Location: Bangalore
Experience: 10 to 15 years
About the role
Strengthen cyber risk management system, in a context of evolving threats, increased requirements from regulators and the continuous transformation of business infrastructures and services. As such, it wishes to benefit from the consultant's expertise in terms of:
- Cyber Risk Analysis,
- identification and assessment of vulnerabilities,
- definition of remediation plans,
- and support for project and operational teams in risk management.
As observed in the existing services related to cybersecurity, the mission is part of the overall cyber strategies as well as best practices in risk management.
Scope of the Role
The service covers the entire cyber risk analysis cycle, and includes support for projects, operational teams, and security governance.
Internal Risk Analysis
- Carrying out risk analyses on applications, infrastructures, flows, IT projects and exposed devices.
- Methodology inspired by EBIOS RM
- Assessment of threat scenarios, business impacts, and probability of occurrence.
- Analysis of deviations from internal standards and recommendations.
Third-Party Risk Analysis (TPRM)
- Review of the risks related to service providers, SaaS/IaaS/PaaS providers.
- Evaluation of the security measures taken, risk scoring, definition of action plans.
- TPRM Steering Support
Project safety support
- Integration of security requirements (Secure by Design).
- Participation in architecture workshops, approvals, and design reviews.
- Recommendations on technical choices.
Risk Monitoring and Governance
- Updating of risk registers.
- Follow-up of actions, decisions, acceptances and justifications
- Contribution to safety committees.
Monitoring, repositories and standards
- Cyber monitoring (technical, regulatory and sectoral).
- Participation in the updating of safety policies, standards and guides, practice already observed.
Candidate Profile:
- Risk analysis methodologies (ISO 27005, NIST RMF, optional EBIOS RM as it is a French ANSSI methodology a training will be performed by SSG France).
- In-depth knowledge of network, application and cloud architecture.
- Security best practices (OWASP, CIS Benchmarks, NIST SP 80053).
- Understanding of IAM/PAM, DevSecOps, API security.
- CRISC / CISSP certified
- ISO 27005 / CISM
Transversal skills
- Ability to analyze and formalize.
- Autonomy, strength of proposal.
- Pedagogy and effective communication, in line with the profiles sought within the Group
- Good Communication & Stakeholder Management skills
Qualification & Certifications
- Engineering graduate - preferably B.E. /B.Tech in IT or Computer Engineering
- At least one Certification Preferred:-
- CRISC / CISSP certified
- ISO 27005 / CISM
At our organization, we are committed to fighting against all forms of discrimination. We foster a work environment that is inclusive and respectful of all differences.
All of our positions are open to people with disabilities.