Padmi

IT Security And Compliance Manager

Delhi NCRPosted 3 months ago
CybersecuritySeniorFull Time; Regular
Apply at CMS It Services

Opens the source posting on shine.com

Source description

About the role

View original

As an IT Security GRC Consultant, your role will involve supporting the CISO in establishing a central Security Governance & Assurance function. This function aims to provide visibility into cybersecurity risks, compliance status, and control effectiveness across plants and corporate IT. Key Responsibilities: - Conduct risk assessment and maintain a centralized risk register - Track risks from VAPT, audits, and IT inputs - Monitor risk closure, aging, and ownership - Track and validate closure of vulnerabilities, security incidents, audit findings, and risks - Identify SLA breaches and control gaps - Highlight repeated non-compliance - Support ISO 27001 program and audits - Support security policy implementation - Support DPDP engagement - Coordinate audit evidence and closure of findings - Prepare monthly security dashboard covering vulnerability status, patch compliance, risk aging, and SLA adherence - Provide trend analysis and risk summaries - Track integration/implementation of security tools/solutions - Highlight gaps, delays, and risks - Work with IT teams and vendors - Drive closure through structured follow-ups - Provide inputs for escalation Experience Required: - 810 years in cybersecurity GRC/governance - Experience in ISO 27001 documents management, audit compliance, policies implementation - Risk and audit tracking - Security reporting - Conducting risk assessment and ensuring risk framework implementation - Driving user awareness program - Experience in a multi-location environment preferred Skills Required: - Strong risk tracking and analytical skills - Good understanding of network security, infrastructure security, vulnerability management, and access control mechanisms - Strong reporting and documentation capability - Ability to work with multiple stakeholders Certifications (Preferred): - CISA (Certified Information Systems Auditor) - ISO/IEC 27001 Lead Auditor - CRISC Location: Central role in Gurugram with periodic travel to plant locations in Hisar, Mundra, Jajpur. For further queries, please contact at 7290068760 or email at salma.saifi@cmsitservices.com. As an IT Security GRC Consultant, your role will involve supporting the CISO in establishing a central Security Governance & Assurance function. This function aims to provide visibility into cybersecurity risks, compliance status, and control effectiveness across plants and corporate IT. Key Responsibilities: - Conduct risk assessment and maintain a centralized risk register - Track risks from VAPT, audits, and IT inputs - Monitor risk closure, aging, and ownership - Track and validate closure of vulnerabilities, security incidents, audit findings, and risks - Identify SLA breaches and control gaps - Highlight repeated non-compliance - Support ISO 27001 program and audits - Support security policy implementation - Support DPDP engagement - Coordinate audit evidence and closure of findings - Prepare monthly security dashboard covering vulnerability status, patch compliance, risk aging, and SLA adherence - Provide trend analysis and risk summaries - Track integration/implementation of security tools/solutions - Highlight gaps, delays, and risks - Work with IT teams and vendors - Drive closure through structured follow-ups - Provide inputs for escalation Experience Required: - 810 years in cybersecurity GRC/governance - Experience in ISO 27001 documents management, audit compliance, policies implementation - Risk and audit tracking - Security reporting - Conducting risk assessment and ensuring risk framework implementation - Driving user awareness program - Experience in a multi-location environment preferred Skills Required: - Strong risk tracking and analytical skills - Good understanding of network security, infrastructure security, vulnerability management, and access control mechanisms - Strong reporting and documentation capability - Ability to work with multiple stakeholders Certifications (Preferred): - CISA (Certified Information Systems Auditor) - ISO/IEC 27001 Lead Auditor - CRISC Location: Central role in Gurugram with periodic travel to plant locations in Hisar, Mundra, Jajpur. For further queries, please contact at 7290068760 or email at salma.saifi@cmsitservices.com.

One address, no account. We’ll tell you when matching roles go live.

More at CMS It Services

Related open roles

View all roles