Manager Information Security Governance
Cognizant · Chennai, Tamil Nadu, India
Cognizant · Chennai, Tamil Nadu, India
**About Cognizant Corporate** Cognizant Corporate is a global community united by a shared purpose: to make a meaningful impact. We are committed to excellence and driven by outcomes that matter. Collaboration is at the heart of how we work, and our forward-thinking mindset fuels continuous learning, innovation, and growth. At Cognizant, careers transcend titles. We empower our people to think strategically, inspire others, and lead with purpose – always guided by our core values. Join us in shaping the future of business. **About the role** As a **Manager – Information Security Governance & Metrics Reporting**, you will be a key member of the **Extended CISO Tower's Cybersecurity Architecture & Risk (CAR)** practice, coordinating closely with Associate Directors, CAR team leads, Enterprise Architecture, IT and business stakeholders. You will own the operational health of Cognizant's **ISO/IEC 27001** Information Security Management System and act as **ISO/IEC 42001 Lead Auditor** for the AI Management System, while consolidating **Key Monthly Operations Metrics** across CAR teams into leadership-ready reporting. You will have the autonomy to bring structure, rigor and clarity to how we measure and communicate our security posture. As a team of self-starters, you can work with impact alongside our vibrant people and culture, all while enjoying unmatched learning opportunities. **In this role, you will:** • Own the day-to-day operation of Cognizant's **ISO/IEC 27001** Information Security Management System (ISMS) – maintaining the **Statement of Applicability, Risk Treatment Plans**, policies and control documentation. • Plan and execute the **internal audit program**, and coordinate **external certification and surveillance audits**, ensuring **non-conformities and corrective actions (NC/CAPA)** are tracked to verified closure. • Serve as **ISO/IEC 42001 Lead Auditor** for Cognizant's AI Management System (AIMS) – planning and conducting audits against Annex A controls (data governance, human oversight, AI impact assessment, transparency), reporting findings and driving corrective actions. • Act as the central coordination point across **CAR sub-teams, Enterprise Architects, IT, Compliance and business stakeholders**, driving open items, validations and remediation actions to closure. • Maintain strong working knowledge of Cognizant's **information security processes, policies and control framework**, ensuring day-to-day CAR activities stay aligned to them. • Own **Key Monthly Operations Metrics** – defining, tracking and consolidating **KPIs, KRIs and SLA/turnaround-time data** across CAR teams into a single, consistent reporting cadence. • Partner with CAR team leads to collect, validate and normalize metrics (validation volumes, findings/remediation aging, audit closure rates) across platform, application and vendor go-live validations. • Prepare and present **monthly and quarterly leadership decks and dashboards**, translating operational metrics into clear trends, risk narratives and business impact for the CISO Tower and senior stakeholders. • Drive continuous improvement in metrics collection and reporting, working towards automated, tool-based tracking (e.g., GRC platform, Power BI/Tableau) over manual spreadsheets. • Stay current on emerging regulatory requirements relevant to the role, including **India's DPDP Act and CERT-In directions**, and reflect these in governance reporting. • Embrace our vibrant culture by striving for excellence, focusing on meaningful outcomes, and collaborating effectively. Take ownership, build relationships, and focus on personal growth to drive business strategy and foster an inclusive culture. **What you must have to be considered** • **9-12 years** of experience in information security governance, risk & compliance, including hands-on **ISO/IEC 27001 ISMS management**. • Bachelor's degree in Computer Science, Information Technology, Cybersecurity or a related field. • **ISO/IEC 27001 Lead Auditor or Lead Implementer** certification – Required. • **ISO/IEC 42001 (AI Management System) Lead Auditor** certification, or equivalent AIMS audit experience – Required. • Strong working knowledge of **enterprise information security processes, controls and validation practices**. • Proven experience defining and consolidating **security metrics, KPIs and KRIs**, with hands-on **dashboarding/reporting** (Power BI, Tableau or similar). • Excellent **stakeholder coordination, communication and project-management** skills, with the ability to drive closure across multiple teams. • A strong sense of ownership, a desire to create meaningful outcomes, and passion for work that serves a greater good. • The embodiment of Cognizant's Values: **Work as One, Dare to Innovate, Raise the Bar, Do the Right Thing, & Own It.** **These will help you succeed** • **CISA or CISM** – strongly preferred. • Experience with **GRC platforms** (ServiceNow GRC, MetricStream) for metrics tracking and reporting. • Working knowledge of **India's DPDP Act (2023 / 2025 Rules) and CERT-In directions**. • **ISO/IEC 27701** or **ITIL** certification. • Experience preparing **leadership-visibility dashboards** consolidating metrics across multiple teams. • Exposure to **AI governance concepts (NIST AI RMF)** supporting the AIMS audit function. **Work model** We believe hybrid work is the way forward as we strive to provide flexibility wherever possible. Based on this role's business requirements, this is a hybrid position requiring 2 days a week in a Cognizant office in Chennai, India. Regardless of your working arrangement, we are here to support a healthy work-life balance though our various wellbeing programs. The working arrangements for this role are accurate as of the date of posting. This may cha