Designation: Manager - Cybersecurity Compliance & IT Audit
Location: Mumbai, India
Experience Required: 8+ Years
Employment Type: Full-time
About the Role:
We are seeking a highly experienced and strategic Manager Cybersecurity Compliance & IT Audit to lead our technical compliance, cybersecurity governance, and IT audit functions. In this role, you will be responsible for overseeing regulatory adherence, strengthening technology risk frameworks, and driving interaction with regulators and key external stakeholders. You will provide collaborative leadership, manage complex compliance challenges with high accountability, and ensure robust IT risk governance across the enterprise.
Candidate Profile & Key Qualifications:
Educational Qualification & Professional Certifications:
Education: Masters Degree in Computer Applications (MCA) / M.Tech / M.Sc. IT (or equivalent technical Master's degree).
Certifications: Professional certification such as CISA (Certified Information Systems Auditor) or CISSP (Certified Information Systems Security Professional) is strongly preferred. Additional certifications like CISM or ISO 27001 Lead Auditor/Implementer are a plus.
Technical & Core Skill Set:
- VAPT & Vulnerability Management: Proven ability to independently read, interpret, and analyze Web/Network VAPT reports, track remediation lifecycles, and validate issue closure.
- Architecture & Access Controls: Deep understanding of network, server, and application security controls, along with hands-on experience conducting User Access Reviews (UAR), Segregation of Duties (SoD), and Privileged Access Management (PAM) audits.
- Cloud Security & Incident RCA: Fundamental knowledge of cloud security governance (AWS/Azure/GCP) and the ability to thoroughly read, analyze, and evaluate Root Cause Analysis (RCA) reports post-incidents.
- Regulatory Expertise: Strong working knowledge of regulatory guidelines and compliance frameworks, specifically SEBI (CSCRF / SEBI System Audit Guidelines) and CERT-In directions, alongside standard frameworks like ISO 27001, ITGC, and ITAC.
Key Responsibilities & Scope of Work:
- Regulatory & Compliance Leadership: Drive compliance alignment with SEBI, CERT-In, and other regulatory bodies; act as the primary liaison during regulatory walkthroughs, system audits, and external assessments.
- IT Audit & Governance: Plan, execute, and lead enterprise IT General Controls (ITGC) and IT Application Controls (ITAC) assessments across applications, cloud environments, and core infrastructure.
- Vulnerability & Incident Oversight: Review internal and external VAPT findings, oversee risk remediation tracking with cross-functional technical teams, and analyze RCAs for security incidents to prevent recurrence.
- Risk & Control Framework Management: Develop, maintain, and enhance Risk & Control Matrices (RCM), Risk Registers, and Statement of Applicability (SoA) to maintain high audit readiness.
- Access & Third-Party Risk Oversight: Oversee identity and access governance practices (UAR, SoD) and execute Vendor/Third-Party Risk Assessments (TPRM) to mitigate supply chain security exposures.
- Executive Reporting: Prepare and present executive dashboards, audit metrics, and risk assessment reports for senior management and risk committees.
Key Attributes:
- Strong analytical, investigative, and problem-solving mindset.
- Executive-level written and verbal communication skills with the ability to translate complex technical risks into business context.
- Ability to manage high-accountability mandates independently while guiding cross-functional teams.
Didn’t find the job appropriate? Report this Job