B

GRC with Cloud Security- Bengaluru

BDO India · Bengaluru, Karnataka, India

full_timePosted 3w ago
Apply now →

Job description

**Role & responsibilities** : - Lead and manage end-to-end delivery of cybersecurity consulting engagements including regulatory assessments, technical reviews, and risk advisory. - Conduct and review audits and assessments aligned to frameworks such as ISO 27001, RBI, SEBI, IRDAI, and other applicable standards. - Oversee evaluation of IT General Controls (ITGC) and IT Application Controls (ITAC), and support gap remediation strategies. - Collaborate with client stakeholders to define cybersecurity objectives, identify risks, and implement actionable solutions. - Support technical/business development activities, including responding to RFPs/RFIs, developing solution proposals tailored to client requirements, defining delivery models, and preparing supporting materials such as data capture questionnaires (DCQs), scoping documents, and client-specific value propositions. - Work closely with internal leadership to build service capability decks, participate in opportunity planning, and contribute to strategic client conversations. - Support ongoing project operations, including maintaining project delivery, team operations and other delivery documentation / templates to ensure team efficiency and reporting accuracy. - Mentor junior team members and contribute to the knowledge development of the practice. **Candidate Requirements:** - 2 to 4 years of experience in cybersecurity consulting with strong exposure to both delivery and client engagement. - Proficiency in standards and regulatory frameworks such as ISO 27001, RBI, SEBI, IRDAI, ITGC, and ITAC. - Ability to translate client requirements into executable cybersecurity solutions and delivery plans. - Experience supporting technical/BD activities, including solutioning for proposals, drafting scoping documents, and collaborating with cross-functional teams. - Strong documentation and coordination skills with the ability to create and maintain organized repositories of project delivery assets. - Strong communication and stakeholder management skills, including the ability to present to senior leadership. - Certifications such as ISO 27001 Lead Auditor, CISA, or CISM are desirable. - Exposure to Vulnerability Assessment and Penetration Testing (VAPT), Red Teaming or other offensive testing areas will be an added advantage.