C

ICT Risk Management Specialist (Information and Communication)

Colt Technology Services · Bengaluru, Karnataka, India - Gurugram, Haryana, India

5–12 yrs experiencefull_timePosted 3w ago
Apply now →

Job description

**Why we need this role** We are looking for an experienced **ICT Risk Management Specialist** to support the identification, assessment, and management of information and communication technology (ICT) risks across the organization. This role plays a key part in ensuring that ICT risks are effectively understood, documented, and mitigated in line with business objectives and regulatory expectations (e.g., TSA UK, NIS2, DORA). The ideal candidate has strong analytical skills, experience with risk frameworks, and the ability to engage stakeholders across technical and business domains. Join us and you will be part of a fast-growing community of like-minded experts to grow and learn alongside you in your career. **What you will do** **1.** **ICT Risk Identification & Assessment** - Identify and assess ICT risks across systems, applications, infrastructure, and third parties - Conduct risk assessments (qualitative and quantitative) aligned with organizational methodology - Maintain a centralized ICT risk register, ensuring risks are documented and regularly updated - Evaluate threats, vulnerabilities, and potential business impacts **2.** **Risk Management & Mitigation** - Support risk owners in defining and implementing mitigation plans - Track risk treatment actions and ensure timely remediation - Assess residual risk and ensure alignment with risk appetite - Provide guidance on risk treatment strategies (accept, mitigate, transfer, avoid) **3.** **Framework & Regulatory Alignment** - Align ICT risk management practices with: - DORA (ICT risk and operational resilience) - NIS2 Directive - ISO 27005 / ISO 31000 - NIST Risk Management Framework - Ensure risks are linked to controls and compliance requirements 4. Risk Reporting & Governance - Prepare risk reports, dashboards, and metrics for management and governance forums - Present key risks, trends, and mitigation status to stakeholders - Support risk committees and governance structures **5.** **Collaboration & Advisory** - Work closely with security, IT, enterprise risk compliance, and business teams - Provide risk advisory during projects, system implementations, and change initiatives - Promote risk awareness and risk-based decision-making across the organization **What were looking for** Must haves: - Bachelors degree in Information Security, Risk Management, IT, or related field - 6+ years of experience in **ICT risk management, information security, or GRC** - Hands-on experience with **risk assessments and risk registers** - Understanding of ICT environments (networks, cloud, applications, infrastructure) - Strong analytical and risk assessment skills - Ability to translate technical risks into business impact - Structured thinking and attention to detail - Effective communication and stakeholder engagement - Ability to manage multiple risks and priorities Might haves: - Certifications such as: - CRISC (Certified in Risk and Information Systems Control) - CISM, CISSP, or ISO 27005 Risk Manager - Experience in regulated industries (financial services, telecom, critical infrastructure) - Familiarity with: - DORA ICT risk requirements - NIS2 risk management obligations - Experience with GRC tools (Riskonnect, ServiceNow GRC, Archer, etc.)