Padmi

Cyber Risk and Compliance Advisor (Bengaluru)

BangalorePosted 2 months ago
CybersecurityMid-levelFull Time; Regular
Apply at Mitigata - Full-Stack Cyber Resilience

Opens the source posting on shine.com

Source description

About the role

View original

About Mitigata Mitigata is India's first Security + Compliance + Insurance company, helping businesses mitigate cyber risks through a combination of risk assessments, compliance consulting, cyber insurance, and security solutions. We work with businesses to strengthen their security posture, ensure regulatory compliance, and provide tailored cyber insurance policies to minimize financial exposure from cyber threats. We are backed by a consortium of premier investors, including Nexus Venture Partners, Titan Capital, and WEH Ventures, alongside a global network of industry leaders. Become a part of the first line of defence of digital India. Experience : 3- 7yrs Work location : Bangalore onsite (Work from Office) Required Skills & Expertise Technical Requisites The incumbent should have a fair understanding of the technological landscape (devices and appliances) which includes firewalls, routers, VPN/VDI, Active Directory, IDS/IPS, DLP, VLAN and proxies The incumbent should possess a good understanding of Identity and Access Management (IDAM) including federated access, privilege user access management (PUA), data access model (DAM), dynamic rules, entitlements, least privilege and rogue access The incumbent should also have fair understanding of vulnerability assessment (Network Discover, Asset-based scans, false positive analysis) zero-day vulnerability remediation, red-team exercise, penetration testing (SAST/DAST), source-code audit (SCA), vulnerability scoring and remedial process The incumbent should have fair exposure to architectural reviews, security flashpoints, network diagram review and review implementation test-cases for various security controls The incumbent should also have a good understanding of end-point hardening, patching process, log management (Technical logs/ Applicative logs and Business logs) and encryption techniques The incumbent should have knowledge of database security (obfuscation, pseudomisation, anonimisation), encryption of data at rest/ motion, data backup including restore testing and different types of backup (realtime, mirroring and incremental) The incumbent should have a fair knowledge of Application Security frameworks such as defense-in-depth, secure-by-design and SSDLC (Secure) framework for sift-left culture Operational Requisites The incumbent should have a good understanding and implementation experience of different standards (ISO), regulations (PCI-DSS, HIPAA, SOC- II, DPDP, GDPR et.Al., ) and frameworks (COSO, COBIT, CMMI, TOGAF, ITIL, CIS and NIST) The incumbent should have the valuable knowledge on complete lifecycle of an audit, assessment and gap analysis The incumbent should have hands on experience in developing continual improvement process, maturity assessments (CMMI/CIS), process-lean models, incident/ problem and change management The incumbent should have working experience on internal controls testing (technical and operational) for design and operating effectiveness. Suggest corrective actions for deficient controls and hand-hold control owners for control sign-off The incumbent should have hands-on experience on complete lifecycle of Risk Assessment (Asset identification, valuation, risk rank, risk treatment, create risk register, KPI/ KRA reporting and closure) It would be a plus if the incumbent has a good working relationship with the accreditors (BCI, DNV, TUV and BVQI) and assessors (EY, PwC, KPMG and other tier-II vendors) for the audit/ assessment engagement The incumbent should have hands on experience in carrying out vendor risk assessments (VPQR and TPRM) and drive open risks towards closure It would be a plus if the incumbent has working experience on GRC (Governance-Risk-Compliance) and ITSM tools such Archer eGRC, SNOW (ServiceNow), Proquis, Peregrine et.Al., Behavioural Requisites The incumbent should possess excellent vocabulary, verbal and written and narrative communication - (English) The incumbent should have good negotiation skills, not limited to clients and vendors, but extends to both internal and external stakeholders The incumbent should drive solutioning, upsell/cross-sell, requirement gathering and discovery calls with clients and vendors towards successful closure The incumbent should have experience in reporting KPIs/ KRAs and security posture to the Mid and Senior Management, not limited to metrics, but gap assessments, delinquent controls, roadmaps, functional limitations, technical overview and cost parameters The incumbent should have fair discretionary skills in service management, audit management, Operational efficiencies and drive projects towards targeted closures The incumbent should have experience in creating test-cases for Proof-of- Concepts (POC) and train new recruits and other team members in newer skills The incumbent should demonstrate an appetite for learning and upskilling basis

One address, no account. We’ll tell you when matching roles go live.