Cyber security Manager

3 days ago


Bengaluru, Karnataka, India GCOO Full time


Job Summary:

We are seeking an experienced IT Infrastructure Risk Officer and Security Operations Manager to join our team. In this role, you will be responsible for implementing and overseeing controls related to information system security (ISS) within our company's functional scope. You will ensure compliance with Group policies and security standards, perform security assessments, contribute to security audits, and communicate effectively with various stakeholders. Additionally, you will play a vital role in developing and maintaining the IT skills of our employees, participating in ISS events, and actively contributing to the overall IT function and security community within our organization.

Responsibilities:

Manage IT risk and IT compliance\: 

o   Contribute to the drafting of Group policies / standards on the ISS in relation to its functional scope; if necessary, define and maintain up-to-date local procedures / best practices to meet the specificities of its department; 

o   Participate in the definition of the strategy and roadmap of the ISS for its functional scope, in collaboration with the RSSI GTS and the ISS function;

o   Define and validate the roadmaps for implementing IT risk treatment plans (application of standards, implementation of controls, etc.), ensuring that the relevant teams obtain funding and commitment.

o   Contribute to the updating of permanent control policies (update of the library of normative controls, etc.)

Plan\: 

o   Contribute to Security Projects initiated directly by and for its reporting department;

o   Support the deployment of security projects initiated by the Group and/or GTS within its operating scope as a relay and participate in the governance of these projects;

o   In general, acting as a security expert to advise on projects deployed within its projected department

o   Assess and manage IT risk treatment in all new projects or infrastructure within its scope (integration of security into projects, security by design processes);

o   Enforce Group policies / standards and/or procedures / good security practices within its projected department;

o   Validate and monitor exceptions, RAF, etc.;

o   Lead the resolution of security incidents and contribute to the post-mortem investigation of security incidents;

o   Lead the remediation of critical vulnerabilities in coordination with technical teams, SOC and CERT;

o   Maintain up-to-date IT security risk assessment of products/services/infrastructure within its functional scope 

o   Monitor and coordinate the timely closure of audit recommendations (internal / regulators), where appropriate intervene in support of operational teams.

Controls\: 

o   Rely on the controls team for the implementation of controls relating to the ISS within its functional scope (operational controls, managerial controls, mitigant risk description, NIST, etc.) and follow the associated remediation plans; 

o   Perform regular security assessments of the most critical infrastructure in accordance with Group policies and security standards (pentest, review of high-privilege accounts, hardening, USF, etc.), and produce the resulting analysis reports;

o   Contribute to security audits (internal audit / regulators) within its scope.

Communicate\: 

o   Communicate regularly on the IT risks of its scope and on the mitigation plans;

o   Communicate the status of security audits (internal audit / regulators) as well as the plans for dealing with recommendations;

o   Communicate on its activities (definition of relevant KPIs/KRIs) and on security alert points;

o   In the event of the detection of a security anomaly on its functional scope, exercise a duty of alert as soon as possible vis-à-vis the RSSI GTS and its hierarchy;

o   Raise to its projected department any changes in Group policies / standards or decisions by the ISS function in relation to the activities of its functional scope.



Qualifications:

1. Bachelor's degree in computer science, information technology, or a related field. Relevant certifications (e.g., CISSP, CISM, CRISC) are preferred.

2. Proven experience in information system security management, risk assessment, and security operations.

3. Strong knowledge of security controls, regulatory requirements, and industry best practices.

4. Familiarity with NIST standards or equivalent and PEN test tools

5. Excellent communication skills, including the ability to communicate complex security concepts to both technical and non-technical stakeholders.

6. Strong analytical and problem-solving abilities.

7. Proactive approach to identifying and mitigating security risks.

8. Ability to work collaboratively in a team environment and contribute to a positive work culture.

9. Strong organizational and project management skills, with the ability to prioritize and multitask effectively.

10. Up-to-date knowledge of emerging security threats and trends.




  • Cyber Security

    2 days ago


    Bengaluru, Karnataka, India Schneider Electric Full time

    Looking for a project co ordinator who will work with the Governance Cyber Security team on implementing the various cyber security initiatives.Main missions :Contribute to the improvement of Schneider Electric's external Cybersecurity indicatorsRisk analysis and project management with external service providersPreparation of monthly reporting for Schneider...


  • Bengaluru, Karnataka, India Nasdaq Full time

    Nasdaq Technology is looking for a passionate Specialist with focus on Cyber Security Audit, to join the Bangalore technology center in India. If Innovation and effectiveness drive, you forward this is the place for you Nasdaq is continuously revolutionizing markets and undergoing transformations while we adopt new technologies to develop innovative...


  • Bengaluru, Karnataka, India CloudSEK Full time

    WHO ARE WE?We are a bunch of super enthusiastic, passionate, and highly driven people, working to achieve a common goal We believe that work and the workplace should be joyful and always buzzing with energyCloudSEK, one of India's most trusted Cyber security product companies, is on a mission to build the world's fastest and most reliable AI technology that...


  • Bengaluru, Karnataka, India Deloitte Full time

    Cyber:Deloitte Cyber understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful insights and help clients navigate the ever-changing threat landscape, leveraging cutting-edge design and technology as we partner with clients to transform their security posture.Position SummaryLevel: Senior Solution...

  • sfcc ui

    3 days ago


    Bengaluru, Karnataka, India Royal Cyber Full time

    Dear Candidate,We have opening for SFCC UI Developer , please find the detailed description belowCompany Details :Royal Cyber is a trusted global IT consulting & digital transformation partner, empowering enterprises for over two decades to evolve with agility, security, and innovation. Founded in 2002, Royal Cyber has built a strong legacy of helping...


  • Bengaluru, Karnataka, India GCOO Full time

    Requirements:· years of experience in security, IT, or a related field·       Strong understanding of vulnerability management, security frameworks, and compliance regulations·       Experience with Agile methodologies and Scaled Agile Framework (SAFe)·       Excellent communication, collaboration, and project management...


  • Bengaluru, Karnataka, India GCOO Full time

    Requirements:· years of experience in security, IT, or a related field·       Strong understanding of vulnerability management, security frameworks, and compliance regulations·       Experience with Agile methodologies and Scaled Agile Framework (SAFe)·       Excellent communication, collaboration, and project management...


  • Bengaluru, Karnataka, India Chevron Full time

    Total Number of Openings1Chevron is seeking highly skilled onsite augmentation technical experts to support OT cybersecurity initiatives across critical infrastructure. These experts will provide additional hands-on technical support during turnarounds, maintenance windows, and spikes in cybersecurity activity, ensuring timely and comprehensive...


  • Bengaluru, Karnataka, India Mitigata™ - Full-Stack Cyber Resilience Full time

    Company DescriptionMitigata is a full-stack cyber resilience company that secures businesses and individuals by integrating cybersecurity, insurance, compliance, and consultancy services. With support from over 800 clients, investors, and partners, Mitigata offers tailored solutions such as Smart Cyber Insurance, advanced cybersecurity measures, and...


  • Bengaluru, Karnataka, India HTC Global Services Full time

    Job DescriptionAbout the Role:We are seeking a skilled Cloud Security Analyst to join our team. The ideal candidate will have extensive experience in cloud security, particularly with Azure. This role involves ensuring the security of our cloud infrastructure, identifying and mitigating risks, and implementing best practices to protect our data and...