards, KRIs, KPIs, executive reporting, governance metrics, and risk heat maps
- Experience supporting cyber risk quantification programs utilizing FAIR methodologies or similar quantitative risk models
- Experience facilitating cyber, cloud, data, artificial intelligence, and technology risk assessments
- Experience supporting AI governance initiatives and implementation of NIST AI RMF and ISO/IEC 42001
- Experience integrating cybersecurity, privacy, AI governance, data governance, and risk management practices into enterprise governance frameworks
- Experience within healthcare, medical technology, life sciences, manufacturing, or other highly regulated industries
- Experience working with ServiceNow IRM, SAP GRC, AuditBoard, or similar GRC technologies
- Knowledge of NIST CSF, RMF, ISO/IEC 27001, ISO/IEC 31000, ISO/IEC 42001, HIPAA, NIS2, and related privacy and regulatory frameworks
- CRISC certification
- CISSP certification
- CISM certification
- CISA certification
- CGRC certification
- Open FAIR Foundation or Open FAIR Practitioner certification
- ISO/IEC 27001 Lead Implementer or Lead Auditor certification
- ISO/IEC 42001 Artificial Intelligence Management Systems Certification
- AI Governance, AI Assurance, Responsible AI, or Emerging Technology Risk Certifications
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.